Skip to content

Releases: 7RedViolin/pySigma-backend-cortexxdr

v0.1.4

24 Aug 17:10
b86f571
Compare
Choose a tag to compare

What's Changed

  • Fix for backend & pipeline crash with recent pySigma versions by @jgubler in #16

Full Changelog: v0.1.3...v0.1.4

v0.1.3

28 Mar 13:39
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.1.2...v0.1.3

v0.1.2

10 Nov 02:15
c94d905
Compare
Choose a tag to compare

What's Changed

  • Update dependencies to support pySigma 0.10.X by @7RedViolin in #7

Full Changelog: v0.1.1...v0.1.2

v0.1.1

24 Jul 20:27
5915375
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.1.0...v0.1.1

Initial Release

01 Jul 16:30
Compare
Choose a tag to compare

General

First release of pysigma-backend-cortexxdr.

Backend

  • Output formats include plaintext and JSON (includes query and rule metadata)
  • Uses Cortex XDR XQL syntax

Pipelines

  • Supports linux, windows, and macos product types
  • Supports the following category types for field mappings
    • process_creation
    • file_event
    • file_change
    • file_rename
    • file_delete
    • image_load
    • registry_add
    • registry_delete
    • registry_event
    • registry_set
    • network_connection
    • firewall
      Any unsupported fields or categories will throw errors