Skip to content

Prepare for release v3.109.0 - #2074

Merged
arielkr256 merged 10 commits into
mainfrom
develop
May 26, 2026
Merged

arielkr256 merged 10 commits into
mainfrom
develop

Conversation

@alessandrarizzo

Copy link
Copy Markdown
Contributor

Background

Changes

Testing

zaynahsmith-dasilva and others added 9 commits May 14, 2026 17:49
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: maxrichie5 <max.richmond@panther.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
Co-authored-by: panther-bot-automation <github-service-account-automation@panther.io>
…r` out of experimental + create Anthropic pack (#2073)
… 6.1.1 (#2050)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@alessandrarizzo
alessandrarizzo requested a review from a team as a code owner May 26, 2026 14:36
@cursor

cursor Bot commented May 26, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes alter correlation log types, baseline/lookup SQL, and alert severity mapping for vendor passthrough rules, which can shift alert volume and fidelity until validated in tenant data.

Overview
Release v3.109.0 prep bumps the release workflow’s AWS configure-credentials action to v6.1.1 and refreshes detection catalog/index entries for Snowflake.

Snowflake: The Snowflake Data Exfiltration correlation detection is repointed from streaming/QueryHistory to snowflake_data_exfiltration.yml on Snowflake.AccountUsage. The configuration-drift scheduled query now excludes EXPLAIN, tightens which successful non-SELECT activity counts (including Panther lookup COPY INTO noise), and the user created alert title parses usernames with a regex (including IF NOT EXISTS).

Okta baselines: AD-agent and main baseline queries drop system@okta.com, cap per-user distribution aggregates to the top 50 values, and rebuild SWA “known IP/UA” lists as frequency-ranked top 50 instead of unbounded distinct arrays.

CrowdStrike / Wiz: Adds disabled lookup crowdstrike_aid_device_info (AID → device metadata from FDR) to the CrowdStrike pack; passthrough rules normalize severity from name or numeric fallback (CrowdStrike summary uses safer string handling). Wiz maps INFORMATIONAL → INFO and dedupes informational/low similarly.

Packs & rules: New Anthropic pack; Anthropic rules lose Experimental status. Standard.OTX.MaliciousIndicator and panther_otx_helpers join the standard ruleset pack (OTX rule no longer Experimental).

Reviewed by Cursor Bugbot for commit 666baee. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread rules/crowdstrike_rules/crowdstrike_detection_passthrough.py
@alessandrarizzo alessandrarizzo changed the title Prepare for release v3.108.2 May 26, 2026
@arielkr256
arielkr256 enabled auto-merge May 26, 2026 14:43

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 666baee. Configure here.

if sevname == "INFORMATIONAL":
sevname = "INFO"
if sevname in allowed_values:
return sevname

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing SeverityName crashes passthrough

High Severity

The updated severity handler calls .upper() on get_crowdstrike_field(event, "SeverityName") without guarding missing values. When SeverityName is absent, that value is None, so alert generation raises AttributeError instead of using the numeric fallback.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 666baee. Configure here.

ARRAY_UNIQUE_AGG(aip) AS aips,
MAX_BY(event, p_event_time) AS details
FROM panther_logs.public.crowdstrike_fdrevent
WHERE p_occurs_since('10d')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lookup window contradicts description

Medium Severity

The new crowdstrike_aid_device_info lookup describes device data from the last 90 days, but its SQL filters with p_occurs_since('10d'). Enabling the table yields only ten days of AID mappings, not the documented window.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 666baee. Configure here.

@arielkr256
arielkr256 merged commit c2a8b90 into main May 26, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants