How to validate a complete install, or upgrade, for a macOS sensor.
ps -ax | grep -i cbosx
systemextensionctl list
Check Settings > Security&Privacy > es-extension
Check Settings > Network
cat /var/log/cblog.log
log show -start “yyyy-mm-dd hh:mm:ss" -debug | grep -i cb (use the date/timestamp of the install) log show -start “yyyy-mm-dd hh:mm:ss" -debug | grep -i carbonblack
| /Applications/Vmware Carbon Black EDR/Contents/MacOS/CbOsxSensorService | Sensor service |
| /Applications/Vmware Carbon Black EDR/Contents/Resources/sensoruninst.sh | Uninstall script |
| /System/Library/Extensions/CbOsxSensorNetmon.kext (macOS 10.x & earlier) | Network monitor |
| /System/Library/Extensions/CbOsxSensorProcmon.kext (macOS 10.x & earlier) | Process monitor |
| macOS 11.x & newer Run systemextensionctl list [activated enabled]) |
User-mode monitor |
| /var/root/Library/Preferences/ com.carbonblack.sensor-service.plist |
Settings file |
| /Library/Keychains/carbonblack.keychain | Keychain |
sudo launchctl unload /Library/LaunchDaemons/com.carbonblack.daemon.plist sudo launchctl load /Library/LaunchDaemons/com.carbonblack.daemon.plist
/Applications/VMware\ Carbon\ Black\ EDR.app/Contents/MacOS/CbOsxSensorService -v
Additional Links: