CB Response: False Positives from Multiple Domain List (MDL) Feed
book
Article ID: 290687
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
- Receiving false positive from MDL feed.
- Reports from MDL are suddenly noisy.
Environment
- CB Response Server: All Versions
- Multiple Domain List (MDL) feed enabled
Cause
- The MDL website is no longer being updated, this feed has been deprecated and is scheduled to be removed on 4/1/19.
Resolution
- Performing a 'Full Sync' is suggested, this will clear any reports received from the feed,
- Click on Threat Intelligence icon.
- Find MDL feed > click Actions
- Click on 'Full Sync'
- Disabling or Removing the MDL feed will have the same effect.
Feedback
thumb_up
Yes
thumb_down
No