-
Notifications
You must be signed in to change notification settings - Fork 511
Open
Labels
Integration:crowdstrikeCrowdStrikeCrowdStrikeTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]enhancementNew feature or requestNew feature or request
Description
The crowdstrike.falcon integration is using TacticId, TacticIds, Tactic, Tactics, TechniqueId, TechniqueIds Technique and Techniques fields to populate threat.* ECS fields for various detection events.
According to CrowdStirke documentation these fields are deprecated and these fields are moved under MitreAttack object.
Though the deprecating fields are still show up in the live logs, It would be good to switch to the recommended fields.
Metadata
Metadata
Assignees
Labels
Integration:crowdstrikeCrowdStrikeCrowdStrikeTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]enhancementNew feature or requestNew feature or request
