Broadcom Carbon Black
Broadcom Carbon Black is an advanced endpoint security and threat detection platform that provides comprehensive visibility and protection for endpoints across an organization. Formerly known as VMware Carbon Black before Broadcom's acquisition, this cloud-native endpoint protection platform (EPP) combines next-generation antivirus (NGAV), endpoint detection and response (EDR), and behavioral analytics to defend against sophisticated cyber threats, malware, ransomware, and advanced persistent threats (APTs).
| Category | EDR |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | broadcom.com |
Before you start
Huntbase signs in to Broadcom Carbon Black with API Key. Create the credential in Broadcom Carbon Black first, then keep it to hand for the Connect step.
- Sign in to the Carbon Black EDR console as the user the connection should act as.
- Click your user name in the top right corner and select My Profile.
- Click API Token on the left and copy the token. If no token is shown, click Reset to create one.
- This connection works with Carbon Black EDR (formerly CB Response). Carbon Black Cloud uses different API keys that won't work here.
- Each user has one API token. It has all of that user's rights and doesn't expire, so treat it like a password. Clicking Reset revokes the old token.
For the vendor's own instructions, see Carbon Black EDR API authentication.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Broadcom Carbon Black
- Go to Connections and click New connection, or click New connection on the Broadcom Carbon Black product page.
- On Product, pick Broadcom Carbon Black and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Broadcom Carbon Black lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your Carbon Black EDR server, such as cbserver.example.com. |
| Port | Yes | 443 unless your EDR server listens on a different port. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Advanced settings
These settings are under Advanced. You can usually leave them alone.
| Field | Required | Notes |
|---|---|---|
| Events Mode | No | Searches the process events API instead of processes. Requires Carbon Black EDR 6.1 or later. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Token | Yes | API token of the data source. Secret — not shown again after you save it. |
Query it
Once connected, Broadcom Carbon Black can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog