From 2933b6bca5c19fcc12d08e4d882cce5ca34c0dde Mon Sep 17 00:00:00 2001 From: squioc Date: Tue, 20 Feb 2024 14:26:06 +0000 Subject: [PATCH] Refresh automation library documentation --- _shared_content/automate/library/extrahop.md | 33 + docs/assets/playbooks/library/extrahop.png | Bin 0 -> 21139 bytes mkdocs.yml | 1712 +++++++++--------- 3 files changed, 890 insertions(+), 855 deletions(-) create mode 100644 _shared_content/automate/library/extrahop.md create mode 100644 docs/assets/playbooks/library/extrahop.png diff --git a/_shared_content/automate/library/extrahop.md b/_shared_content/automate/library/extrahop.md new file mode 100644 index 0000000000..a19783f412 --- /dev/null +++ b/_shared_content/automate/library/extrahop.md @@ -0,0 +1,33 @@ +# ExtraHop + +![ExtraHop](/assets/playbooks/library/extrahop.png){ align=right width=150 } + +ExtraHop is a leading provider of network detection and response (NDR) solutions. + +## Configuration + +| Name | Type | Description | +| --------- | ------- | --------------------------- | +| `base_url` | `string` | API base URL | +| `client_id` | `string` | Client ID | +| `client_secret` | `string` | Client Secret | + +## Triggers + +### [BETA] Fetch new alerts from ExtraHop Reveal(x) 360 + +Get last logs from the ExtraHop Reveal(x) 360 + +**Arguments** + +| Name | Type | Description | +| --------- | ------- | --------------------------- | +| `frequency` | `integer` | Batch frequency in seconds | +| `chunk_size` | `integer` | The size of chunks for the batch processing | +| `intake_server` | `string` | Server of the intake server (e.g. 'https://intake.sekoia.io') | +| `intake_key` | `string` | Intake key to use when sending events | + + +## Extra + +Module **`ExtraHop` v0.1.0** \ No newline at end of file diff --git a/docs/assets/playbooks/library/extrahop.png b/docs/assets/playbooks/library/extrahop.png new file mode 100644 index 0000000000000000000000000000000000000000..6269293179d4b0f87957b0c9b6555c87a114b487 GIT binary patch literal 21139 zcmbSS1yfv2v&P*$Sa4ljf&_Ob=t9uNExbT*2<{eagS)f9E*>n{;_edM-2*|w<@*bF zs!r8RPxo}4>F)FN>8Xj))>Oj9qQpW#K)_W|me)Z*Kmz{n!9aea#I)L)%6tK zhG!2?zjyYau%?