Carbon BlackProcess Search

Sigma to Carbon Black EDR

Paste a Sigma rule, get Process Search for Carbon Black EDR.

  1. Paste the ruleYAML in
  2. Pick your SIEMCarbon Black EDR · Process Search
  3. Read the reportQuery, field map, gaps
certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the fieldValid Sigmaprocess_creation · windows29 lines · 968 B
Splunk logo An information technology company based in California, United States Splunk2
Microsoft3
Elastic3
CrowdStrike1
SentinelOne1
Palo Alto Networks1
Carbon BlackCarbon Black2
Google Security OperationsGoogle1
IBM1
Sumo Logic1
Rapid71
Graylog1
OpenSearch2
Grafana1
DFIR2
3 caveats
cmdline:-encode OR cmdline:/encode
1 line · 34 B1/2 conditions

Notes — not part of the query

Target: Carbon Black EDR (Process Search) — engine 1.0.1 — 2026-09-09

Profile: windows / process_creation → Carbon Black EDR

Coverage: 1/2 conditions

annotated: Image — Kept the closest available mapping; it is not an exact equivalent.

dropped: OriginalFileName — Dropped the predicate; the query is broader than the rule.

Setup (Process Search): Paste this into the Process Search box. The search page is the scope — there is no dataset stanza in the query text — so run it on Process Search rather than on Binary or Threat Report Search, where these fields do not all exist.

huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — NOASSERTION

Verify against your own telemetry before deploying.

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

No account needed for this, and none for reading the library. Every rule shows the reporting behind it, the telemetry it needs and the ATT&CK technique it covers. Sign in to keep the ones you use.

Conversion reportwindows / process_creation → Carbon Black EDR1 field mapped · 2 unmapped · 2 constructs unsupportedDegraded

Converted to Carbon Black EDR Process Search with 2 notes. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule.

Profile

Matched on product + category

Field map

Sigma fieldTarget fieldSource
CommandLinecmdlinetechdocs.broadcom.com

Unmapped fields

  • Imagemapped, but not in the query

    Another predicate in the same clause had no verified mapping and was dropped. Dropping widens, and a widened branch absorbs the OR it sits in, so this predicate was removed with it and the query does not constrain this field at all.

  • OriginalFileNamedropped — query broadened

    Carbon Black EDR's published process-search field list has no column for 'OriginalFileName'. The list is complete and typed, so this is a telemetry gap rather than an unread page.

    techdocs.broadcom.com

Know the right column? Tell us and we will add it.

Unsupported constructs

  • DroppedField unmapped, predicate dropped

    OriginalFileName

    Carbon Black EDR's published process-search field list has no column for 'OriginalFileName'. The list is complete and typed, so this is a telemetry gap rather than an unread page.

    Dropped the predicate; the query is broader than the rule.

  • AnnotatedField mapped approximately

    Image

    'Image' maps approximately: Carbon Black EDR records this process as a FILE NAME, not a path: the column is documented as "Filename of the executable backing this process" and its keyword type has "no tokenization", so it holds cmd.exe and matches it whole. A value anchored on the file name alone (Image|endswith: '\cmd.exe') is rewritten to match the basename exactly, which preserves the rule's meaning because an executable path always carries at least one separator; a value with a directory component has no representation in this column. The vendor's `path` field is not used instead — its own description assigns it to the PARENT process, which contradicts its name, and mapping Image onto a possibly-parent column is the failure this refuses.

    Kept the closest available mapping; it is not an exact equivalent.

Coverage

  1. selection_imgno longer matches the same events
  2. selection_cliexpressed

1 / 2 conditions expressed

Engine 1.0.12026-09-09Rule licensed NOASSERTION

Worked examples on Carbon Black EDR

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationDegraded

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        The flag is written out in both its dash and slash spellings, because the utility
        accepts either and a rule that names only one misses half the invocations.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains:
                - '-encode'
                - '/encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    

    Carbon Black EDR · Process Search

    cmdline:-encode OR cmdline:/encode

    Converted to Carbon Black EDR Process Search with 2 notes. 1 field had no verified mapping and was dropped from the query. 1 mapped field did not reach the query either: the clause holding it collapsed when a dropped predicate widened it. The query matches more than the original rule. 1/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationFailed

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    

    Carbon Black EDR · Process Search

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write this value in expression position: a character in this value has no escape sequence.

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write this value in expression position: a character in this value has no escape sequence. 1/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationFailed

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    

    Carbon Black EDR · Process Search

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write 'regex' in expression position: no 'regex' spelling.

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write 'regex' in expression position: no 'regex' spelling. 1/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationDegraded

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    

    Carbon Black EDR · Process Search

    process_name:print.exe AND cmdline:print* AND cmdline:/D AND cmdline:.exe AND (-cmdline:print.exe)

    Converted to Carbon Black EDR Process Search with 1 note. 1/2 conditions

  5. Scheduled Task Created From A Temp Pathwindows / process_creationFailed

    Sigma

    title: Scheduled Task Created From A Temp Path
    id: 9d24a3ee-8a1b-4f26-b90f-4a71e2c85d17
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects schtasks.exe registering a task whose
        command line points into a temp directory, a common persistence shape. It exercises the
        bread-and-butter Sigma form — several selections ANDed by the condition — with no exotic
        modifiers, so it converts on every shipped target.
    author: HuntRule Team
    date: 2026-08-11
    tags:
        - attack.persistence
        - attack.t1053.005
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            Image|endswith: '\schtasks.exe'
        selection_create:
            CommandLine|contains: '/create'
        selection_path:
            CommandLine|contains:
                - '\AppData\Local\Temp\'
                - '\Windows\Temp\'
        condition: all of selection_*
    falsepositives:
        - Installers registering update tasks from their extraction directory
    level: medium
    

    Carbon Black EDR · Process Search

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write this value in expression position: a character in this value has no escape sequence.

    Could not convert to Carbon Black EDR: carbon_black_edr cannot write this value in expression position: a character in this value has no escape sequence. 1/3 conditions

  6. LSASS Memory Dump Via Comsvcswindows / process_creationDegraded

    Sigma

    title: LSASS Memory Dump Via Comsvcs
    id: 6a95c2d4-1e08-4f7b-9d52-8c41e7b30a96
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the comsvcs.dll MiniDump export being
        invoked through rundll32 to dump process memory, a common LSASS credential-theft technique.
        It exercises `endswith` against the image path together with `contains|all` on one field.
    author: HuntRule Team
    date: 2026-08-10
    tags:
        - attack.credential-access
        - attack.t1003.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            Image|endswith: '\rundll32.exe'
        selection_cli:
            CommandLine|contains|all:
                - 'comsvcs'
                - 'MiniDump'
        condition: all of selection_*
    falsepositives:
        - Administrators legitimately capturing a process dump with comsvcs
    level: high
    

    Carbon Black EDR · Process Search

    process_name:rundll32.exe AND cmdline:comsvcs AND cmdline:MiniDump

    Converted to Carbon Black EDR Process Search with 1 note. 1/2 conditions

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns Process Search for Carbon Black EDR, the log-source profile it matched, the field map it applied, and anything Carbon Black EDR cannot express. Free, no sign-up.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Carbon Black EDR here.