Carbon BlackPlatform Search

Sigma to Carbon Black Cloud

Paste a Sigma rule, get a Carbon Black Cloud Platform Search query for investigated process telemetry. Free, no sign-up.

certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the field28 lines · 906 B
Carbon BlackCarbon Black Cloud

Carbon Black

Google Security Operations

Target not listed? Tell us which →
device_os:WINDOWS AND ((process_name:*\\certutil.exe OR process_original_filename:CertUtil.exe) AND (process_cmdline_raw:*\-encode* OR process_cmdline_raw:*\/encode* OR process_cmdline_raw:*–encode* OR process_cmdline_raw:*—encode* OR process_cmdline_raw:*―encode*))
1 line · 272 B2/2 conditions

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

Conversion reportwindows / process_creation → Carbon Black Cloud3 fields mappedClean

Every condition converted cleanly to Carbon Black Cloud Platform Search.

Profile

Matched on product + category

Field map

Sigma fieldTarget fieldSource
CommandLineprocess_cmdline_rawdeveloper.carbonblack.com
Imageprocess_namedeveloper.carbonblack.com
OriginalFileNameprocess_original_filenamedeveloper.carbonblack.com

Coverage

  1. selection_imgexpressed
  2. selection_cliexpressed

2 / 2 conditions expressed

Engine 1.0.12026-08-07Rule licensed DRL-1.1

Worked examples on Carbon Black Cloud

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationClean

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        It exercises the `windash` modifier, where one flag has to be matched in both its dash
        and slash spellings.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains|windash: '-encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    license: DRL-1.1
    

    Carbon Black Cloud · Platform Search

    device_os:WINDOWS AND ((process_name:*\\certutil.exe OR process_original_filename:CertUtil.exe) AND (process_cmdline_raw:*\-encode* OR process_cmdline_raw:*\/encode* OR process_cmdline_raw:*–encode* OR process_cmdline_raw:*—encode* OR process_cmdline_raw:*―encode*))

    Every condition converted cleanly to Carbon Black Cloud Platform Search. 2/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationClean

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    license: DRL-1.1
    

    Carbon Black Cloud · Platform Search

    device_os:WINDOWS AND ((process_cmdline_raw:*.DownloadString\(* OR process_cmdline_raw:*.DownloadFile\(* OR process_cmdline_raw:*Invoke\-WebRequest\ * OR process_cmdline_raw:*Invoke\-RestMethod\ *) AND (process_cmdline_raw:*\|\ IEX* OR process_cmdline_raw:*IEX\ \(* OR process_cmdline_raw:*Invoke\-Expression*))

    Every condition converted cleanly to Carbon Black Cloud Platform Search. 2/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationClean

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    license: DRL-1.1
    

    Carbon Black Cloud · Platform Search

    device_os:WINDOWS AND ((process_name:*\\regedit.exe OR process_original_filename:REGEDIT.EXE) AND process_cmdline_raw:*.reg* AND process_cmdline_raw:/.*:[^ \\].*/ AND (NOT (process_cmdline_raw:*\ \-e\ * OR process_cmdline_raw:*\ \/e\ * OR process_cmdline_raw:*\ –e\ * OR process_cmdline_raw:*\ —e\ * OR process_cmdline_raw:*\ ―e\ * OR process_cmdline_raw:*\ \-a\ * OR process_cmdline_raw:*\ \/a\ * OR process_cmdline_raw:*\ –a\ * OR process_cmdline_raw:*\ —a\ * OR process_cmdline_raw:*\ ―a\ *)))

    Every condition converted cleanly to Carbon Black Cloud Platform Search. 3/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationClean

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    license: DRL-1.1
    

    Carbon Black Cloud · Platform Search

    device_os:WINDOWS AND (process_name:*\\print.exe AND process_cmdline_raw:print* AND process_cmdline_raw:*\/D* AND process_cmdline_raw:*.exe* AND (NOT process_cmdline_raw:*print.exe*))

    Every condition converted cleanly to Carbon Black Cloud Platform Search. 2/2 conditions

What to know about Carbon Black Cloud Platform Search

This target emits the Lucene query that Carbon Black Cloud's Processes Search API accepts in its query field, rather than a legacy Carbon Black EDR or CB Response search. They share a brand but not a schema: Platform Search names the process path process_name and the command line process_cmdline, while older products use different field families. Keeping that boundary explicit matters because a query that parses against the wrong product can still return no results and look perfectly healthy.

The first coverage slice is deliberately focused on Windows process creation. Every query starts with device_os:WINDOWS and uses the documented Process Search fields for process image, parent, PID, user, original filename and executable metadata. Command lines bind to the raw command-line fields, which preserve separators such as backslashes and parentheses; the ordinary tokenized field intentionally discards many of those characters while indexing.

Carbon Black Process Search supports negation, but its own documentation points out the consequence: NOT process_cmdline:value also includes records where the command line is missing. That is the same absence behaviour Sigma negation expects, so the converter does not add an existence guard that would silently narrow the rule. Fields whose values are not provably comparable — Sysmon process GUIDs, composite Hashes and Windows logon-session IDs — make this strict target refuse the conversion instead of emitting a plausible-looking mismatch. Validate the resulting query against your tenant before turning it into a watchlist or alert.

Carbon Black Cloud Platform Search reference →

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns Platform Search for Carbon Black Cloud, the log-source profile it matched, the field map it applied, and anything Carbon Black Cloud cannot express. Free, no sign-up.

Carbon Black Cloud Platform Search, specifically the Processes Search API and Investigate process-search surface. It does not emit the legacy Carbon Black EDR/Response query language or Live Query SQL, because those products use different schemas and query contracts.

The first verified coverage slice is Sigma Windows process creation. device_os:WINDOWS is the documented Platform Search population filter, so it prevents a process-name or command-line clause from searching a different operating system population.

This is a strict schema target. A Sysmon GUID, composite Hashes value or Windows logon-session ID is not automatically the same thing as a similarly named Carbon Black field. The converter stops with the field named rather than sending a query that runs and silently matches nothing.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Carbon Black Cloud here.