Skip to content

Commit 1a50cff

Browse files
authored
Merge pull request #224 from UncoderIO/gis-8397_ref
Gis 8397 Add CarbonBlack render
2 parents 8ea81ff + bb73730 commit 1a50cff

24 files changed

+364
-102
lines changed

uncoder-core/app/routers/meta_info.py

Lines changed: 0 additions & 88 deletions
This file was deleted.
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
platform: CarbonBlack
2+
source: default
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: linux_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: linux_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: macos_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
platform: CarbonBlack
2+
source: macos_network_connection
3+
4+
5+
field_mapping:
6+
DestinationHostname:
7+
- netconn_domain
8+
- netconn_proxy_domain
9+
DestinationPort: netconn_port
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
platform: CarbonBlack
2+
source: windows_create_remote_thread
3+
4+
5+
field_mapping:
6+
SourceImage: parent_name
7+
StartModule: modload_name
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_dns_query
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
platform: CarbonBlack
2+
source: windows_file_event
3+
4+
5+
field_mapping:
6+
User:
7+
- childproc_username
8+
- process_username
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
platform: CarbonBlack
2+
source: windows_image_load
3+
4+
5+
field_mapping:
6+
OriginalFileName: process_original_filename

0 commit comments

Comments
 (0)