Carbon Black
Telemetry Evidence
These values show how indexed rules identify Carbon Black telemetry.Kusto
CarbonBlackEvents_CL CarbonBlackNotifications_CL Panther
CarbonBlack.AlertV2 CarbonBlack.Audit carbonblack
Detection Rules
Kusto #
- Known Malware Detected source medium: 'This creates an incident when a known Malware is detected on a endpoint managed by a Carbon Black.'
T1204
Panther #
- Carbon Black Admin Role Granted source high: Detects when a user is granted Admin or Super Admin permissions.
T1098 - Carbon Black API Key Created or Retrieved source medium: Detects when a user creates a new API key or retrieves an existing key.
T1136 - Carbon Black Data Forwarder Stopped source high: Detects when a user disables or deletes a Data Forwarder.
T1685.002 - Carbon Black Log Entry Flagged source medium: Detects when Carbon Black has flagged a log as important, such as failed login attempts and locked accounts.
T1110 - Carbon Black User Added Outside Org source high: Detects when a user from a different organization is added to Carbon Black.
T1136
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #
T1210Panther #
Compatible Rules
These rules declare Carbon Black connector or schema compatibility without a product-specific query filter.Kusto #
T1490T1547T1112, T1547T1685T1685T1027, T1059