Skip to content

Commit

Permalink
Create definition.json for Crowdstrike report
Browse files Browse the repository at this point in the history
  • Loading branch information
akshayjain-1 authored Nov 20, 2023
1 parent ca371d4 commit feeaa60
Showing 1 changed file with 53 additions and 0 deletions.
53 changes: 53 additions & 0 deletions objects/crowdstrike-report/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
{
"attributes": {
"filename": {
"description": "Filename on disk",
"disable_correlation": true,
"misp-attribute": "filename",
"multiple": true,
"ui-priority": 1
},
"fullpath": {
"description": "Complete path of the filename including the filename",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 0
},
"process-name": {
"description": "Name of the process trigerring the detection",
"misp-attribute": "text",
"multiple": true,
"ui-priority": 1
},
"parent-command": {
"description": "Commandline of the parent process",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 1
},
"command": {
"description": "Commandline triggering the detection",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 1
},
"file-hash": {
"description": "Unique file hash",
"misp-attribute": "text",
"ui-priority": 1
},
"ip": {
"description": "Source IP address",
"misp-attribute": "ip-src",
"ui-priority": 1
}
},
"description": "An Object Template to encode an Crowdstrike detection report",
"meta-category": "misc",
"name": "crowdstrike-report",
"uuid": "805b327c-8f1b-4d76-a3ba-c8bc4964e740",
"version": 1
}

0 comments on commit feeaa60

Please sign in to comment.