Skip to main content

Broadcom Carbon Black

Broadcom Carbon Black is an advanced endpoint security and threat detection platform that provides comprehensive visibility and protection for endpoints across an organization. Formerly known as VMware Carbon Black before Broadcom's acquisition, this cloud-native endpoint protection platform (EPP) combines next-generation antivirus (NGAV), endpoint detection and response (EDR), and behavioral analytics to defend against sophisticated cyber threats, malware, ransomware, and advanced persistent threats (APTs).

CategoryEDR
DirectionQuery source
Sign-inAPI Key
Query languagesSTIX
Websitebroadcom.com

Before you start​

Huntbase signs in to Broadcom Carbon Black with API Key. Create the credential in Broadcom Carbon Black first, then keep it to hand for the Connect step.

  1. Sign in to the Carbon Black EDR console as the user the connection should act as.
  2. Click your user name in the top right corner and select My Profile.
  3. Click API Token on the left and copy the token. If no token is shown, click Reset to create one.
Watch out for
  • This connection works with Carbon Black EDR (formerly CB Response). Carbon Black Cloud uses different API keys that won't work here.
  • Each user has one API token. It has all of that user's rights and doesn't expire, so treat it like a password. Clicking Reset revokes the old token.

For the vendor's own instructions, see Carbon Black EDR API authentication.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Broadcom Carbon Black​

  1. Go to Connections and click New connection, or click New connection on the Broadcom Carbon Black product page.
  2. On Product, pick Broadcom Carbon Black and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Broadcom Carbon Black lives:

FieldRequiredNotes
Server AddressYesThe hostname of your Carbon Black EDR server, such as cbserver.example.com.
PortYes443 unless your EDR server listens on a different port. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Advanced settings​

These settings are under Advanced. You can usually leave them alone.

FieldRequiredNotes
Events ModeNoSearches the process events API instead of processes. Requires Carbon Black EDR 6.1 or later.

Credentials​

The only Method is API Key. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesAPI token of the data source. Secret — not shown again after you save it.

Query it​

Once connected, Broadcom Carbon Black can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​