-X<+k?Djm^#dm)DNY&dI6i`QMvs>l*_@gXfamN z+TVX~#5a-Y>Djlbo!z~L#>TGx;o;M#-kqChGP3R)!fj~gl=7h=unMpSAuF+(c1@aYHq=_DMqoX zMY5_!bb!{?wPIOjp;*^fRn_5J<<-{K4i1gJc=C2DcCv$OLfBV**&$vts!=aE0>T}ygx3cB-0HWGiWB=&8)RSnCASCvj5L^O@xzP_4dv=JJGbsj#egckZi z2JnHYRvAs#*S85B^FFm>_)eA2Yij@Vev7X5 zE%E)^vC!J!0cGVHba~AAdPpDUct1?WO^v})Zg>1{XWAfdsp-0-PN4b1vm%@nujX#GI~BMr#&HWiV=bfUMk5ek^a~H z|1}G*vo&}O9p2`{V}A>+z1v~Titke80r6GD16q?dVfeUTiEGg;Hpl+uZPDswUZ(hZwlkRwcMG&#@=WoN#OG0zgoCoXgMPW+*ue%T{ zqu1rx(v!s>P2^8vvnmaur%l!42~n&xqmSr=_uK$3uCtYy#7j z;>rt-?4@?We{PBv$r%?;Q`6f2`&^*0tnw+or%vJX=cqI8@ES&vhwgI=1)dqq(|sRF8FR6MeFC+04>^PDEy%; z7xK5j`|q9QAph@Ss{<()h?b{LjS#z};IkqD3Q&((Ag1-s``Qr>t%4>P*KKCIA*^TUmi_+hjgr>}XQEyLV{tUM%zK zEK})jI%Y@nX3Na8ThM47lM!=;GI>ik{#P-n++~wZs-ha9aedXZD0G@p6IR1E{y#SR z+xMHU&(sEDBj`<&-qfRd;$-VJ2K6YMU8BEedKm_85cBiA0J=24?PC$&!vyVeWJIH- zVU2lpE6}l~U$X;#SgLLeq4iKgg1zyBM4O7R4^d6wdzDoQGdVy9%gVH?4)5NsOS`JY ze1T+k1|b~>JZe?l1CBwhKfZ;P>*`b~e6=Da?6CS?(D%hmRhY*tY^?F4L-hAFjy8_# zmB?QRL6II6#C8rg0UNORTldn9XaW&dgi?{`AfSAe$CWGhOZ~AVszp z1*g-G2b%cb`juO~vwI!%3WizSU}6KQlRlh&Eo8yQ6g#7T+K^ z#t<_TF;iLzDtP|iQqv*dG%)1DQwWcs!FtwjOZWaYW+5oP?o-v(N#poHyIyaZd9ZSz zjxkrj6pt8)i%qg81`(nHhj7=hR;aYhL1UB40^~ipcbaiWr56WvlnF7&M-=->OM-h= zif~6ij;3OuK8ln>hazn%_G}60LE#=4*v`OxV_LLmh8T>INcjLVgVjiz0`fEEqKd7K zUJ%796zA5RS!PSgh-88pfF=wOkXVjpM(c83f>^k= zdKo6)*qkS!c)PwRdyG1M{0`>XeA9VN<4_D$r2-KIkDVTW_STJ!4+Gi&h;Ukwq&p2c341m>A~&G26l8vXLIS0O;Hl1isXs9v<2|`nf3%?H00v|GU$D6QvCuKu1CO z?RP@@VKJc7ZE&4yZOv5a{sQ~Uqo1>Mfg$|S2l2}qiMNkF8E+Xt8 zGWM4Pt6Uit^4`0fooz+f?c5$eRYs{PnC z8eOEwaNuw4L-G?G-hX9$o8XiDpu+2uP5t(uji6hgot=lL%X-`Oz!+Lobpajc#J2S~ zyc-MHF#72}@L;-ZaWMX!+d`azI|Pb<>+lWskDMF(*z%US*sgg|PuRtzDRA;Cc05P> zJmvS;SR`6h-?u?<>;)#NH=Rp0zR9~c;DYb#QxAGWy3{(``49DE48lZB4r>;f5U^5tGMN z*xEWZqFM?{P-N6fVxicjOwM&9GakpJLtZhunz5cy(Vxy17R5G69DD4@@5&3OO(N&G zAm9|7`v3}Tw4X-5F(Z1oqV+E98YUIlBF54g&kxFP`9ibr_w#2ar>+V258RA#_(E^5 zEawcXFs)U-uF`B;YOi4y-2C0Zn5B(FZX(~RGb)b8a4OD(>}N$a-;>BS9=}rQD)TJ? zSg$Pog6ylyUWe>vx?