In the Carbon Black EDR console, you can toggle the collection of AMSI events per sensor group. This is disabled by default.

Procedure

  1. On the left navigation bar, click Sensors.
  2. Select the sensor group.
  3. n the Event Collection Settings section, select the checkbox for Fileless script loads.
    cbr-sensor-groups-amsi
  4. Click Save Group.
    See "Sensor Groups" in the VMware Carbon Black EDR User Guide.