Carbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
How are reputations assigned for files? Is there a set order for which reputation gets used if there is more than one? Where can I find the reputation priority matrix?
Environment
Carbon Black Cloud Console: All Versions
Endpoint Standard Sensor: All Versions
Microsoft Windows: All Supported Versions
Apple MacOS: All Supported Versions
Resolution
Reputation assignment depends on:
The type of file (Pre-Existing, New, Network)
The policy configuration. Settings such as Background Scan, Local Scanner Configuration, Delay Execute for Cloud Scan, Scan Files on Network Drives, Scan Execute on Network Drives all come into play.
Where the file is at in the execution process (No Execute, Pre-Execute, Post-Execute).
The current reputation (if any).
The reputation assignment priority matrix and a full breakdown of how reputations are assigned can be found in the "Reputation Assignment" section of the User Guide.