@@ -274,6 +274,10 @@ processors:
274274 field : json.tgt.process.publisher
275275 target_field : sentinel_one_cloud_funnel.event.tgt.process.publisher
276276 ignore_missing : true
277+ - set :
278+ field : process.code_signature.subject_name
279+ copy_from : sentinel_one_cloud_funnel.event.tgt.process.publisher
280+ ignore_empty_value : true
277281 - rename :
278282 field : json.tgt.process.reasonSignatureInvalid
279283 target_field : sentinel_one_cloud_funnel.event.tgt.process.reason_signature_invalid
@@ -293,6 +297,14 @@ processors:
293297 field : json.tgt.process.signedStatus
294298 target_field : sentinel_one_cloud_funnel.event.tgt.process.signed_status
295299 ignore_missing : true
300+ - set :
301+ field : process.code_signature.exists
302+ value : true
303+ if : ctx.sentinel_one_cloud_funnel?.event?.tgt?.process?.signed_status == 'signed'
304+ - set :
305+ field : process.code_signature.exists
306+ value : false
307+ if : ctx.sentinel_one_cloud_funnel?.event?.tgt?.process?.signed_status != 'signed'
296308 - date :
297309 field : json.tgt.process.startTime
298310 tag : ' date_json_tgt_process_startTime'
@@ -321,6 +333,14 @@ processors:
321333 field : json.tgt.process.verifiedStatus
322334 target_field : sentinel_one_cloud_funnel.event.tgt.process.verified_status
323335 ignore_missing : true
336+ - set :
337+ field : process.code_signature.trusted
338+ value : true
339+ if : ctx.sentinel_one_cloud_funnel?.event?.tgt?.process?.verified_status == 'verified'
340+ - set :
341+ field : process.code_signature.trusted
342+ value : false
343+ if : ctx.process?.code_signature?.exists == true && ctx.sentinel_one_cloud_funnel?.event?.tgt?.process?.verified_status != 'verified'
324344 - remove :
325345 field :
326346 - process.parent
@@ -336,6 +356,10 @@ processors:
336356 field : process.name
337357 copy_from : sentinel_one_cloud_funnel.event.tgt.process.name
338358 ignore_empty_value : true
359+ - set :
360+ field : process.executable
361+ copy_from : sentinel_one_cloud_funnel.event.tgt.process.image.path
362+ ignore_empty_value : true
339363 - convert :
340364 field : sentinel_one_cloud_funnel.event.tgt.process.pid
341365 target_field : process.pid
0 commit comments