CB ThreatHunter: Watchlist False Positive for process_file_description:"Windows Command Processor"
book
Article ID: 289703
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
- Process with unknown file descriptions are marked by watchists requiring process_file_description:"Windows Command Processor"
- Searches on the investigate page will return the same results
Resolution
Carbon Black is investigating the root cause
Feedback
thumb_up
Yes
thumb_down
No