From 120b426a797b75f22711cf4964e64f33c40411d7 Mon Sep 17 00:00:00 2001 From: Josh Brower Date: Fri, 24 Jul 2026 17:23:00 -0400 Subject: [PATCH] Add already_running mapping --- .../files/soc/sigma_playbook_pipeline.yaml | 24 +++++++++++++++++++ salt/soc/files/soc/sigma_so_pipeline.yaml | 18 +++++++++++--- 2 files changed, 39 insertions(+), 3 deletions(-) diff --git a/salt/soc/files/soc/sigma_playbook_pipeline.yaml b/salt/soc/files/soc/sigma_playbook_pipeline.yaml index 04bd2ffaf..a779c4dec 100644 --- a/salt/soc/files/soc/sigma_playbook_pipeline.yaml +++ b/salt/soc/files/soc/sigma_playbook_pipeline.yaml @@ -12,6 +12,30 @@ transformations: process.command_line: process.command_line.caseless process.parent.command_line: process.parent.command_line.caseless file.path: file.path.caseless + # entity_id pivots must also match processes that were already running when the + # agent started: Defend emits already_running (event.type:info), not start. + # Kept out of Playbook sigma query because Sysmon has no equivalent concept. + # contains_field is exact, so child pivots (process.parent.entity_id) stay + # start-only. Drop must precede add; + - id: playbook_process_lifecycle_drop_start_scope + type: drop_detection_item + field_name_conditions: + - type: include_fields + fields: ['event.type'] + rule_conditions: + - type: logsource + category: process_creation + - type: contains_field + field: process.entity_id + - id: playbook_process_lifecycle_add-fields + type: add_condition + conditions: + event.type: ['start', 'info'] + rule_conditions: + - type: logsource + category: process_creation + - type: contains_field + field: process.entity_id # file_activity: playbook-only pseudo-category spanning all file operations. - id: playbook_file_activity_add-fields type: add_condition diff --git a/salt/soc/files/soc/sigma_so_pipeline.yaml b/salt/soc/files/soc/sigma_so_pipeline.yaml index 724740673..64b691d8f 100644 --- a/salt/soc/files/soc/sigma_so_pipeline.yaml +++ b/salt/soc/files/soc/sigma_so_pipeline.yaml @@ -68,13 +68,25 @@ transformations: - type: logsource category: antivirus # OS-agnostic process_creation scoping for product-less (NIDS/host-pivot) rules. + # pySigma: rule_cond_expr requires rule_conditions as a mapping, not a list. - id: process_creation_os_agnostic type: add_condition conditions: event.category: process rule_conditions: - - type: logsource - category: process_creation + pc_cat: + type: logsource + category: process_creation + pc_win: + type: logsource + product: windows + pc_mac: + type: logsource + product: macos + pc_lin: + type: logsource + product: linux + rule_cond_expr: "pc_cat and not (pc_win or pc_mac or pc_lin)" # Transforms the `Hashes` field to ECS fields # ECS fields are used by the hash fields emitted by Elastic Defend # If shipped with Elastic Agent, sysmon logs will also have hashes mapped to ECS fields @@ -630,4 +642,4 @@ transformations: tags: '*file' rule_conditions: - type: logsource - category: file \ No newline at end of file + category: file