The Binary Toolkit lets you integrate between Carbon Black Cloud Enterprise EDR and a binary analysis engine, like YARA. When the toolkit receives hashes of binaries encountered by your organization, it sets off a process where it fetches metadata about the binaries from the Unified Binary Store (UBS) and then sends the binaries through the analysis engine. The results from the engine and the metadata are consolidated and sent back to the Carbon Black Cloud where you can subscribe and monitor your environment in Watchlists.
For details on the expected performance for the CBC Binary Toolkit see the Performance Metrics wiki page here.
The wiki page will be updated with any changes or additional tests that may be run in the future.
There are two ways to use the Carbon Black Cloud Binary Toolkit. You can either: