Watchlist with Negated MD5 are Generating Unexpected Alerts
search cancel

Watchlist with Negated MD5 are Generating Unexpected Alerts

book

Article ID: 435976

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

A watchlist that is using a negated md5: search term is generating alerts for processes containing that hash.

Environment

  • Carbon Black EDR Server: 7.9.1 and below

Cause

md5 field does not exist in a watchlist tagged segment within the document. The alert is being generated off of another watchlist hit. 

Resolution

  • Workaround: Update the watchlist to use "process_md5" rather than "md5"
  • Fix Version: 7.9.2 Server

Additional Information

  • If this issue is generating an overwhelming amount of alerts, contact support for a drop in patch file until the fix version release.