panther-labs / panther-analysis

Built-in Panther detection rules and policies
https://panther.com/
Apache License 2.0
339 stars 173 forks source link

CrowdStrike event stream api rules #1286

Closed JPhenglavong closed 4 months ago

JPhenglavong commented 4 months ago

Background

basic crowdstrike api token rules, added a crowdstrike_event_stream_alert_context() helper method and a key_value pairs global helper function

Changes

Testing

github-actions[bot] commented 4 months ago

:scream: looks like some things could be wrong with the packs

[INFO][root]: ignoring file dependabot.yml