General
First release of pysigma-backend-carbonblack.
Backend
- Output formats include plaintext and JSON (includes query and rule metadata)
- Uses Carbon Black syntax
Pipelines
- Two pipelines
- `CarbonBlack_pipeline` = Carbon Black Enterprise EDR
- `CarbonBlackResponse_pipeline` = Carbon Black EDR
- Supports `linux`, `windows`, and `macos` product types
- Supports the following category types for field mappings
- `process_creation`
- `file_event`
- `file_change`
- `file_rename`
- `file_delete`
- `image_load`
- `registry_add`
- `registry_delete`
- `registry_event`
- `registry_set`
- `network_connection`
- `firewall`