forked from demisto/content
-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
- Loading branch information
Showing
184 changed files
with
13,307 additions
and
1,705 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
{ | ||
"breakingChanges": true, | ||
"breakingChangesNotes": "Raised the default value of device events max fetch and events max fetch to 50k and 100k respectively and lowered the device fetch interval default value to 4 hours." | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
|
||
#### Integrations | ||
|
||
##### Armis Event Collector | ||
|
||
- Raised the default value of device events max fetch and events max fetch to 50k and 100k respectively and lowered the device fetch interval default value to 4 hours. | ||
- Updated the Docker image to: *demisto/python3:3.11.9.103066*. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2,7 +2,7 @@ | |
"name": "Armis", | ||
"description": "Agentless and passive security platform that sees, identifies, and classifies every device, tracks behavior, identifies threats, and takes action automatically to protect critical information and systems", | ||
"support": "partner", | ||
"currentVersion": "1.1.15", | ||
"currentVersion": "1.1.16", | ||
"author": "Armis Corporation", | ||
"url": "https://support.armis.com/", | ||
"email": "[email protected]", | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
|
||
#### Scripts | ||
|
||
##### DBotTrainTextClassifierV2 | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. | ||
##### DBotFindSimilarIncidentsByIndicators | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. | ||
##### GetMLModelEvaluation | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. | ||
##### DBotPredictPhishingWords | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. | ||
##### DBotFindSimilarIncidents | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. | ||
##### DBotPreProcessTextData | ||
|
||
- Updated the Docker image to: *demisto/ml:1.0.0.103517*. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
93 changes: 52 additions & 41 deletions
93
Packs/CiscoASA/ModelingRules/CiscoASA_1_4/CiscoASA_1_4.xif
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
|
||
#### Modeling Rules | ||
|
||
##### Cisco ASA Modeling Rule | ||
|
||
Fixed an issue for TCP and UDP connection teardown events (Event IDs 302014 & 302016, respectively), which caused the source and target fields to be inverted. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,2 +0,0 @@ | ||
[file:README.md] | ||
ignore=RM108 | ||
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,16 +1,16 @@ | ||
# CloudIDS | ||
Google Cloud IDS is a next-generation advanced intrusion detection service that provides threat detection for intrusions, malware, spyware, and command-and-control attacks. | ||
|
||
## What does this pack do? | ||
|
||
### Playbook | ||
* `Cloud_IDS-IP_Blacklist-GCP_Firewall_Extract`: Gets the attacker's IP address from Cloud IDS through Google Pub/Sub. | ||
`Cloud_IDS-IP_Blacklist-GCP_Firewall_Append` will update the ip list so GCP automatically blocks the IP address. | ||
|
||
#### Flow Chart of Playbook | ||
* [Cloud_IDS-IP_Blacklist-GCP_Firewall](https://github.com/demisto/content/blob/423e13b69b375288d3ec2183bfbd4d2ee6fe018c/Packs/CloudIDS/Playbooks/Cloud_IDS-IP_Blacklist-GCP_Firewall_README.md) | ||
![Playbook Image](doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Combine.png) | ||
![Playbook Image](doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Extract.png) | ||
![Playbook Image](doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Append.png) | ||
|
||
|
||
# CloudIDS | ||
Google Cloud IDS is a next-generation advanced intrusion detection service that provides threat detection for intrusions, malware, spyware, and command-and-control attacks. | ||
|
||
## What does this pack do? | ||
|
||
### Playbook | ||
* `Cloud_IDS-IP_Blacklist-GCP_Firewall_Extract`: Gets the attacker's IP address from Cloud IDS through Google Pub/Sub. | ||
`Cloud_IDS-IP_Blacklist-GCP_Firewall_Append` will update the ip list so GCP automatically blocks the IP address. | ||
|
||
#### Flow Chart of Playbook | ||
* [Cloud_IDS-IP_Blacklist-GCP_Firewall](https://github.com/demisto/content/blob/423e13b69b375288d3ec2183bfbd4d2ee6fe018c/Packs/CloudIDS/Playbooks/Cloud_IDS-IP_Blacklist-GCP_Firewall_README.md) | ||
![Playbook Image](https://github.com/demisto/content/raw/423e13b69b375288d3ec2183bfbd4d2ee6fe018c/Packs/CloudIDS/doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Combine.png) | ||
![Playbook Image](https://github.com/demisto/content/raw/423e13b69b375288d3ec2183bfbd4d2ee6fe018c/Packs/CloudIDS/doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Extract.png) | ||
![Playbook Image](https://github.com/demisto/content/raw/423e13b69b375288d3ec2183bfbd4d2ee6fe018c/Packs/CloudIDS/doc_files/Cloud_IDS-IP_Blacklist-GCP_Firewall_Append.png) | ||
|
||
|
Oops, something went wrong.