General
First release of pysigma-backend-sentinelone-pq.
Backend
- Output formats include plaintext and JSON (includes query and rule metadata)
- Uses SentinelOne's PowerQuery syntax
Pipelines
- Supports `linux`, `windows`, and `macos` product types
- Supports the following category types for field mappings
- `process_creation`
- `file_event`
- `file_change`
- `file_rename`
- `file_delete`
- `image_load`
- `pipe_creation`
- `registry_add`
- `registry_delete`
- `registry_event`
- `registry_set`
- `dns_query`
- `dns`
- `network_connection`
- `firewall`