CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.
search cancel

CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.

book

Article ID: 288200

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Querying on the fileless_scriptload_cmdline may return additional process hits where the CMD field (in the process analysis pages) does not render the string searched for.

Environment

  • CBC Console: 1.3 and earlier
  • CBC Windows Sensors: All versions
  • Microsoft Windows: All versions

Cause

This is internal issue LC-1971. In reality, the string DOES occur, and therefore the query is ACCURATE.
What's occurring is the CMD field is so large, it cannot fit into the UI.
The queried string CAN be seen by turning on Chrome Devtools and rendering the process analysis page
where the string can be found in a  "results" field/

Resolution

Feature Request "FR-002859" has been created which will likely create a new field to render the CMD results properly.