Skip to content

Commit 1a50cff

Browse files
authored
Merge pull request #224 from UncoderIO/gis-8397_ref
Gis 8397 Add CarbonBlack render
2 parents 8ea81ff + bb73730 commit 1a50cff

24 files changed

+364
-102
lines changed

uncoder-core/app/routers/meta_info.py

Lines changed: 0 additions & 88 deletions
This file was deleted.
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
platform: CarbonBlack
2+
source: default
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: linux_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: linux_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: macos_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: macos_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
platform: CarbonBlack
2+
source: windows_create_remote_thread
3+
4+
5+
field_mapping:
6+
SourceImage: parent_name
7+
StartModule: modload_name
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_file_event
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
platform: CarbonBlack
2+
source: windows_image_load
3+
4+
5+
field_mapping:
6+
OriginalFileName: process_original_filename

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy