Skip to content

Commit ed9b5c6

Browse files
committed
gis-8397 add CarbonBlack render
1 parent 8ea81ff commit ed9b5c6

23 files changed

+364
-14
lines changed
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
platform: CarbonBlack
2+
source: default
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: linux_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: linux_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: macos_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: macos_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
platform: CarbonBlack
2+
source: windows_create_remote_thread
3+
4+
5+
field_mapping:
6+
SourceImage: parent_name
7+
StartModule: modload_name
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_file_event
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
platform: CarbonBlack
2+
source: windows_image_load
3+
4+
5+
field_mapping:
6+
OriginalFileName: process_original_filename
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: windows_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port

0 commit comments

Comments
 (0)