How to validate a complete install, or upgrade, for a macOS sensor.
ps -ax | grep -i cbosx
systemextensionctl list
Check Settings > Security&Privacy > es-extension
Check Settings > Network
cat /var/log/cblog.log
log show -start “yyyy-mm-dd hh:mm:ss" -debug | grep -i cb (use the date/timestamp of the install) log show -start “yyyy-mm-dd hh:mm:ss" -debug | grep -i carbonblack
/Applications/Vmware Carbon Black EDR/Contents/MacOS/CbOsxSensorService | Sensor service |
/Applications/Vmware Carbon Black EDR/Contents/Resources/sensoruninst.sh | Uninstall script |
/System/Library/Extensions/CbOsxSensorNetmon.kext (macOS 10.x & earlier) | Network monitor |
/System/Library/Extensions/CbOsxSensorProcmon.kext (macOS 10.x & earlier) | Process monitor |
macOS 11.x & newer Run systemextensionctl list [activated enabled]) |
User-mode monitor |
/var/root/Library/Preferences/ com.carbonblack.sensor-service.plist |
Settings file |
/Library/Keychains/carbonblack.keychain | Keychain |
sudo launchctl unload /Library/LaunchDaemons/com.carbonblack.daemon.plist sudo launchctl load /Library/LaunchDaemons/com.carbonblack.daemon.plist
/Applications/VMware\ Carbon\ Black\ EDR.app/Contents/MacOS/CbOsxSensorService -v
Additional Links: