Skip to content

Add Crowdstrike AID device info lookup table - #2069

Merged
alessandrarizzo merged 2 commits into
developfrom
add-crowdstrike-aid-device-info-lookup
May 26, 2026
Merged

alessandrarizzo merged 2 commits into
developfrom
add-crowdstrike-aid-device-info-lookup

Conversation

@arielkr256

@arielkr256 arielkr256 commented May 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds lookup_tables/crowdstrike/crowdstrike_aid_device_info.yml
  • Maps Crowdstrike AIDs to devices with most-recent ComputerName, known IPs (aip aggregate), and the full latest aid_master event details (10-day window)
  • Enriches Crowdstrike log types keyed by aid (plus SensorId for DetectionSummary)
  • Disabled by default; daily refresh (1440 min)
   Maps Crowdstrike AIDs to devices with known IPs, hardware, and
   software
   specs from the most recent aid_master FDR event in the last 10
   days.
   Enriches Crowdstrike log types keyed by aid.
@arielkr256
arielkr256 requested a review from a team as a code owner May 20, 2026 16:18
@cursor

cursor Bot commented May 20, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Low risk: adds a new, disabled-by-default lookup table and wires it into the Crowdstrike pack; impact is limited to extra query/refresh load only if enabled.

Overview
Adds a new Crowdstrike lookup table, crowdstrike_aid_device_info, that aggregates recent aid_master FDR events to map aid to the latest ComputerName, a de-duplicated list of aip values, and the most recent full event payload.

Updates the Crowdstrike pack (packs/crowdstrike.yml) to include this lookup table for optional enrichment; the table is disabled by default and configured to refresh daily.

Reviewed by Cursor Bugbot for commit 9f6b2ed. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256 arielkr256 added the lookup_table LookUpTables provide enrichment for Rules label May 20, 2026
Comment thread lookup_tables/crowdstrike/crowdstrike_aid_device_info.yml Outdated
Comment thread lookup_tables/crowdstrike/crowdstrike_aid_device_info.yml Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 9f6b2ed. Configure here.

AssociatedLogTypes:
- LogType: Crowdstrike.FDREvent
Selectors:
- "aid"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing AssociatedLogTypes per PR description intent

High Severity

The PR description states this lookup "enriches Crowdstrike log types keyed by aid (plus SensorId for DetectionSummary)," but AssociatedLogTypes only contains Crowdstrike.FDREvent. Many Crowdstrike log types with an aid field — such as Crowdstrike.ProcessRollup2, Crowdstrike.DNSRequest, Crowdstrike.UserIdentity, Crowdstrike.NetworkConnect, Crowdstrike.AIDMaster, etc. — are missing. Crowdstrike.DetectionSummary with a SensorId selector is also absent.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 9f6b2ed. Configure here.

@alessandrarizzo
alessandrarizzo added this pull request to the merge queue May 26, 2026
Merged via the queue into develop with commit a138ab4 May 26, 2026
20 checks passed
@alessandrarizzo
alessandrarizzo deleted the add-crowdstrike-aid-device-info-lookup branch May 26, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lookup_table LookUpTables provide enrichment for Rules

2 participants