Enterprise EDR: Watchlist IOC is found in the investigate page but not triggered
search cancel

Enterprise EDR: Watchlist IOC is found in the investigate page but not triggered

book

Article ID: 287451

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Watchlist IOC is found in the Investigate page but not triggered.

Environment

  • Carbon Black Cloud Console: All Versions
    • Enterprise EDR

Cause

IOC has a missing or incorrect "Field" name.

Resolution

Update or recreate IOC to include "Field" name that work on the Investigate page.

Additional Information

All IOC's must have a "Field" assigned to them. They will be seen either in the IOC itself or using DevTools viewing the IOC. Incorrect "Field" will not produce results on the Investigate page.

Example:
Searching Investigate page for an IP using "netconn_ipv4:152.70.253.207" may trigger results and will work as a watchlist. 
"Field" would equal netconn_ipv4 and could be visible in the watchlist IOC or if not defined in the IOC it will be visible in DevTools, not both. 

Finding the "Field" value in DevTools
  1. Open DevTools
  2. Navigate to a Watchlist
  3. Navigate to a Report
  4. Select an IOC
  5. In the URL after the word report the IOC ID will be listed 
  6. Find and select the IOC ID in DevTools
  7. Expand the iocs_v2 and drill down to the IOC and "Field" name
It will be defined as null if it is in the actual IOC.