CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.
book
Article ID: 288200
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Querying on the fileless_scriptload_cmdline may return additional process hits where the CMD field (in the process analysis pages) does not render the string searched for.
Environment
CBC Console: 1.3 and earlier
CBC Windows Sensors: All versions
Microsoft Windows: All versions
Cause
This is internal issue LC-1971. In reality, the string DOES occur, and therefore the query is ACCURATE. What's occurring is the CMD field is so large, it cannot fit into the UI. The queried string CAN be seen by turning on Chrome Devtools and rendering the process analysis page where the string can be found in a "results" field/
Resolution
Feature Request "FR-002859" has been created which will likely create a new field to render the CMD results properly.