EDR: How to find the last time a binary's associated Alliance Feed was updated
book
Article ID: 290381
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Show More
Show Less
Issue/Introduction
Find the last time an Alliance feed associated with a binary was updated.
Resolution
Collect the binary doc from the master server via the following curl command replacing BINARYMD5 with the corresponding binary MD5 value
Find the alliance_updated date field for the related feed. This will contain the last update time
Additional Information
This is useful in situations where a binary alert has triggered for an old event. This can be correlated with the last update time with the feed hit in /var/log/cb/job-runner/job-runner.log.
Feedback
thumb_up
Yes
thumb_down
No