Skip to content

crowdstrike/fdr: Support SSL Certificate-related events #3485

@adriansr

Description

@adriansr

Crowdstrike integration / fdr data_stream does not enrich events related to SSL Certificates. We should add support to these.

Example event:

{
  "eid": 118,
  "IssuerCN": "GlobalSign ObjectSign CA",
  "CustomerIdString": "f3011c6076444fbedffa8472f8aaaaa",
  "EventType": "Event_ExternalApiEvent",
  "SubjectCertValidTo": "2008-09-24T10:50:55Z",
  "SignInfoFlagUnknownError": false,
  "SubjectVersion": "3",
  "UTCTimestamp": 1653626693230,
  "AuthorityKeyIdentifier": "ffffffffeeeeeeeeeddddddddccccccceaaaaaaaa",
  "SubjectDN": "CN=Testing Testing,C=JP,1.2.999.999999.1.9.1=#ffffffffeeeeeeeeddddddddccccccccbbbbbbbbaaaaaaaaaa",
  "SignatureDigestEncryptAlg": "RSA",
  "SignInfoFlagHasValidSignature": true,
  "AuthenticodeHashData": "ffffffffffffffffffffffffffffffffffffffff",
  "SignInfoFlagSignHashMismatch": false,
  "AuthenticodeMatch": true,
  "SignInfoFlagMicrosoftSigned": false,
  "SignInfoFlagNoSignature": false,
  "SubjectSerialNumber": "115372fffff",
  "timestamp": "2022-05-27T04:44:53Z",
  "SignInfoFlagInvalidSignChain": false,
  "IssuerDN": "CN=GlobalSign ObjectSign CA,OU=ObjectSign CA,O=GlobalSign nv-sa,C=BE",
  "SignatureDigestAlg": "SHA1-RSA",
  "SignInfoFlagNoCodeKeyUsage": false,
  "SHA256HashData": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
  "SubjectKeyIdentifier": "",
  "SubjectCN": "Testing Testing",
  "ExternalApiType": "Event_ModuleSummaryInfoEvent",
  "SignInfoFlagNoEmbeddedCert": false,
  "Nonce": 1202666347322065700,
  "SignInfoFlagThirdPartyRoot": false,
  "SubjectCertThumbprint": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
  "SignInfoFlagCatalogSigned": false,
  "SignInfoFlagSelfSigned": false,
  "SignInfoFlagFailedCertCheck": false,
  "AgentIdString": "99999999999999999999999999999999",
  "SubjectCertValidFrom": "2007-09-24T10:50:55Z",
  "SignInfoFlagEmbeddedSigned": true,
  "cid": "11111111111111111111111111111111"
}

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions