Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CrowdStrike-Endpoint-Security] Updating action when deleting indicator on OpenCTI #3167

Open
al0rd25l opened this issue Dec 19, 2024 · 0 comments
Labels
feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team

Comments

@al0rd25l
Copy link
Contributor

Use case

Stop detecting matches on an indicator in CrowdStrike when it has been deleted on OpenCTI.

Current Workaround

When CROWDSTRIKE_PERMANENT_DELETE is set to False, if an indicator is deleted (whether it is actually deleted or it just stops being seen by the stream), it is not removed from CrowdStrike. Instead, it is just labeled with TO_DELETE. And while you can update the action later, this approach is not practical since viewing these labels requires accessing each indicator individually.

Proposed Solution

Add a function to update the action and mobile_action fields from detect to no_action for a "deleted" indicator (pretty much similar to the _handle_labels function).

Additional Information

Perhaps, if to allow flexibility, it can be configured as an optional env variable CROWDSTRIKE_UPDATE_ACTION.
Not sure if you find it necessary to keep the label update with this approach (I personally don’t see the need for it).

Would you be willing to submit a PR?

Sure, I'm already running a custom version with a _handle_action function, I would just need to add the optional variable setting.

@al0rd25l al0rd25l added feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team labels Dec 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team
Projects
None yet
Development

No branches or pull requests

1 participant