Carbon Black Cloud: Inaccurate binary details indicates deleted hash value removed from more endpoints than expected.
search cancel

Carbon Black Cloud: Inaccurate binary details indicates deleted hash value removed from more endpoints than expected.

book

Article ID: 289021

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Marking a hash to be deleted from a small group (or single) sensor appears to have a wider effect than expected creating an Audit log trail showing almost ALL endpoints have the hash removed.

Environment

  • Carbon Black Cloud: Version 1.21 and Earlier

Cause

When the hash is marked to be deleted from sensors, if it is not found on an endpoint, it will still be included in origins index on all endpoints and create a false positive effect in the Audit logs and Binary details pages showing the hash being deleted everywhere.

Resolution

Created DSER-47845 and the issue was fixed in 1.22 backend release (January 18th 2024)