In the Carbon Black EDR Console, you can toggle the collection of AMSI events per sensor group. This is disabled by default.
To enable AMSI events for a sensor group:
-
On the navigation bar, click Sensors.
-
Select the sensor group.
-
In the Event Collection Settings section, select the checkbox for Fileless script loads.
-
Click Save Group.
See also "Sensor Groups" in the VMware Carbon Black EDR User Guide.