Skip to content

Update normalized-threat-rules.md - #6992

Open
jc-sumo wants to merge 1 commit into
SumoLogic:mainfrom
jc-sumo:normalized-threat-rules
Open

Update normalized-threat-rules.md#6992
jc-sumo wants to merge 1 commit into
SumoLogic:mainfrom
jc-sumo:normalized-threat-rules

Conversation

@jc-sumo

@jc-sumo jc-sumo commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Purpose of this pull request

This pull request adds new detection passthrough classes and reflects current state of migration

Select the type of change

  • Minor Changes - Typos, formatting, slight revisions
  • Update Content - Revisions, updating sections
  • New Content - New features, sections, pages, tutorials
  • Site and Tools - .clabot, version updates, maintenance, dependencies, new packages for the site (Docusaurus, Gatsby, React, etc.)

Ticket (if applicable)

https://sumologic.atlassian.net/browse/TLAB-2666

Adds new detection passthrough classes and reflects current state of migration
@jc-sumo jc-sumo self-assigned this Aug 5, 2026
@cla-bot cla-bot Bot added the cla-signed Contributor approved, listed in .clabot file label Aug 5, 2026

Classes are assigned per log mapping, not per vendor, so a single security product can contribute to several classes. For example, out-of-the-box CrowdStrike log mappings are assigned to `endpoint`, `identity`, `network`, and `data_protection`.

* **runtime**. Container and cloud-native runtime detections from workload security agents: Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), and Aqua Security.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per the Aug 4 content release note (PR #6986): "Runtime detections from Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security, and Contrast ADR now route to the Normalized Runtime Detection rule (MATCH-S01159)..." — but this bullet only lists Falco, Sysdig Secure, Twistlock, and Aqua Security. Contrast ADR only shows up under data_protection below (line 132).

Given the "classes are assigned per log mapping, not per vendor" note above (and the CrowdStrike example spanning 4 classes), Contrast ADR may legitimately contribute to both runtime and data_protection via separate log mappings — in which case it should be added here too, similar to how CrowdStrike is called out as spanning multiple classes. Worth confirming with the content/rules team before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed Contributor approved, listed in .clabot file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants