CB Response: Does CB Response have a Packet Capture function
book
Article ID: 288813
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Does CB Response have a packet capture and inspection capability similar to Wireshark or TCPDump
Environment
- CB Response Sensor: All Versions
- CB Response Console: All Versions
Resolution
No. Netconns are logged, but individual packets for inspection are not available.
Feedback
thumb_up
Yes
thumb_down
No