-
Notifications
You must be signed in to change notification settings - Fork 385
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Develop Responder for CB Response / Carbon Black Endpoint Detection and Response #856
Comments
Hey @yugoslavskiy, happy to collaborate on this one. Any idea how we can have access to a testing environment / account ? |
Hey @nadouani! Sounds great! How about this weekend? I have access to CB PSC (: |
I'll try to cook something before the weekend so we can test it ;) |
Hello @yugoslavskiy I have no experience with CB PSC but this is my finding when taking a look into the documentation:
|
This is an initial commit, we need a discussion about how does CB OSC works to complete the responder: |
Hello @nadouani! Sorry for the late participation. |
Here are the results of my research:
Regardless of the tools/licenses/products, they have released new API and most probably stopped supporting the old library that you were referring to, @nadouani. People are saying that they cannot authenticate. I wasn't able to find any information about blocking functionality in their new API for cloud products. It seems that such API calls are available only for on-premise solutions. So, it seems that there is nothing I can help with, unfortunately ): How about asking people in TheHive mail user group/twitter if any of them have this on-premise "CB Response" that is now called "Carbon Black Endpoint Detection and Response" or "Carbon Black EDR"? I would love to collab with them anyway. PS |
I've got this one for both cloud an on-prem with both an analyzer and responder. Will release cloud first. |
Hello @xg5-simon! Do you need any help with it? (: |
Hello @xg5-simon! Would you like to proceed with the PR? |
Feature description
Responder for CB Response (previous name) / Carbon Black Endpoint Detection and Response (current name) or just "Carbon Black EDR" that would be able to execute the following Response Actions:
Describe the solution you'd like
Here is the official API documentation that includes all information required for the development.
Additional context
You can refer to the existing Cisco AMP (EDR) Responder during the development.
The text was updated successfully, but these errors were encountered: