Update normalized-threat-rules.md - #6992
Conversation
Adds new detection passthrough classes and reflects current state of migration
|
|
||
| Classes are assigned per log mapping, not per vendor, so a single security product can contribute to several classes. For example, out-of-the-box CrowdStrike log mappings are assigned to `endpoint`, `identity`, `network`, and `data_protection`. | ||
|
|
||
| * **runtime**. Container and cloud-native runtime detections from workload security agents: Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), and Aqua Security. |
There was a problem hiding this comment.
Per the Aug 4 content release note (PR #6986): "Runtime detections from Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security, and Contrast ADR now route to the Normalized Runtime Detection rule (MATCH-S01159)..." — but this bullet only lists Falco, Sysdig Secure, Twistlock, and Aqua Security. Contrast ADR only shows up under data_protection below (line 132).
Given the "classes are assigned per log mapping, not per vendor" note above (and the CrowdStrike example spanning 4 classes), Contrast ADR may legitimately contribute to both runtime and data_protection via separate log mappings — in which case it should be added here too, similar to how CrowdStrike is called out as spanning multiple classes. Worth confirming with the content/rules team before merging.
Purpose of this pull request
This pull request adds new detection passthrough classes and reflects current state of migration
Select the type of change
Ticket (if applicable)
https://sumologic.atlassian.net/browse/TLAB-2666