Cylance Finds
Log In or Register to download the BES file, and more.

0 Votes

Description

Reads information from Cylance logs.

Property Details

ID2995825
StatusQA - Ready for Production Level Testing
TitleCylance Finds
DomainBESC
KeywordsCYLANCE
Added by on 12/7/2015 2:18:04 PM
Last Modified by on 12/7/2015 2:18:04 PM
Counters 4781 Views / 15 Downloads
User Rating 1 star 2 star 3 star 4 star 5 star * Average over 0 ratings. ** Log In or Register to add your rating.

Properties

Alerted Files
Period 1 day
 
  * Results in a true/false
Show indented relevance
(unique values of ("Alerted File: " & (following text of last "\" of preceding text of last "'" of it) & " SHA256: " & (following text of first "SetCache should block " of preceding text of last " '" of it) & " Path: " & (following text of first "'" of preceding text of last "\" of it)) of lines whose (it contains "SetCache should block" AND it contains "[22]") of files of (folder "Program Files\Cylance\Desktop\log" of drive of system folder))
Blocked Files
Period 1 day
 
  * Results in a true/false
Show indented relevance
(unique values of ("File: " & (following text of last "\" of preceding text of last "'" of it) & " SHA256: " & (following text of first "SetCache block " of preceding text of last " '" of it) & " Path: " & (following text of first "'" of preceding text of last "\" of it)) of lines whose (it contains "SetCache block" AND (it contains "[17]" or it contains "[25]")) of files of (folder "Program Files\Cylance\Desktop\log" of drive of system folder))

Relevance

isWindows (Relevance 1172)
Used in 1155 fixlets and 538 analyses   * Results in a true/false
Show indented relevance
windows of operating system
Used in 1 analsis   * Results in a true/false
Show indented relevance
exists key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2E64FC5C-9286-4A31-916B-0D8AE4B22954}" of native registry

Sharing

Social Media:
Share this page on Yammer

Comments

Log In or Register to leave comments!