-
Notifications
You must be signed in to change notification settings - Fork 558
crowdstrike/fdr: Support SSL Certificate-related events #3485
Copy link
Copy link
Closed
Labels
Integration:crowdstrikeCrowdStrikeCrowdStrikeStalledenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is needed
Description
Crowdstrike integration / fdr data_stream does not enrich events related to SSL Certificates. We should add support to these.
Example event:
{
"eid": 118,
"IssuerCN": "GlobalSign ObjectSign CA",
"CustomerIdString": "f3011c6076444fbedffa8472f8aaaaa",
"EventType": "Event_ExternalApiEvent",
"SubjectCertValidTo": "2008-09-24T10:50:55Z",
"SignInfoFlagUnknownError": false,
"SubjectVersion": "3",
"UTCTimestamp": 1653626693230,
"AuthorityKeyIdentifier": "ffffffffeeeeeeeeeddddddddccccccceaaaaaaaa",
"SubjectDN": "CN=Testing Testing,C=JP,1.2.999.999999.1.9.1=#ffffffffeeeeeeeeddddddddccccccccbbbbbbbbaaaaaaaaaa",
"SignatureDigestEncryptAlg": "RSA",
"SignInfoFlagHasValidSignature": true,
"AuthenticodeHashData": "ffffffffffffffffffffffffffffffffffffffff",
"SignInfoFlagSignHashMismatch": false,
"AuthenticodeMatch": true,
"SignInfoFlagMicrosoftSigned": false,
"SignInfoFlagNoSignature": false,
"SubjectSerialNumber": "115372fffff",
"timestamp": "2022-05-27T04:44:53Z",
"SignInfoFlagInvalidSignChain": false,
"IssuerDN": "CN=GlobalSign ObjectSign CA,OU=ObjectSign CA,O=GlobalSign nv-sa,C=BE",
"SignatureDigestAlg": "SHA1-RSA",
"SignInfoFlagNoCodeKeyUsage": false,
"SHA256HashData": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"SubjectKeyIdentifier": "",
"SubjectCN": "Testing Testing",
"ExternalApiType": "Event_ModuleSummaryInfoEvent",
"SignInfoFlagNoEmbeddedCert": false,
"Nonce": 1202666347322065700,
"SignInfoFlagThirdPartyRoot": false,
"SubjectCertThumbprint": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"SignInfoFlagCatalogSigned": false,
"SignInfoFlagSelfSigned": false,
"SignInfoFlagFailedCertCheck": false,
"AgentIdString": "99999999999999999999999999999999",
"SubjectCertValidFrom": "2007-09-24T10:50:55Z",
"SignInfoFlagEmbeddedSigned": true,
"cid": "11111111111111111111111111111111"
}Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Integration:crowdstrikeCrowdStrikeCrowdStrikeStalledenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is needed
Type
Fields
Give feedbackNo fields configured for issues without a type.