FDR
FDR copied to clipboard
Standardize OCSF mapping rules format
The ocsf.py
file implements a non-standard mapping rule definition. Since Crowdstrike is a contributor to OCSF, and the YAML-based approach is way better than using JSON to define mapping rules to translate to OCSF, it would be a good opportunity to standardize this format to be used to translate anything to OCSF, not just FDR.
See this discussion for details.