Carbon Black

Telemetry Evidence

These values show how indexed rules identify Carbon Black telemetry.

Kusto

  • Queried source table CarbonBlackEvents_CL (1 rule)
  • Queried source table CarbonBlackNotifications_CL (1 rule)

Panther

  • Log type CarbonBlack.AlertV2 (1 rule)
  • Log type CarbonBlack.Audit (5 rules)
  • Platform carbonblack (6 rules)

Detection Rules

Kusto #

Panther #

Other Index Content

This content is indexed for research but excluded from the detection-rule headline.

Kusto #

Panther #

  • Carbon Black Passthrough Rule source medium: This rule enriches and contextualizes security alerts generated by Carbon Black. The alert title and description are dynamically updated based on data included in the alert log.

Compatible Rules

These rules declare Carbon Black connector or schema compatibility without a product-specific query filter.

Kusto #