$&kH{ur^WF7wFd0cB0cU3BP1>C7rx72tj?1m09nu+N)*hVa@ zQ8KY+LjyPV8q)0nKfyK>k+${$C_LMOl(94X(Ppj6sm@890IyQPw3aWqo;UL?e%xR_ zgR=O`ZEXrl`rYX73d&4`eny$EiWzxLvD2J+Zue^~9lzWL|8$DCoXR?`$5;7^>Qp{9 zr&lPGUfxLHI7Vw5bBzu(P+Xj1VUMK@G?0we8%J)zi(-ISBS&9j;Tc$zdc!(2F8oGU za;&2yWGg0#kqaxaeP@Vf1e_c?>^DU~LVo%v^_c7*YPa>JZ$TlkSfGKUXd2+*uRFNa zC;n}{y}@6=*ngfEOR{N?A(g>$WB{1c4T7=Rhl0bHiKW{IK$ctpr=BEIEYw#rvsif@ z)lwb$9ph};+`K$Mx(*iV*J2}nKVz3#_xs2l8UaOrNs>rxM#io5MR>|^8c`wtLXg&B z&`|V^-#b1K*6`RTfsK}i_7<37MDzMcI;Uv9iEtu{0N0>=64M@tPvJ-eMgXp$h4~1g zB-bhdVvG7g={?f@y#k`5MiEZ*wBtzO600LA9W@(s9miK#I-QaqP008LovNwA3$y^4 zyiZE6rl+s(h*?ZkTK%@MFUD5>jZYM}<9&Gv?Pp8-@QK$vA2DB5O~AQ%8-x=OPfF?$ zxe#p$mcgrg>_=);4yRxiL#4s}N`gpEh(kbBs5WL=ZE-1#3~5d?@pkc6iY^CnsS8!j zC&zX0kbSR6?`1|eBYO~)NHxbj+Nz?|k&vE$wuj3Q6%&*kPXWBrzzpnm6eSC`i4cG? zT@eOv_!}JN0E6G3W0aFuF9Oz;|E;8ge#R2iH*4ht8KSwC1@3eH5+h3NWe9bp3z*WDx)RW*|`v z6GzZ8P4RO}+D>5Bx5bli@{Q$(n-BiY)El0c*y?w!S-uj-=$Q%`XUnl#Bz2P`BOGk| zGP0zD1Iw5UBHe8AV*JCYvHf#LQ;5e*SW|YyLI|Jm%S|{-v8jL7C@tuj?JU15X;n(q zsqY;H4bzbg<$M3M01A|~Xa&5)rJKCBy;%PuDNr}+vLju-1lPF3!dCe&Rt3px>@Sw6 zwq%s53Z-}qcO#NMdq!w^B05h+&tWd5JX0I-Bz5uCG_7*|3KK;kv5Y!VruI13shH7zB7P z21*5mbQRikV1?gzk4=f|si}`+D#|XF7LW3{)|;Qd25Gvf<(xLQ>8LukXS4WwjS_eA zfBYRMUdWiH9XkpO@2z;BM~K4{TBe@)PZm9XrPGeJl2*{QLXiqh2CEw1xpQ1sVc$S-X$S>Oxo4V{Och&_P>mHnGL!b(Guu$(u0&PL<#UxJ z|HrXxP;yqg4h1Q58drdQhlL2AZEtmYRM7frf~K3DhsWK${s|>j5VH&x@yD@CB8;U@ zX$$)W5TQ{&rD#$kItQ(aCJ$L~+DNUXkXLd>l$cS*wyoP-P}n(geO{K8%1)E5p{?)T zL>8yS@}!$q(K=h^3EVvlr$Q#CJPX5$*@CB8|c-;$?5g+^37~Tj>mzpuYwA?=F#LF zwM0JMt?*BOw>&!73|jeB6G+rD-)9SZQINu9%`!Y21unEzKF6N*$K283%}T`Cd=sQI ztI@FY?_`jMAQ3ewBh~IT9TUen-A^-w7LgNP^A(7pir#63@CIsIT#g`*C(F6k>qgWH z--EMJY5%)wX7(FKUq?Q0tsb_w7o1onW1?U|i5$aN_l7K(rYwhI=Fe_7enbQvl3 z=L15XDWX}m$PS6IZMS;lst&}kqP0SY>FI>;wuoUAEK$oPpG4zmqJ)15FNbvvA3j}- z|Jmot3g_=MR_=dnJ^i;eGl7XEIt6>hc!#2u!zQn4qhzXEtiALuZS3!#STvV+;HIn^ zoIa!)FbaLa6uV!6e=l*@G=go2Za-1juRHW-L)fJ&LcA#FmsEO*&i?{mB8ARq=auuh z<8Jq{bV_x&bU^?Bm81})eI=~j5nrg8WEBf~O5GEiusGf3sm@GZoy-)X zlt61YHGIFT)l!So{9<-z;}kI>vFm7SE4&VbNmw)939mV{h?iaoj=O?_^#YE=?