Tamper Detection Alerts For the Sensor not being Generated
book
Article ID: 413572
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Tamper detection alerts are not getting created.
- Stopping the sensor service manually on the endpoint should send a tamper alert.
Environment
- Carbon Black EDR Console: All Versions
Cause
A configuration is not enabled causing the alert to not send.
Resolution
Verify the following configurations are set in the EDR console
- Enable the Feed, alerting and reports
- Navigate to the Threat Intelligence page.
- Find the Tamper Detection feed and click Enabled
- Drop down the Notifications and select "Create Alert"
- Click the link to "Threat Reports". Verify all reports are not set to "Ignore"
- Enable detection on Sensors
- Navigate to the sensors page.
- Select a sensor group and click the settings gear.
- Click "Advanced" to expand the settings.
- Set "Tamper Protection Level" to Detection or Protection.
- Save the group before continuing.
- Repeat for each sensor group requiring tamper monitoring.
Additional Information
- Tamper events can be searched in the process search page using "tampered:true"
- Tamper alerts can be filtered by the Feed facet under the name "cbtamper"
Feedback
thumb_up
Yes
thumb_down
No