Prepare for release v3.109.0 - #2074
Conversation
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
…r` out of experimental + create Anthropic pack (#2073)
… 6.1.1 (#2050) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
PR SummaryMedium Risk Overview Snowflake: The Snowflake Data Exfiltration correlation detection is repointed from streaming/ Okta baselines: AD-agent and main baseline queries drop CrowdStrike / Wiz: Adds disabled lookup Packs & rules: New Anthropic pack; Anthropic rules lose Experimental status. Standard.OTX.MaliciousIndicator and Reviewed by Cursor Bugbot for commit 666baee. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 666baee. Configure here.
| if sevname == "INFORMATIONAL": | ||
| sevname = "INFO" | ||
| if sevname in allowed_values: | ||
| return sevname |
There was a problem hiding this comment.
Missing SeverityName crashes passthrough
High Severity
The updated severity handler calls .upper() on get_crowdstrike_field(event, "SeverityName") without guarding missing values. When SeverityName is absent, that value is None, so alert generation raises AttributeError instead of using the numeric fallback.
Reviewed by Cursor Bugbot for commit 666baee. Configure here.
| ARRAY_UNIQUE_AGG(aip) AS aips, | ||
| MAX_BY(event, p_event_time) AS details | ||
| FROM panther_logs.public.crowdstrike_fdrevent | ||
| WHERE p_occurs_since('10d') |
There was a problem hiding this comment.
Lookup window contradicts description
Medium Severity
The new crowdstrike_aid_device_info lookup describes device data from the last 90 days, but its SQL filters with p_occurs_since('10d'). Enabling the table yields only ten days of AID mappings, not the documented window.
Reviewed by Cursor Bugbot for commit 666baee. Configure here.


Background
Changes
Testing