@7RU z^Z=vuoQYKR0pV{jT2|5|G|<(dA3RjRL~)Y$**ie`1Q{l6B9mxItav`d;C*13l#+?f zlOJ`5Yx$`GW@Pv0bShdVFjFoA_tKG|w|8GL*=mj15z{EjMv&zTmE-Pmz0_wYDd z^FV{(NE{jV2bL|BYZg3=0bVxpEt*ih+T#d@q1SMXxGJBD)B?-|bh(?2CajNNU%#@U zv`PL0QJ@NrF6mdyRMk^6&pVa*H}-FhzX$2s6tbmUvwGmOXx5qW+D}A<1!og{SCezw zasTe9{`}`3EOe`9NXdYvjwMy5TK2evKwcaD;U=gI3BNuA3m@;QyUHg>zD>r1j!q}~ zvfFzmnCz3JbO>7|gG;H1QlOb(f|9MqX9=F)t!#~p`7&^<1O$;*ap(WY0Kk41EfTCk zFrSpymPE*#mS{d2r4Nn!woC5r^3ev3p}XpH1p6gGm-Ct)^p6}ViI2`kr?H|-j+5}* zXqg8K_;22D!HO_^T$Dw`0NDyX4#tE^wTpMcgNd58&kk}Yg^|Rz!bX4}#)2S{96dQB zE;B&--0{d)*QG_twc?GoPd3;$jQeAzgppQXET^OiMwMw5erE|#$cqQ}wImE&_D|AM zvQlu5E%}r*HBDQN)|ZUpy5HJOX$#{xz(^>4>wry9ob+JUkKbI3PN@q~6e=)=Ew(Z4 z2zy1h9ujdU%2C%2lr63QY`=dmhApi9QSz*3)ivn9EZ2LCguMS|+f8etD5;>y1Kdf7 z8Ed)NpwjC8viPx-4l8pxKvKq^k!@$o5;3yj7C+u1P;n8+syNt>w{=&ICOady^K!jB zzg7Fc0Sp{!^a-h;-<(q1rX3HfF0ST)OZr9XioY==Q0h`QuX-q!R;_@@99&i=oZkil z@qTY4#5~nkKfUyRpSjAaftc8GQhGBzi)kNL?i&P;mH(dma+UJ_oIFQHQR;4arqNdo z%silK?boT3lKUryXS}V+_C8rIlMC;&iD1BXf0ir73MeKTXisz0h`H3(W~nhgN2f(T zmngpBF_6&yFm~&f7kJ(Ebl!S1A^yXLmFTb4yx+TT@6!I(+bl}FK)XNu7P_h0wDP^f zQ<4D-4A3?V6ChvO{F@?+YbuE3i~zm^K6d?bn1LQWU3q?EOd%R$YAlN1XT%WtarKr~8%e8wbO5{C`aBNa{73BVV<(97} z#hnQ&_As4(ltufs&8sRP#U3LbhO8D-Ngs!CrXFX41yjdlzdN5;JLm#-4#F_XUj8f} zm)bboNG1yHADl#3_tH}%{Gm|^{tierYaVA!?PJ#%tUjSO0H>tzGLy491g|CXq@_`| zNdvH^R#2Rgoy-L8a>$)lbhRXX&pbD4n3YS01cg58s1V?BkO>#Lfrh7ApZi(u*flm_ zO&kr<(=9c?Vi``YVwq8Iwm9ZJ{}~dEY!lqO{EO#D6VvD0>xK`%y;fa*nE6cyZZN0@ z#=7x*QjE35zU6Ixp)7d_ z3Q7@Mh`a(QgpSyX7fzu@WJPoWw0rK9;P!g4GQ5C2=3aq{f_BFSH@X5ZUe;IHKjh|g z;7j^=TkcTVGwC}vj5mqgJv>1Q`>+4bxsDBEqdm8vRW^cdLs;=kU zUgO8Dt425x6M#uS+{M<~Nuy+ZMv^&BHXs#RI?)}PsWXzf@n6^20Xt2b&yxpZWi7uG zNaW?UHCKR`pz)XMLf7wb^72R}w-grlQ`{qxy z6q)`AsT0=7x&*f#I{9TNNjQ>LDa}YCAR41HY z8~Vjz?wv;2?QR-eIwmEU2&Gcy?`L3|jG_A8k8j=?5d2>B1qhYnMO@uo?-Ca3&uw}X zzER6UR?A0{hvVbgu0NF;4V568?`D!CYk$`rGByG1?CkD~1?8U;+R+lSZ4bN4*AFAj znH1zNe-H+iz2Y(wDYiR2PFf~^ZF{d_2h9XDAJk1GdsJB--B%A5S|9?rk=2|c?2UW? z6OKUV{+_=tmOuq)^WCk~%URVjGUxsDL3N%?