Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CrowdStrike Event Streams Passthrough Rule #1442

Merged
merged 4 commits into from
Dec 6, 2024

Conversation

ben-githubs
Copy link
Contributor

Background

Now that CrowdStrke has resolved issues with their Go SDK, we can reliable and accurately ingest EppDetectionSummaryEvent logs. This PR includes a rule to raise such events as alerts in Panther.

Changes

  • add new rule Crowdstrike.EppDetectionSummary
  • update PantherManaged.CrowdstrikeEventStreams to include new rule

Testing

  • 5 unit tests based on genuine data

@ben-githubs ben-githubs requested a review from a team as a code owner December 3, 2024 20:50
@arielkr256 arielkr256 added the rules Real-time log data detections label Dec 4, 2024
@arielkr256 arielkr256 enabled auto-merge (squash) December 6, 2024 15:57
@arielkr256 arielkr256 merged commit 9ef96a8 into develop Dec 6, 2024
8 checks passed
@arielkr256 arielkr256 deleted the THREAT-311/cs_eventstreams_passthrough branch December 6, 2024 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
rules Real-time log data detections
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants