Carbon Black Cloud Integrations


Partner Integrations

Carbon Black Cloud Integrations

Name Description Version Release Date Supported Products
Binary Toolkit Lets you integrate between Carbon Black Cloud Enterprise EDR and a binary analysis engine, like YARA. 1.1.0 2020-11-20 Enterprise EDR
CBC Python SDK Provides an easy interface to connect with Carbon Black Cloud products. Use this SDK to more easily query and manage your endpoints, manipulate data as Python objects, and harness the full power of Carbon Black Cloud APIs. 1.4.1 2022-10-21 Platform
Workload
Enterprise EDR
Endpoint Standard
Audit and Remediation
Data Forwarder Built in to the Carbon Black Cloud platform; Delivers Alert, Event and Watchlist Hit data to an AWS S3 bucket, ready for consumption by third-party solutions. N/A 2020 Platform
Workload
Enterprise EDR
Endpoint Standard
QRadar App Configures a connection in QRadar to ingest alerts, audit logs, and events from Carbon Black Cloud using the Data Forwarder and APIs into IBM QRadar. Actions such as quarantining devices and adding IOCs to watchlists can be initiated in QRadar to take effect in Carbon Black Cloud. 2.1.0 2022-05-17 Platform
Workload
Enterprise EDR
Endpoint Standard
Service Now - ITSM App and SecOps App Ingest Alerts and Vulnerabilities from Carbon Black Cloud to Service Now and automatically create Service Now incidents to track the resolution. A large set of actions such as quarantining devices are available to be initiated in ServiceNow and take effect in Carbon Black Cloud. 1.0.0 2022-07-06 Platform
Workload
Enterprise EDR
Endpoint Standard
Splunk App Lets administrators bring alerts, events, audit logs, or vulnerability data from Carbon Black Cloud into their Splunk dashboard. 1.1.8 2023-01-12 Platform
Workload
Enterprise EDR
Endpoint Standard
Audit and Remediation
Splunk SOAR App Configures a connection in Splunk SOAR to ingest alerts from Carbon Black Cloud using the REST APIs. Actions can be initiated in Splunk SOAR to take effect in Carbon Black Cloud. 1.0.1 2023-01-18 Platform
Enterprise EDR
Endpoint Standard
Syslog Connector Lets administrators forward alert notifications and audit logs from their Carbon Black Cloud instance to local, on-premise systems. 1.3.1 2021-01-15 Platform
Enterprise EDR
Endpoint Standard
Threat Intel Module (Deprecated) Lets you integrate Carbon Black Cloud Enterprise EDR and a threat intelligence source, with an example for STIX/TAXII to import intel into Enterprise EDR Feeds. 1.0 N/A Enterprise EDR
Threat Intelligence Connector A python connector for ingesting and processing STIX Content from various third party sources, such as TAXII servers or directly from XML or JSON files. 1.4 2023-01-23 Enterprise EDR
Zscaler Sandbox Connector Scans files from Carbon Black Cloud Endpoint Standard or Enterprise EDR that come through the network before they reach the endpoint. 1.1 2021-12-06 Enterprise EDR
Endpoint Standard
Last modified on January 10, 2023