fdr2humio
psfalcon
Our great sponsors
fdr2humio | psfalcon | |
---|---|---|
2 | 169 | |
6 | 317 | |
- | 2.8% | |
0.0 | 9.2 | |
6 months ago | 6 days ago | |
Python | PowerShell | |
Apache License 2.0 | The Unlicense |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
fdr2humio
-
Falcon Data Replicator - FDR
fdr2humio for ingesting FDR data into Humio
-
Humio and Crowdstrike
Next step is to set up SIEM connector or FDR to be ingested into Humio. Read more on this here: https://github.com/humio/fdr2humio
psfalcon
-
Migrate child cid to parent cid
Rather than using flight control, you could consider doing a import/export of your configuration, then mass uninstall and reinstall each individual existing CID into your new single CID. The parent would really only help with policy inheritence/detection rollup/rbac which you would no longer need after converting to a single instance.
-
Get Falcon Scanning Results Via API
Try using PSFalcon and Get-FalconDetection to see what's in a detection record.
- Filter issue with Get-FalconAsset
- Identity API for PSfalcon or FalconPY
-
Change sensor grouping tags via API
Add-FalconSensorTag Get-FalconSensorTag Remove-FalconSensorTag
- API for removing VDIs older than 24 hours
-
Create IOA Falconpy
There's an example of required fields under the New-FalconIoaRule wiki page, along with the values for disposition_id.
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
Status of API batch RTR commands when queued offline
Check out Get-FalconQueue. It goes through a few steps:
-
Invoke-FalconDeploy Behavior Change
Could you open an issue and include a PowerShell transcript with $VerbosePreference = 'Continue'?
What are some alternatives?
FDR - Falcon Data Replicator
falconpy - The CrowdStrike Falcon SDK for Python
CrowdStrike-Spotlight-Humio-Package-Integration
swagger-ui - Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
PowerFGT - PowerShell module to manage Fortinet (FortiGate) Firewall
rtr - Real-time Response scripts and schema
BulkStrike - BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
PSKoans - A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
SnipeitPS - Powershell API Wrapper for Snipe-it
PSWinReporting - This PowerShell Module has multiple functionalities, but one of the signature features of this module is the ability to parse Security logs on Domain Controllers providing easy to use access to AD Events.
KaceSMA - A module for interacting with a Quest Kace Systems Management Appliance API via Powershell.