carbon-black-cloud

Plan and document Carbon Black Cloud Enterprise EDR detection content across surfaces.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill carbon-black-cloud
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: carbon-black-cloud
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/carbon-black-cloud
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill carbon-black-cloud

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Plan and document detection content for Carbon Black Cloud Enterprise EDR configurations, distinguishing surface types, IOC structure, and alert semantics to enable consistent MDR authoring.

Core Features & Use Cases

  • Clarifies CBC surfaces (Watchlists, Scheduled Searches, Live Response) and how to structure detection content across them.
  • Details CBC query syntax, event taxonomy, and instrumentation requirements to enable consistent authoring of Reports and IOCs.
  • Documents OpenTide MDR integration considerations (surface identification, MITRE mapping, sensor tier, and data flow) to enable end-to-end CBC-based detections.

Quick Start

Configure a CBC detection content block by identifying the surface, crafting a report with MITRE mappings, and documenting sensor tier requirements for an OpenTide MDR configuration.

Frequently Asked Questions about carbon-black-cloud

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure Carbon Black Cloud EDR watchlists for consistent detection content?

Structure Carbon Black Cloud EDR watchlists by identifying the target surface, crafting a report with valid CBC query syntax, and mapping events to MITRE tactics. This ensures consistent alert semantics and proper sensor tier coverage across Windows, macOS, and Linux.

What is the difference between CBC watchlists and scheduled searches when configuring Enterprise EDR?

CBC watchlists and scheduled searches are distinct EDR surfaces. Watchlists monitor continuous IOC matches for alert generation, while scheduled searches run queries at intervals to document historical detection events and report specific telemetry.

How do I map MITRE tactics to Carbon Black Cloud detection content?

Map MITRE tactics to Carbon Black Cloud detection content by aligning CBC event taxonomy and query syntax with specific adversary techniques. This documents alert semantics and establishes sensor capability boundaries for OpenTide MDR configurations.

Does Carbon Black Cloud Enterprise EDR detection content support Windows, macOS, and Linux sensors?

Carbon Black Cloud Enterprise EDR detection content supports Windows, macOS, and Linux sensors. Detection authoring must document sensor tier considerations and capability boundaries to ensure queries target the correct telemetry across all operating systems.

What are the limitations of Carbon Black Cloud Live Response for detection content authoring?

Carbon Black Cloud Live Response is a distinct surface with specific sensor capability boundaries. It focuses on remote remediation rather than scheduled searches or watchlists, requiring dedicated instrumentation and tier considerations for MDR configurations.