Carbon Black Cloud: Inaccurate binary details indicates deleted hash value removed from more endpoints than expected.
book
Article ID: 289021
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Marking a hash to be deleted from a small group (or single) sensor appears to have a wider effect than expected creating an Audit log trail showing almost ALL endpoints have the hash removed.
Environment
Carbon Black Cloud: Version 1.21 and Earlier
Cause
When the hash is marked to be deleted from sensors, if it is not found on an endpoint, it will still be included in origins index on all endpoints and create a false positive effect in the Audit logs and Binary details pages showing the hash being deleted everywhere.
Resolution
Created DSER-47845 and the issue was fixed in 1.22 backend release (January 18th 2024)