
Jul 21, 2026
2.0.0
ThreatQ Versions >= 4.25.0
VMware Carbon Black Cloud Platform Alerts
Overview
The VMware Carbon Black Cloud Platform Alerts CDF enables ThreatQ to ingest Carbon Black Cloud Platform v7 alerts directly into ThreatQ as Incident objects. During ingestion, the integration automatically extracts and relates associated indicators, MITRE ATT&CK attack patterns, and TTPs, providing analysts with enriched context to support investigation and response.
The integration provides the following feed:
- VMWare Carbon Black Cloud Platform Alerts - ingests VMware Carbon Black Cloud alerts as Incident objects and automatically extracts and relates associated indicators, MITRE ATT&CK attack patterns, and TTPs within ThreatQ.
The integration ingests the following system objects:
- Attack Patterns
- Incidents
- Incident Attributes
- Indicators
- Indicators Attributes
- TTPs