feat(sentinelone): re-model OCSF mappers to actor/target semantics

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Guillaume BOURGEOIS
2026-06-26 13:20:35 +02:00
parent 24e8c652ac
commit 1157735be1
3 changed files with 55 additions and 42 deletions
@@ -1,5 +1,5 @@
name: "SentinelOne Alerts → OCSF"
description: "Maps a SentinelOne v2.1 cloud-detection alert object (data[]) to OCSF endpoint/file/process/rule fields."
description: "Maps a SentinelOne v2.1 cloud-detection alert object (data[]) to OCSF. The initiating (source) process is the actor (actor.*); the process/file acted upon is the target (process.*/file.*)."
field_mappings:
title: "ruleInfo.name"
severity: "ruleInfo.severity = 'Critical' ? 5 : (ruleInfo.severity = 'High' ? 4 : 3)"
@@ -18,17 +18,28 @@ ocsf:
- { source_path: "ruleInfo.description", ocsf_field: "rule.desc" }
- { source_path: "alertInfo.alertId", ocsf_field: "finding_info.uid" }
- { source_path: "alertInfo.dvEventId", ocsf_field: "metadata.original_event_uid" }
# Source process
- { source_path: "sourceProcessInfo.name", ocsf_field: "process.name" }
- { source_path: "sourceProcessInfo.pid", ocsf_field: "process.pid" }
- { source_path: "sourceProcessInfo.filePath", ocsf_field: "process.file.path" }
- { source_path: "sourceProcessInfo.commandline", ocsf_field: "process.cmd_line" }
- { source_path: "sourceProcessInfo.user", ocsf_field: "process.user.name" }
- { source_path: "sourceProcessInfo.integrityLevel", ocsf_field: "process.integrity" }
- { source_path: "sourceProcessInfo.fileHashSha256", ocsf_field: "file.hashes.sha256" }
- { source_path: "sourceProcessInfo.fileHashSha1", ocsf_field: "file.hashes.sha1" }
- { source_path: "sourceProcessInfo.fileHashMd5", ocsf_field: "file.hashes.md5" }
# Parent process
- { source_path: "sourceParentProcessInfo.name", ocsf_field: "process.parent_process.name" }
- { source_path: "sourceParentProcessInfo.pid", ocsf_field: "process.parent_process.pid" }
- { source_path: "sourceParentProcessInfo.commandline", ocsf_field: "process.parent_process.cmd_line" }
# Initiating (source) process — the actor
- { source_path: "sourceProcessInfo.name", ocsf_field: "actor.process.name" }
- { source_path: "sourceProcessInfo.pid", ocsf_field: "actor.process.pid" }
- { source_path: "sourceProcessInfo.filePath", ocsf_field: "actor.process.file.path" }
- { source_path: "sourceProcessInfo.commandline", ocsf_field: "actor.process.cmd_line" }
- { source_path: "sourceProcessInfo.user", ocsf_field: "actor.user.name" }
- { source_path: "sourceProcessInfo.integrityLevel", ocsf_field: "actor.process.integrity" }
- { source_path: "sourceProcessInfo.fileHashSha256", ocsf_field: "actor.process.file.hashes.sha256" }
- { source_path: "sourceProcessInfo.fileHashSha1", ocsf_field: "actor.process.file.hashes.sha1" }
- { source_path: "sourceProcessInfo.fileHashMd5", ocsf_field: "actor.process.file.hashes.md5" }
# Parent of the source process
- { source_path: "sourceParentProcessInfo.name", ocsf_field: "actor.process.parent_process.name" }
- { source_path: "sourceParentProcessInfo.pid", ocsf_field: "actor.process.parent_process.pid" }
- { source_path: "sourceParentProcessInfo.commandline", ocsf_field: "actor.process.parent_process.cmd_line" }
# Target process — the process acted upon
- { source_path: "targetProcessInfo.tgtProcName", ocsf_field: "process.name" }
- { source_path: "targetProcessInfo.tgtProcPid", ocsf_field: "process.pid" }
- { source_path: "targetProcessInfo.tgtProcCmdLine", ocsf_field: "process.cmd_line" }
- { source_path: "targetProcessInfo.tgtProcImagePath", ocsf_field: "process.file.path" }
- { source_path: "targetProcessInfo.tgtProcUid", ocsf_field: "process.uid" }
# Target file — the file acted upon
- { source_path: "targetProcessInfo.tgtFilePath", ocsf_field: "file.path" }
- { source_path: "targetProcessInfo.tgtFileId", ocsf_field: "file.uid" }
- { source_path: "targetProcessInfo.tgtFileHashSha256", ocsf_field: "file.hashes.sha256" }
- { source_path: "targetProcessInfo.tgtFileHashSha1", ocsf_field: "file.hashes.sha1" }
@@ -1,5 +1,5 @@
name: "SentinelOne Threats → OCSF"
description: "Maps a SentinelOne v2.1 threat object (data[]) to OCSF endpoint/file/process/malware fields."
