How To Provide A Malware Sample To Carbon Black Support
book
Article ID: 291879
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)Carbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)Carbon Black EDR (formerly Cb Response)Carbon Black Hosted EDR (formerly Cb Response Cloud)
Issue/Introduction
Explain how to provide a malware sample when requested by Support
Environment
All Carbon Black Products
Resolution
Search for the hash on VirusTotal.com
If the hash is known to VT, a sample can be downloaded
If this is the case, let Support know the file can be downloaded via VirusTotal and ignore further steps
Put the file in question in an encrypted ZIP archive with password "infected"
Once uploaded, communicate the filename to Support via the case
Additional Information
Do not upload any files without request from Support
Files should not be uploaded simply to analyze if something is a false positive or malicious. To be made aware of malicious hashes in an environment, consider adding on Managed Detection to a VMware CB Cloud instance by contacting an assigned Sales Account Manager.
Malware should never be attached to an email or Support case
Malware uploaded is only visible by the Threat Analysis Unit