Skip to content

Commit ed9b5c6

Browse files
committed
gis-8397 add CarbonBlack render
1 parent 8ea81ff commit ed9b5c6

23 files changed

+364
-14
lines changed
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
platform: CarbonBlack
2+
source: default
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: linux_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: linux_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: macos_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: macos_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
platform: CarbonBlack
2+
source: windows_create_remote_thread
3+
4+
5+
field_mapping:
6+
SourceImage: parent_name
7+
StartModule: modload_name
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_file_event
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
platform: CarbonBlack
2+
source: windows_image_load
3+
4+
5+
field_mapping:
6+
OriginalFileName: process_original_filename
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: windows_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy