Home

Awesome

Tests Coverage Badge Status

pySigma CrowdStrike Backend

This is the CrowdStrike backend for pySigma. It provides the package sigma.backends.crowdstrike with the LogScaleBackend class.

Further it contains the following processing pipelines under sigma.pipelines.crowdstrike:

Supported Rules

Falcon Pipeline

The following categories and products are supported by the pipelines:

categoryproductCrowdStrike event_simpleName
process_creationwindows, linuxProcessRollup2, SyntheticProcessRollup2
network_connectionwindowsNetworkConnectIP4, NetworkReceiveAcceptIP4
dns_querywindowsDnsRequest
image_loadwindowsClassifiedModuleLoad
driver_loadwindowsDriverLoad
ps_scriptwindowsCommandHistory, ScriptControlScanTelemetry

There's likely more windows categories that can be supported by the pipelines; We will be adding support gradually as availability allows.

Limitations and caveats:

References

This backend is currently maintained by: