It is designed to work alongside the Carbon Black web interface to aid in searching and bulk analysis of data, providing a fast and effective means of querying and filtering results. After months of development and success on incident response engagements, we believe the tool is mature enough to be released to the wider community.
Designed to be accessible to people of all technical abilities and backgrounds, CbRCLI provides powerful suggestion and autocompletion functionality through the excellent prompt_toolkit library to speed up analysis and reduce typing mistakes. Data is displayed in a tabular format, allowing the user to specify the fields they are interested in, speeding up analysis time and improving efficiency.
For more information, including installation and usage instructions with examples, see the project github page at github.com/ctxis/cbrcli.
The video below shows a quick overview of some of the functionality available in CbRCLI.