File tree Expand file tree Collapse file tree 9 files changed +96
-0
lines changed
uncoder-core/app/translator
mappings/platforms/sentinel_one Expand file tree Collapse file tree 9 files changed +96
-0
lines changed Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : default
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : dns
3+
4+ field_mapping :
5+ Image : src.process.image.path
6+ CommandLine : src.process.cmdline
7+ ParentImage : src.process.parent.image.path
8+ ParentCommandLine : src.process.parent.cmdline
9+ query : event.dns.request
10+ answer : event.dns.response
11+ QueryName : event.dns.request
12+ record_type : event.dns.response
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : linux_file_event
3+
4+ field_mapping :
5+ Image : src.process.image.path
6+ CommandLine : src.process.cmdline
7+ ParentImage : src.process.parent.image.path
8+ ParentCommandLine : src.process.parent.cmdline
9+ TargetFilename : tgt.file.path
10+ SourceFilename : tgt.file.oldPath
11+ User : src.process.use
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : windows_image_load
3+
4+ field_mapping :
5+ Image : Image
6+ ImageLoaded : ImageLoaded
7+ SignatureStatus : SignatureStatus
8+ OriginalFileName : OriginalFileName
9+ Signed : Signed
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : windows_network_connection
3+
4+ field_mapping :
5+ Image : src.process.image.path
6+ CommandLine : src.process.cmdline
7+ ParentImage : src.process.parent.image.path
8+ ParentCommandLine : src.process.parent.cmdline
9+ DestinationHostname :
10+ - url.address
11+ - event.dns.request
12+ DestinationPort : dst.port.number
13+ DestinationIp : dst.ip.address
14+ User : src.process.user
15+ SourceIp : src.ip.address
16+ SourcePort : src.port.number
17+ Protocol : NetProtocolName
18+ dst_ip : dst.ip.address
19+ src_ip : src.ip.address
20+ dst_port : dst.port.number
21+ src_port : src.port.number
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : windows_pipe_created
3+
4+ field_mapping :
5+ PipeName : namedPipe.name
6+ Image : src.process.image.path
7+ CommandLine : src.process.cmdline
8+ ParentImage : src.process.parent.image.path
9+ ParentCommandLine : src.process.parent.cmdline
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : windows_process_creation
3+
4+ field_mapping :
5+ ProcessId : tgt.process.pid
6+ Image : tgt.process.image.path
7+ Description : tgt.process.displayName
8+ Publisher : tgt.process.publisher
9+ Product : tgt.process.displayName
10+ Company : tgt.process.publisher
11+ CommandLine : tgt.process.cmdline
12+ CurrentDirectory : tgt.process.image.path
13+ User : tgt.process.user
14+ TerminalSessionId : tgt.process.sessionid
15+ IntegrityLevel : tgt.process.integrityLevel
16+ md5 : tgt.process.image.md5
17+ sha1 : tgt.process.image.sha1
18+ sha256 : tgt.process.image.sha256
19+ ParentProcessId : src.process.pid
20+ ParentImage : src.process.image.path
21+ ParentCommandLine : src.process.cmdline
Original file line number Diff line number Diff line change 1+ platform : Sentinel One Power Query
2+ source : windows_registry_event
3+
4+ field_mapping :
5+ Image : src.process.image.path
6+ CommandLine : src.process.cmdline
7+ ParentImage : src.process.parent.image.path
8+ ParentCommandLine : src.process.parent.cmdline
9+ TargetObject : registry.keyPath
10+ Details : registry.value
Original file line number Diff line number Diff line change 1818}
1919
2020sentinel_one_events_query_details = PlatformDetails (** SENTINEL_ONE_EVENTS_QUERY_DETAILS )
21+ sentinel_one_power_query_details = PlatformDetails (** SENTINEL_ONE_POWER_QUERY_DETAILS )
You can’t perform that action at this time.
0 commit comments