Skip to main content

CBFindIP

This Script is part of the Carbon Black Enterprise Response Pack.#

Search Carbon Black for connection to specified IP addresses.

Script Data#


NameDescription
Script Typepython3
Tagscarbon-black, endpoint, enhancement
Cortex XSOAR Version5.0.0

Inputs#


Argument NameDescription
ipCSV list of IP addresses to identify.

Outputs#


PathDescriptionType
Process.PathProcess path.String
Process.PIDProcess PID.Number
Process.MD5Process MD5 hash.String
Process.HostnameProcess hostname.String
Process.NameProcess name.String
Process.CbSegmentIDCarbon Black "segment" where this process instance is stored. Required to fetch additional information for a process.String
Process.CbIDCarbon Black unique ID for this process instance. Required (together with CbSegmentID) to fetch additional information for a process.String
Process.EndpointThe endpoint of the process.String