Skip to content

Databricks SQL Addition Crowdstrike Queries - #2127

Merged
zaynahsmith-dasilva merged 3 commits into
developfrom
databricks-queries-crowdstrike
Jul 7, 2026
Merged

zaynahsmith-dasilva merged 3 commits into
developfrom
databricks-queries-crowdstrike

Conversation

@zaynahsmith-dasilva

Copy link
Copy Markdown
Contributor

Background

Changes

  • Added a databricks sql YAML key to the existing SQL queries within the Crowdstrike log type.

Testing

@zaynahsmith-dasilva zaynahsmith-dasilva added the tuning detection tuning label Jul 2, 2026
@zaynahsmith-dasilva
zaynahsmith-dasilva requested review from a team as code owners July 2, 2026 19:45
@cursor

cursor Bot commented Jul 2, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Medium risk because these are detection query changes for security analytics and require dialect correctness across Databricks nested-field access and SQL operators. Existing scheduled queries remain disabled and Snowflake logic is largely preserved, limiting runtime impact.

Overview
Adds DatabricksQuery definitions to seven CrowdStrike-related scheduled queries for AWS, Okta, 1Password, large zip creation, and macOS browser credential access detections.

The previous generic Query blocks are renamed to SnowflakeQuery, and the new Databricks variants adapt Snowflake-specific syntax such as LIKE ANY, variant field access, and casts to Databricks-compatible SQL.

Reviewed by Cursor Bugbot for commit c662ec0. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit d62c39c. Configure here.

Comment thread queries/crowdstrike_queries/CrowdStrike_Large_Zip_Creation.yml Outdated
@zaynahsmith-dasilva
zaynahsmith-dasilva force-pushed the databricks-queries-crowdstrike branch from 249a764 to 9ea20db Compare July 6, 2026 17:55
@zaynahsmith-dasilva
zaynahsmith-dasilva force-pushed the databricks-queries-crowdstrike branch from 81dceda to c662ec0 Compare July 7, 2026 14:54
@zaynahsmith-dasilva
zaynahsmith-dasilva added this pull request to the merge queue Jul 7, 2026
Merged via the queue into develop with commit 972d269 Jul 7, 2026
19 checks passed
@zaynahsmith-dasilva
zaynahsmith-dasilva deleted the databricks-queries-crowdstrike branch July 7, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tuning detection tuning

2 participants