11[metadata ]
22creation_date = " 2020/11/18"
3- integration = [" endpoint" , " windows" , " system" , " m365_defender" , " sentinel_one_cloud_funnel" ]
3+ integration = [" endpoint" , " windows" , " system" , " m365_defender" , " sentinel_one_cloud_funnel" , " crowdstrike " ]
44maturity = " production"
5- updated_date = " 2024/10/15 "
5+ updated_date = " 2024/10/31 "
66min_stack_version = " 8.14.0"
77min_stack_comments = " Breaking change at 8.14.0 for the Windows Integration."
88
@@ -23,6 +23,7 @@ index = [
2323 " logs-system.security*" ,
2424 " logs-m365_defender.event-*" ,
2525 " logs-sentinel_one_cloud_funnel.*" ,
26+ " logs-crowdstrike.fdr*" ,
2627]
2728language = " eql"
2829license = " Elastic License v2"
@@ -41,13 +42,17 @@ tags = [
4142 " Data Source: Microsoft Defender for Endpoint" ,
4243 " Data Source: Sysmon" ,
4344 " Data Source: SentinelOne" ,
45+ " Data Source: Crowdstrike" ,
4446]
4547timestamp_override = " event.ingested"
4648type = " eql"
4749
4850query = '''
4951process where host.os.type == "windows" and event.type == "start" and
50- process.executable : "C:\\*Program*Files*\\*.exe" and
52+ process.executable : (
53+ "C:\\*Program*Files*\\*.exe",
54+ "\\Device\\HarddiskVolume?\\*Program*Files*\\*.exe"
55+ ) and
5156 not process.executable : (
5257 "?:\\Program Files\\*.exe",
5358 "?:\\Program Files (x86)\\*.exe",
@@ -56,6 +61,18 @@ process where host.os.type == "windows" and event.type == "start" and
5661 "?:\\Windows\\Downloaded Program Files\\*.exe",
5762 "?:\\Windows\\Temp\\.opera\\????????????\\CProgram?FilesOpera*\\*.exe",
5863 "?:\\Windows\\Temp\\.opera\\????????????\\CProgram?Files?(x86)Opera*\\*.exe"
64+ ) and
65+ not (
66+ event.dataset == "crowdstrike.fdr" and
67+ process.executable : (
68+ "\\Device\\HarddiskVolume?\\Program Files\\*.exe",
69+ "\\Device\\HarddiskVolume?\\Program Files (x86)\\*.exe",
70+ "\\Device\\HarddiskVolume?\\Users\\*.exe",
71+ "\\Device\\HarddiskVolume?\\ProgramData\\*.exe",
72+ "\\Device\\HarddiskVolume?\\Windows\\Downloaded Program Files\\*.exe",
73+ "\\Device\\HarddiskVolume?\\Windows\\Temp\\.opera\\????????????\\CProgram?FilesOpera*\\*.exe",
74+ "\\Device\\HarddiskVolume?\\Windows\\Temp\\.opera\\????????????\\CProgram?Files?(x86)Opera*\\*.exe"
75+ )
5976 )
6077'''
6178
0 commit comments