Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] Include Event Details for CbC and CbR #126

Open
3 of 10 tasks
rc-csmith opened this issue Jul 18, 2023 · 0 comments
Open
3 of 10 tasks

[FR] Include Event Details for CbC and CbR #126

rc-csmith opened this issue Jul 18, 2023 · 0 comments
Labels

Comments

@rc-csmith
Copy link
Contributor

Which category is the feature part of?

  • Definition File
  • Code/Logic Feature
  • Other (please explain)

Which product is the feature part of?

  • All Products
  • Carbon Black Response
  • Carbon Black Threat Hunter
  • Defender for Endpoints
  • SentinelOne
  • Cortex
  • Other

Use Cases

When searching for anything non-process-related (e.g. regmod, netconn, filemod), the actual result is not included in the output from CbR or CbC. You don't know what registry key was found or what file modification was identified by the query - you're only given the process and then have to pivot into the native EDR's portal to continue searching.

Proposal

Expand CbR and CbC to include event details. This change can definitely impact performance so I propose only including event details if explicitly set via flag/param at runtime.

Additional Context

N/A

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant