Process Used to Run Carbon Black EDR Live Response
book
Article ID: 289044
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
What process(es) or executables are used to run Live Response by the sensor?
Environment
EDR Server: All Supported Versions
EDR Sensor: All Supported Versions
Resolution
The process used by the sensor to run a Live Response session is C:/Windows/CarbonBlack/cb.exe
Additional Information
Communication from the sensor still comes through the sensor port (443) via nginx service and then gets forwarded to the LiveResponsePort where the Live Response service is running. The EDR sensor service process running on the endpoint is responsible for the Live Response activity on the endpoint.
No .dlls are used to run Live Response on the endpoint