In the Carbon Black EDR console, you can toggle the collection of fileless script load events per sensor group. This is disabled by default.

Procedure

  1. On the left navigation bar, click Sensors.
  2. Select the sensor group.
  3. In the Event Collection Settings section, select the checkbox for Fileless script loads.
    cbr-sensor-groups-amsi
  4. Click Save Group.