Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test Telemetry Linux - Crowdstrike (on debian) #86

Closed
mthcht opened this issue Nov 21, 2024 · 6 comments
Closed

Test Telemetry Linux - Crowdstrike (on debian) #86

mthcht opened this issue Nov 21, 2024 · 6 comments

Comments

@mthcht
Copy link
Contributor

mthcht commented Nov 21, 2024

@tsale
The result of my test:

[
telemetry_debian_edr_crowdstrike_test.md
](url)

@tsale
Copy link
Owner

tsale commented Nov 23, 2024

Thanks @mthcht! I have a quick question: Could you please let me know if you can see any of the events below?

User Logon
User Logoff
Logon Failed
Script Content (The content of the script that is being executed)

@mthcht
Copy link
Contributor Author

mthcht commented Nov 23, 2024

i can see all the content script yes, i'll have to check again later for the others

@mthcht
Copy link
Contributor Author

mthcht commented Nov 23, 2024

@tsale I checked again, and there are no traces of user logon, logoff, or failed logon events for my session.

Correction: Regarding the script content, the event log differs from all the others. I noticed it does not have an "event_simpleName" assigned (This event is likely to go unnoticed by most and is not properly parsed by default) and i don't have the full content of the script, it's truncated by crowdstrike:

image

@tsale
Copy link
Owner

tsale commented Nov 23, 2024

Thanks @mthcht! In terms of the script content, this is good. I would still count that.

@mthcht
Copy link
Contributor Author

mthcht commented Nov 23, 2024

@tsale i added a scheduled task manually with a crontab command since the script failed and no dedicated event for this, only visible in process execution 'ProcessRollup2'

@tsale
Copy link
Owner

tsale commented Nov 23, 2024

Thank you for the clarification @mthcht!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants