Enterprise EDR: Process Analysis page is not showing correct parent process name for selected process
search cancel

Enterprise EDR: Process Analysis page is not showing correct parent process name for selected process

book

Article ID: 287681

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

  • Process path showing at top of Process Analysis page does not match selected process.
  • Selecting process in process tree displays correct process path in┬ápanel on right of page.

Environment

  • Carbon Black Cloud
  • Enterprise EDR (Formerly Threat Hunter)
  • Carbon Black Cloud Sensor (v3.5+)

Cause

  • Sensor incorrectly applying script replacement logic for processes resulting in Enterprise EDR reporting the process┬áname incorrectly
    • Ex. Winword.exe opens doc1.docx, sensor then shows any further activity as being from doc1.docx

Resolution

Upgrade to 3.6+ sensor version