24e8c652ac
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
34 lines
2.4 KiB
YAML
34 lines
2.4 KiB
YAML
name: "SentinelOne Threats → OCSF"
|
|
description: "Maps a SentinelOne v2.1 threat object (data[]) to OCSF endpoint/file/process/malware fields."
|
|
field_mappings:
|
|
title: "threatInfo.threatName"
|
|
severity: "threatInfo.confidenceLevel = 'malicious' ? 4 : 3"
|
|
description: "threatInfo.classification"
|
|
# source_path is evaluated against ONE threat object (alert rule results_path = data).
|
|
# Paths absent from a given threat are skipped at ingestion, so extra entries are safe.
|
|
ocsf:
|
|
# Endpoint
|
|
- { source_path: "agentRealtimeInfo.agentComputerName", ocsf_field: "src_endpoint.hostname" }
|
|
- { source_path: "agentRealtimeInfo.agentDomain", ocsf_field: "src_endpoint.domain" }
|
|
- { source_path: "agentRealtimeInfo.agentOsType", ocsf_field: "src_endpoint.os.type" }
|
|
- { source_path: "agentRealtimeInfo.agentUuid", ocsf_field: "device.uid" }
|
|
- { source_path: "agentDetectionInfo.externalIp", ocsf_field: "src_endpoint.ip" }
|
|
- { source_path: "agentDetectionInfo.agentOsName", ocsf_field: "src_endpoint.os.name" }
|
|
- { source_path: "agentDetectionInfo.agentLastLoggedInUserName", ocsf_field: "actor.user.name" }
|
|
# Threat / malware
|
|
- { source_path: "threatInfo.threatName", ocsf_field: "malware.name" }
|
|
- { source_path: "threatInfo.classification", ocsf_field: "malware.classifications" }
|
|
- { source_path: "threatInfo.threatId", ocsf_field: "finding_info.uid" }
|
|
- { source_path: "threatInfo.confidenceLevel", ocsf_field: "confidence" }
|
|
- { source_path: "threatInfo.mitigationStatus", ocsf_field: "status" }
|
|
# Process
|
|
- { source_path: "threatInfo.processUser", ocsf_field: "process.user.name" }
|
|
- { source_path: "threatInfo.maliciousProcessArguments", ocsf_field: "process.cmd_line" }
|
|
# File
|
|
- { source_path: "threatInfo.filePath", ocsf_field: "file.path" }
|
|
- { source_path: "threatInfo.fileExtension", ocsf_field: "file.ext" }
|
|
- { source_path: "threatInfo.fileSize", ocsf_field: "file.size" }
|
|
- { source_path: "threatInfo.sha256", ocsf_field: "file.hashes.sha256" }
|
|
- { source_path: "threatInfo.sha1", ocsf_field: "file.hashes.sha1" }
|
|
- { source_path: "threatInfo.md5", ocsf_field: "file.hashes.md5" }
|