diff --git a/rules/crowdstrike_rules/event_stream_rules/crowdstrike_detection_summary.py b/rules/crowdstrike_rules/event_stream_rules/crowdstrike_detection_summary.py index 3653fbd0a..d8604cd4b 100644 --- a/rules/crowdstrike_rules/event_stream_rules/crowdstrike_detection_summary.py +++ b/rules/crowdstrike_rules/event_stream_rules/crowdstrike_detection_summary.py @@ -42,6 +42,12 @@ def reference(event: PantherEvent): def alert_context(event: PantherEvent): context = cs_alert_context(event) context.update( - {"FalconLink": event.deep_get("event", "FalconHostLink", default="")} + { + "FalconLink": event.deep_get("event", "FalconHostLink", default=""), + "CompositeId": event.deep_get("event", "CompositeId", default=""), + "FileName": event.deep_get("event", "FileName", default=""), + "FilePath": event.deep_get("event", "FilePath", default=""), + "UserName": event.deep_get("event", "UserName", default=""), + } ) return context