Broadcom CarbonBlack Cloud
Broadcom CarbonBlack Cloud is a comprehensive cloud-native endpoint security platform that provides next-generation antivirus (NGAV), endpoint detection and response (EDR), and managed detection and response (MDR) capabilities. The platform delivers advanced threat detection, incident response, and behavioral analytics to protect endpoints including workstations, servers, laptops, virtual machines, and cloud workloads across Windows, macOS, and Linux operating systems.
| Category | EDR |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | broadcom.com |
Before you start
Huntbase signs in to Broadcom CarbonBlack Cloud with API Key. Create the credential in Broadcom CarbonBlack Cloud first, then keep it to hand for the Connect step.
- In the Carbon Black Cloud console, go to Settings › API Access › Access Levels and click Add Access Level.
- Grant the
org.search.eventspermission with Create, Read and Delete only, then save the access level. - Go to Settings › API Access › API Keys, click Add API Key, choose the Custom access level type and select the access level you just created.
- Save, then copy the API Secret Key and API ID. The secret can't be retrieved later.
- Copy your Org Key from Settings › General, or from Settings › API Access if Carbon Black Cloud manages your identities.
Permissions:
- org.search.events: Create, Read, Delete (process search)
For the vendor's own instructions, see Carbon Black Cloud API authentication documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Broadcom CarbonBlack Cloud
- Go to Connections and click New connection, or click New connection on the Broadcom CarbonBlack Cloud product page.
- On Product, pick Broadcom CarbonBlack Cloud and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Broadcom CarbonBlack Cloud lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | Your console's API hostname for your region, such as defense.conferdeploy.net or defense-eu.conferdeploy.net. |
| Port | Yes | 443. Defaults to 443. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Org Key | Yes | Organization key. Secret — not shown again after you save it. |
| API Token | Yes | Enter the secret and ID joined by a slash, in the form API_SECRET_KEY/API_ID. Secret — not shown again after you save it. |
Query it
Once connected, Broadcom CarbonBlack Cloud can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog