Sensors report events to the Carbon Black EDR server only if they originate from an event that is not backed by an on-disk file. File-based scripts are logged locally.
Support fro decoding fileless script content via AMSI is dependent on the script interpreter that integrates with the AMSI interface in Windows. Carbon Black currently supports Powershell.
AMSI data is part of process execution metadata. A generic event type is added as part of the AMSI data stream.
All AMSI content is logged locally on the endpoint as a text file named AmsiEvents.log. The local file caps at 50 MB unzipped and only two AmsiEvents.log files exist.