-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CrowdStrike Falcon - Raptor release #34805
Merged
RosenbergYehuda
merged 87 commits into
master
from
YR-CrowdStrike-Falcon-Raptor/CIAC-9887
Jul 11, 2024
Merged
Changes from 85 commits
Commits
Show all changes
87 commits
Select commit
Hold shift + click to select a range
accd1b5
configuration changes
RosenbergYehuda 5d30e11
rn
RosenbergYehuda ba1e232
deprecation
RosenbergYehuda 0447dd9
readme deprecation
RosenbergYehuda aa017ff
resolve-identity-detection
RosenbergYehuda 1a8b23d
test
RosenbergYehuda 7520e35
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 5675e36
fix conflict
RosenbergYehuda b4efe1e
cs-falcon-search-detection
RosenbergYehuda 3a97c14
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda a94484f
unit test
RosenbergYehuda d852e21
!cs-falcon-resolve-detection
RosenbergYehuda 45481d0
cs-falcon-list-detection-summaries
RosenbergYehuda fb1af8b
fix the filter
RosenbergYehuda 8e52c1a
fix
RosenbergYehuda e2e2273
fix tests
RosenbergYehuda e4f0f10
fixes
RosenbergYehuda 1758e32
fix
RosenbergYehuda 30365fb
add CrowdStrike.Detections.behaviors.behavior_id
RosenbergYehuda 7a256da
fix outputs of list-detection-summaries
RosenbergYehuda eda32f1
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 20c776a
finally outputs for cs-falcon-list-detection-summaries
RosenbergYehuda 86c1bc7
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda e93c508
test
RosenbergYehuda fa1118d
fetch
RosenbergYehuda 758d33e
mirroring
RosenbergYehuda d9ce66e
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda ea3f287
existing fetch
RosenbergYehuda 8a2d434
new fetch
RosenbergYehuda 4dec9d2
add tests
RosenbergYehuda fc282cc
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 2787993
revert unnecessary changes in the mapper
RosenbergYehuda a9f773e
fix the query
RosenbergYehuda 2530096
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 23035a8
fix
RosenbergYehuda 962bceb
fis tests
RosenbergYehuda 210aad9
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 35d7d80
last mapper
RosenbergYehuda b3a3025
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 3f9abc3
fix mapper
RosenbergYehuda 4f94799
mirroring of new type
RosenbergYehuda 509d4e4
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 9b4b1a5
fixes from cr
RosenbergYehuda 4b7b7cf
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 30f49af
fix
RosenbergYehuda 948659f
remove the raptor from the tests
RosenbergYehuda 44195a2
fix tests
RosenbergYehuda abd70fa
fixes
RosenbergYehuda 4a80dcd
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 66c347d
fix old mapper
RosenbergYehuda b0c6780
legacy
RosenbergYehuda efaa0a1
RN
RosenbergYehuda cb2152e
rn
RosenbergYehuda 319e6de
metadata
RosenbergYehuda eecabca
pre commit
RosenbergYehuda 13c4685
build fixes
RosenbergYehuda 996460c
build fixes #2
RosenbergYehuda cf90121
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda e0df48b
Apply suggestions from code review
RosenbergYehuda 07bfeb9
More from Shirley
RosenbergYehuda 2184ab0
cr
RosenbergYehuda dbaf0be
Merge branch 'YR-CrowdStrike-Falcon-Raptor/CIAC-9887' of https://gith…
RosenbergYehuda e09fce0
cr
RosenbergYehuda c77c0e2
format
RosenbergYehuda eadff64
adding testing the parameters
RosenbergYehuda dbcddf7
Merged master into current branch.
dbfa58a
Bump pack from version CommonTypes to 3.5.8.
e067253
fix test
RosenbergYehuda 5b55631
cr
RosenbergYehuda 6bea61d
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 9b2d15d
logs
RosenbergYehuda f6add2d
fix a mistake
RosenbergYehuda 3f5c2e0
pre commit
RosenbergYehuda 1cd7138
RN
RosenbergYehuda 3775d38
fix rn
RosenbergYehuda 08ce4ec
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 5e539f8
fix rn
RosenbergYehuda 7a33286
fix validate errors
RosenbergYehuda 250b6ba
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda b350618
fix test playbook
RosenbergYehuda f1dd3fc
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 9d1cf27
pre commit
RosenbergYehuda 15249b5
format
RosenbergYehuda 2a4a962
RN
RosenbergYehuda c54ee77
Merge remote-tracking branch 'origin' into YR-CrowdStrike-Falcon-Rapt…
RosenbergYehuda 6ce4786
change output
RosenbergYehuda 63803c1
fix test playbook
RosenbergYehuda File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
|
||
#### Incident Fields | ||
|
||
##### Display Name | ||
|
||
Added the `CrowdStrike Falcon On-Demand Scans Detection` incident type as an associated type. | ||
##### Last Update Time | ||
|
||
Added the `CrowdStrike Falcon On-Demand Scans Detection` incident type as an associated type. | ||
##### Vendor Product | ||
|
||
Added the `CrowdStrike Falcon On-Demand Scans Detection` incident type as an associated type. | ||
##### Device Id | ||
|
||
Added the `CrowdStrike Falcon On-Demand Scans Detection` incident type as an associated type. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it true for all the CS types?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Joining this question - is that the new ID for each fetched event/incident?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We had 3 detection types to fetch:
Endpoint Detection IDP Detection had changed to use "composite_id". and i changed the mapper.
Mobile Detection did not change to composite_id, so i did not modify its mapper.