redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
169 stars 59 forks source link

Add additional parameter mappings and output fields for SentinelOne #85

Closed xC0uNt3r7hr34t closed 1 year ago

xC0uNt3r7hr34t commented 1 year ago

Which category is the feature part of?

Which product is the feature part of?

Use Cases Requesting additional mappings for parameter conversion when using definition files. This will expand the search capabilities for the product. In the same way more fields should be added to give larger context to returned results in the output to csv.

Additional context StorylineID is a key component to pivot when hunting or baselining an environment and is crucial to the output to eliminate the need to return all data to the csv.