pySigma CrowdStrike processing pipelines
Project description
pySigma CrowdStrike Processing Pipeline
This package provides a processing pipeline for CrowdStrike events. It was mainly written for Falcon Data Replicator data but Splunk queries should also work in the CrowdStrike Splunk.
It provides the package sigma.pipeline.crowdstrike
with the crowdstrike_fdr_pipeline
function that returns a ProcessingPipeline object.
Currently the pipeline adds support for the following event types (Sigma logsource category to event_simpleName mapping):
- process_creation: ProcessRollup2
- Only rules with references to the file name of the parent image are supported because CrowdStrike ProcessRollup2 events only contain the file name.
- network_connection: NetworkConnectionIP4 or NetworkReceiveAcceptIP4 (depending on Initiated field value)
- events that refer to process image names are not supported because this information is not available in CrowdStrike network connection events, just a process id reference.
Not supported because the FDR events lack information required by Sigma rules:
- create_remote_thread: event lack information required by most rules. No process details, only reference.
This backend is currently maintained by:
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Close
Hashes for pysigma_pipeline_crowdstrike-1.0.3.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | a50d4f17defc7346264f5091d439146d78d5da0ae4df1a858d0ce61f618419a6 |
|
MD5 | 77e4322fcd3f348218f961e9af0907a0 |
|
BLAKE2b-256 | 7a39102baf4ba0dcf5d6767cafaf34b64b1a6c43cb85a6ffcc025b71d797d5f6 |
Close
Hashes for pysigma_pipeline_crowdstrike-1.0.3-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 2f4b60253e3e6b8baea69b86ea85923bfe5c550f27664c790b00d41865cc42af |
|
MD5 | dfd1b97e0c1887a864deca9a414d2eba |
|
BLAKE2b-256 | ed1504ba0b22304b62297e6de0c88b93363610d055f29a15f29ed268d68b5b34 |