-
Notifications
You must be signed in to change notification settings - Fork 163
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add new sub-category Process Call Stacks #80
base: main
Are you sure you want to change the base?
Conversation
Hello @jdu2600, I think this is a great idea! Could you assist me in collecting information on most of the vendors we currently support for this new telemetry sub-category? I’ll also investigate this. We can use this PR to monitor progress, and once we’re ready, we can merge it 🙂 |
Here's a sample Elastic call stack from a process creation event -
I asked the stack spoofing community on twitter about other products and so far only CrowdStrike has been mentioned - though it looks like they only include them sometimes and don't fully enrich them. I found a CrowdStrike sample here -
|
Awesome, thank you! I'll be testing MDE and LimaCharlie. Feel free to keep updating this commit as you go along the list of vendors. I will do the same! Thank you so much 😊🙏 |
HarfangLab returns the following (for process creation events, but other events also generate stacktraces, and I can provide screenshots if needed):
(I eluded part of the data for readability) |
That's great @pixmaip! Thanks for sharing, a couple of screenshots would be nice. You can send them here or privately to me. 🙏 |
@maximelb (LimaCharlie) ❌ Hey everyone! Could you help speed up adding this new sub-category by answering the question below for the EDR assigned to you? Thank you! 🙏 Does your EDR include Process Call Stack Telemetry events? |
@tsale For ESET Inspect the answer is no. |
@tsale I am not aware that Symantec is supporting this, so the answer is no. |
for carbon balck the answer is no as well |
I also checked LC and I can't find evidence of stack trace. |
@tsale I'm not seeing this telemetry with Trellix EDR. |
@tsale Uptycs can't log Process Call Stacks at this point, so it's a No for Uptycs. |
Pull Request Template
Description
Please provide the below information so we can validate before merging:
Type of change