feat(sentinelone): bundle OCSF mappers for get_threats and get_alerts

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Guillaume BOURGEOIS
2026-06-26 11:42:51 +02:00
parent 826aa63c74
commit 587d7d1340
3 changed files with 27 additions and 2 deletions
@@ -0,0 +1,12 @@
name: "SentinelOne Alerts → OCSF"
description: "Maps a SentinelOne v2.1 cloud-detection alert object (data[]) to OCSF endpoint/file/process fields."
field_mappings:
title: "ruleInfo.name"
severity: "ruleInfo.severity = 'Critical' ? 5 : (ruleInfo.severity = 'High' ? 4 : 3)"
description: "alertInfo.eventType"
ocsf:
- { source_path: "agentDetectionInfo.name", ocsf_field: "src_endpoint.hostname" }
- { source_path: "agentDetectionInfo.osName", ocsf_field: "src_endpoint.os.name" }
- { source_path: "sourceProcessInfo.filePath", ocsf_field: "process.file.path" }
- { source_path: "sourceProcessInfo.commandline", ocsf_field: "process.cmd_line" }
- { source_path: "sourceProcessInfo.fileHashSha256", ocsf_field: "file.hashes.sha256" }
@@ -0,0 +1,13 @@
name: "SentinelOne Threats → OCSF"
description: "Maps a SentinelOne v2.1 threat object (data[]) to OCSF endpoint/file/process fields."
field_mappings:
title: "threatInfo.threatName"
severity: "threatInfo.confidenceLevel = 'malicious' ? 4 : 3"
description: "threatInfo.classification"
ocsf:
- { source_path: "agentRealtimeInfo.agentComputerName", ocsf_field: "src_endpoint.hostname" }
- { source_path: "agentDetectionInfo.externalIp", ocsf_field: "src_endpoint.ip" }
- { source_path: "agentDetectionInfo.agentOsName", ocsf_field: "src_endpoint.os.name" }
- { source_path: "threatInfo.sha256", ocsf_field: "file.hashes.sha256" }
- { source_path: "threatInfo.filePath", ocsf_field: "file.path" }
- { source_path: "threatInfo.maliciousProcessArguments", ocsf_field: "process.cmd_line" }