You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For the OpenBAS implant we create just one signature: EXPECTATION_SIGNATURE_TYPE_PARENT_PROCESS_NAME.
And for Caldera implant we create multiple signatures depending on the payload type (command line, drop file, ect).
We currently have detection issues with a caldera implant and Crowdstrike collector. So we need to use EXPECTATION_SIGNATURE_TYPE_PARENT_PROCESS_NAME for Caldera Implant as well.
The text was updated successfully, but these errors were encountered:
RomuDeuxfois
added
bug
use for describing something not working as expected
needs triage
use to identify issue needing triage from Filigran Product team
labels
Jan 31, 2025
Description
For the OpenBAS implant we create just one signature: EXPECTATION_SIGNATURE_TYPE_PARENT_PROCESS_NAME.
And for Caldera implant we create multiple signatures depending on the payload type (command line, drop file, ect).
We currently have detection issues with a caldera implant and Crowdstrike collector. So we need to use EXPECTATION_SIGNATURE_TYPE_PARENT_PROCESS_NAME for Caldera Implant as well.
The text was updated successfully, but these errors were encountered: