Process Used to Run Carbon Black EDR Live Response
search cancel

Process Used to Run Carbon Black EDR Live Response

book

Article ID: 289044

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

What process(es) or executables are used to run Live Response by the sensor?

Environment

  • EDR Server: All Supported Versions
  • EDR Sensor: All Supported Versions

Resolution

The process used by the sensor to run a Live Response session is C:/Windows/CarbonBlack/cb.exe

Additional Information

  • Communication from the sensor still comes through the sensor port (443) via nginx service and then gets forwarded to the LiveResponsePort where the Live Response service is running. The EDR sensor service process running on the endpoint is responsible for the Live Response activity on the endpoint. 
  • No .dlls are used to run Live Response on the endpoint
  • Live Response communicates over port TCP/443