-
Notifications
You must be signed in to change notification settings - Fork 232
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Process unique ID #1051
Process unique ID #1051
Conversation
stix_shifter_modules/qradar/stix_translation/json/to_stix_map.json
Outdated
Show resolved
Hide resolved
This reverts commit 5292430.
…ityalliance/stix-shifter into process-unique-id
Codecov Report
@@ Coverage Diff @@
## develop #1051 +/- ##
===========================================
- Coverage 64.77% 64.76% -0.01%
===========================================
Files 518 518
Lines 48841 48835 -6
===========================================
- Hits 31637 31629 -8
- Misses 17204 17206 +2
Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here. |
Awesome! Thanks @delliott90 and @pcoccoli ! This is an important feature that helps cross-observation/query reasoning. Kestrel will upgrade with this feature for better process identification. |
Partially addresses this issue: #922 by adding
process.x_unique_id
to QRadar, Elastic ECS, CB Cloud, ReaQta, and Sentinel One.