Skip to content
Alex Van Brunt edited this page Jun 30, 2020 · 17 revisions

Carbon Black Cloud Binary Toolkit

Please read the README before using this Wiki.

This Wiki includes a User Guide and a Developer Guide. The guides include instructions for running the Carbon Black Cloud Binary Toolkit (i.e. Toolkit) and guidelines for how to modify the Toolkit to suit your needs.

Why would I use this toolkit?

The toolkit provides a quickly configurable and extensible way to improve the continuous monitoring of endpoints. By analyzing the binaries that endpoints encounter, you can add that threat intelligence to a Feed that can be continuously monitored through Watchlists.

The example YARA analysis engine included with the toolkit provides a way to improve that monitoring with minimal setup.

For details on the expected performance of CBC Binary Toolkit see Performance Metrics

I want to...

Get Up and Running Quickly

User Guide

For those looking to use the Toolkit to analyze binaries captured by Carbon Black Cloud.

Modify the Toolkit

Developer Guide

For those looking to extend the code of the Toolkit.