Skip to content

Commit

Permalink
cloudtrail mappings
Browse files Browse the repository at this point in the history
Signed-off-by: Grant Haywood <grant@phaseshift.studio>
  • Loading branch information
phaseshiftg committed Nov 4, 2022
1 parent 11ea55a commit d3c382d
Show file tree
Hide file tree
Showing 2 changed files with 31 additions and 10 deletions.
13 changes: 7 additions & 6 deletions src/main/resources/OSMapping/cloudtrail/fieldmappings.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# this file provides pre-defined mappings for Sigma fields defined for all Sigma rules under windows log group to their corresponding ECS Fields.
fieldmappings:
EventID: event_uid
HiveName: unmapped.HiveName
fieldB: mappedB
fieldA1: mappedA
CommandLine: windows-event_data-CommandLine
eventName: aws-cloudtrail-event_type
eventSource: eventSource
requestParameters: aws-cloudtrail-request_parameters
requestParameters-containerDefinitions-command: aws-cloudtrail-request_parameters-container-definitions-command
userIdentity: aws-cloudtrail-user_identity
userIdentity-sessionContext-sessionIssuer-type: aws-cloudtrail-user_identity-session_context-session_issuer-type
userIdentity-type: aws-cloudtrail-user_identity-type
28 changes: 24 additions & 4 deletions src/main/resources/OSMapping/cloudtrail/mappings.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,32 @@
{
"properties": {
"windows-event_data-CommandLine": {
"eventName": {
"type": "alias",
"path": "CommandLine"
"path": "aws-cloudtrail-event_type"
},
"event_uid": {
"eventSource": {
"type": "alias",
"path": "EventID"
"path": "eventSource"
},
"requestParameters": {
"type": "alias",
"path": "aws-cloudtrail-request_parameters"
},
"requestParameters-containerDefinitions-command": {
"type": "alias",
"path": "aws-cloudtrail-request_parameters-container-definitions-command"
},
"userIdentity": {
"type": "alias",
"path": "aws-cloudtrail-user_identity"
},
"userIdentity-sessionContext-sessionIssuer-type": {
"type": "alias",
"path": "aws-cloudtrail-user_identity-session_context-session_issuer-type"
},
"userIdentity-type": {
"type": "alias",
"path": "aws-cloudtrail-user_identity-type"
}
}
}

0 comments on commit d3c382d

Please sign in to comment.