OCTOBER 5 - 7, 2021
d :: h :: m :: s

KUBERNETES

CODE 2782: Automating Ransomware Remediation with the VMware Carbon Black Cloud SDK

October 5, 2021 | 3:05 PM PDT

Are you prepared for the next Ransomware attack? With our Next Generation Anti-Virus and Behavioral EDR in the VMware Carbon Black Cloud, you can feel confident that your employees and sensitive infrastructure will be better protected. The VMware Carbon Black Cloud will help block known malicious behavior and alert you to the incident in order for your security team to step in and clean up the mess. The process a security team member steps through tends to be manual and may require verifying if the deleted files are present on any other machines in your infrastructure. With the Carbon Black Cloud Python SDK, you can automate and script default actions to collect the events associated with the alert, quarantine the device, use Live Response to delete the known malware, and verify with Live Query that the malware is not present on any other devices.

SEE SESSION

Alex Van Brunt

Senior Software Engineer, VMware

Alex Van Brunt is a Senior Software Engineer on the Developer Relations team at VMware Carbon Black. Alex has been interacting with developers through open source repos and the past virtual conferences in order to provide useful tools and resources for developers to integrate with the Carbon Black Cloud. Alex uses the feedback from external developers to help drive new APIs and features continually improving the Carbon Black Cloud


Emanuela Mitreva

Software Developer, VMware