description: "Maps a SentinelOne v2.1 threat object (data[]) to OCSF. The malicious file is the subject (file.*); the process that ran it is the actor (actor.*); the host's logged-in user is the affected user (user.*)."
field_mappings:
title: "threatInfo.threatName"
severity: "threatInfo.confidenceLevel = 'malicious' ? 4 : 3"
@@ -7,27 +7,29 @@ field_mappings:
# source_path is evaluated against ONE threat object (alert rule results_path = data).
# Paths absent from a given threat are skipped at ingestion, so extra entries are safe.
ocsf:
# Endpoint
- { source_path: "agentRealtimeInfo.agentComputerName", ocsf_field: "src_endpoint.hostname" }
- { source_path: "agentRealtimeInfo.agentDomain", ocsf_field: "src_endpoint.domain" }
- { source_path: "agentRealtimeInfo.agentOsType", ocsf_field: "src_endpoint.os.type" }
- { source_path: "agentRealtimeInfo.agentUuid", ocsf_field: "device.uid" }
- { source_path: "agentDetectionInfo.externalIp", ocsf_field: "src_endpoint.ip" }
- { source_path: "agentDetectionInfo.agentOsName", ocsf_field: "src_endpoint.os.name" }
- { source_path: "agentDetectionInfo.agentLastLoggedInUserName", ocsf_field: "actor.user.name" }
# Threat / malware
- { source_path: "threatInfo.threatName", ocsf_field: "malware.name" }
- { source_path: "threatInfo.classification", ocsf_field: "malware.classifications" }
- { source_path: "threatInfo.threatId", ocsf_field: "finding_info.uid" }
- { source_path: "threatInfo.confidenceLevel", ocsf_field: "confidence" }
- { source_path: "threatInfo.mitigationStatus", ocsf_field: "status" }
# Process
- { source_path: "threatInfo.processUser", ocsf_field: "process.user.name" }
- { source_path: "threatInfo.maliciousProcessArguments", ocsf_field: "process.cmd_line" }
# File
- { source_path: "threatInfo.filePath", ocsf_field: "file.path" }
- { source_path: "threatInfo.fileExtension", ocsf_field: "file.ext" }
- { source_path: "threatInfo.fileSize", ocsf_field: "file.size" }
- { source_path: "threatInfo.sha256", ocsf_field: "file.hashes.sha256" }
- { source_path: "threatInfo.sha1", ocsf_field: "file.hashes.sha1" }
- { source_path: "threatInfo.md5", ocsf_field: "file.hashes.md5" }
# Endpoint (where it was seen)
- { source_path: "agentRealtimeInfo.agentComputerName", ocsf_field: "src_endpoint.hostname" }
- { source_path: "agentRealtimeInfo.agentDomain", ocsf_field: "src_endpoint.domain" }
- { source_path: "agentRealtimeInfo.agentOsType", ocsf_field: "src_endpoint.os.type" }
- { source_path: "agentRealtimeInfo.agentUuid", ocsf_field: "device.uid" }
- { source_path: "agentDetectionInfo.externalIp", ocsf_field: "src_endpoint.ip" }
- { source_path: "agentDetectionInfo.agentOsName", ocsf_field: "src_endpoint.os.name" }
# Affected user (logged in on the host)
- { source_path: "agentDetectionInfo.agentLastLoggedInUserName", ocsf_field: "user.name" }
# Finding / malware
- { source_path: "threatInfo.threatName", ocsf_field: "malware.name" }
- { source_path: "threatInfo.classification", ocsf_field: "malware.classifications" }
- { source_path: "threatInfo.threatId", ocsf_field: "finding_info.uid" }
- { source_path: "threatInfo.confidenceLevel", ocsf_field: "confidence" }
- { source_path: "threatInfo.mitigationStatus", ocsf_field: "status" }
# Acting (malicious) process — the actor
- { source_path: "threatInfo.originatorProcess", ocsf_field: "actor.process.name" }
- { source_path: "threatInfo.maliciousProcessArguments", ocsf_field: "actor.process.cmd_line" }
- { source_path: "threatInfo.processUser", ocsf_field: "actor.user.name" }
# Malicious file — the subject
- { source_path: "threatInfo.filePath", ocsf_field: "file.path" }
- { source_path: "threatInfo.fileExtension", ocsf_field: "file.ext" }
- { source_path: "threatInfo.fileSize", ocsf_field: "file.size" }
- { source_path: "threatInfo.sha256", ocsf_field: "file.hashes.sha256" }
- { source_path: "threatInfo.sha1", ocsf_field: "file.hashes.sha1" }
- { source_path: "threatInfo.md5", ocsf_field: "file.hashes.md5" }