>Zh`wERET+=sMqi29e4jiI!BTFs1!G z>3xWEWO^k2`%DPQ$Ij9`X!QA57I}oeXToaIba(Wp&C*qrhquDIFfvOJ&}-Q|X$$04 zX3`!e@+pje;uGz%90!DWZfT(B8R+Y57#r(po1kcYz*o`LHoX1La5yCWLg_xJq4UM+ zsxcsL+TYZ7B5Ku4`O(SLY<( z%?>8so#PXzPOFoj>WkdUUdK^nRw7mgPsOL%ZdD!@In0;X=h`_YlP`wWkP5NO;M`q5 zaQ@AF*%hj(O|3h9T1aUcuWj&N6OpABSBbPlL%1>m1)%p23I+DM9< zl1jk`w?&?w2^qBJ|6)-R2CjYx$V39l$P`-uxv0t25}i%IfwAsQ4Chxu%0^U_>3ikk zWP16N&A~vJ-`!Vufiu)y^WV3-AM8t!q)D93puhBp6ZzB|9a!GLc52h*scB2VSt;l5 zk}R_PkYC}YQP0k51F_6qMr8VFCY;2OzzgvQc=_OCZ|$|ucYR)nJr^=`fhHgy>tr|Y z{!8FD^pEIwUxG^)i-msS6a|ryVSY>K6uOHV5<2q-E{-Qbo#T~>}8j9(>mRx-`1DWU#5J2 zybO(?A1UTI$PIqDE{(xiz#X9Sp(+%D?m<1CLhJp`<*zv;Y@0gU>ZWyXL%2dzhqM%MKT_lmJv3Fw*q~9!06c5)DRb zJ!)9Jv$4426+Y*HjwND~#9;b|Bsj)@IwkWsR*>fUrg>9r#dUwA9gPz7-`d;Z{^J_L z{8TdSF7_>j1@g4OYGJM0!8YGrRbGMEaJV}c14Q2N^&t-ZBB~DZyX-MB3)C3%V4l<} zgLGz9rVd|RXGDi2HEY}|IMvkBy~py14YOHC_V6#0@5tY{ZTKc$vzuV_o<2*`8bol*qEMMV2d62x8ja-27$xC;nB0=iQBVou3M0 zX71Ec)t+0|)pu%W^S8|7aE~Nk+~>vnWm5FG`!*8{gU05u&*KYCTHNCAJ_EfCy$;p3 z65bDpz4}d!by3yOf1<5A;yA*dvJ0%Ygm5F-IXJz;69%)@fKV||;&2=LpTjrrh;9tH zS3_?< z^}W7#T5BZ3c&WnfWrecfMJiZg9M-{iOJ#-`3=VpkUr(3O%)L1`oGnS8dBzAs;$kyYL zmbd4GsO>50TQ|u9H~zXw7Jf0Oac(*vS!R#=C;o1+&8~}lfBL^x-fV|h56@hPhr0R( z5Q9*e4^7=?Ha5nD3quP}SK;Za4{3vR|1gWw4^B}n(#;yHcg2r4J_|}MBSS+G^OLac zNzl}?LrSMJA_%%;|0FrLy`RKxai4UZA|)Y{-D68JfR^+f+jl5By1rbymh(eJG?$@B zg^oWqFWzqiNadA3?ydiJ~0gmuAR7wc)bu>*$(m8WEOWeyyzqq+apIoZ7C5;mVN;qWNtq%v?%1koQ5IwdL&# zq)gPj1fMM6pm+bFLZgE%nj8@pB10zK!kg}W;UwJ9b?Ods2_Z9(CO3~Z) zu&(25@kz%r_wHIT7|u6sZ$!|;kYV)AZ{xzs29p~n*Cn)DK9EqD$frGUnvB}gRM=E~ z3rVd!6~pP*-sdQgivv*R?VOzs*g=2*Bt$2FvK_V)=@n~(NsB@!0(@^i^CdDCP5)<7 z2wi#yltCFihdzOIH`}i~;0NIHHPwA?13AiJu`jVaNeRTXM}~V>n?TmGHX(4xHgk`d&&|{b_xnDAk%)*c%79A@GCe@3gNh|Kc4{ap zv?4&oR1BT^8Lk`@zawIB1eN`W4`oPx2h87U!ALNK7v-c_w zucWOrY{t1N|1eWst!Cjsai*4{6sA5GrfDATfbk$f^n2d+g8Mjtno!FKM1xRfV;$mD z3SnJ3U`8vErM^nAXYawPp;UIPn4qn|q@9HWrj0_Jg{U9~nOzc;0YLqPcjoh;2UH^BphwW{@NpZid|{3i@0AgwBov)w`zQpHAecyJf?liz$1j7twp)^_h?LB$VfdU~xcxqC<6cc>CUa4`(}3#b1@Swy5VW-nT_w9~uNQ+A|M zyoJGkJ26Z^r-h_Hh=2i{FmHHotb8;<>kJWH9Cq(#%h#!eR9L$j>%|%xF)fr1q56tm z1U65!3G+`K3*3)ul04n=)Z!fA0%@REFli_c+dorJPnXH1A})&F$J&vdv10h+0_Gep#A`0sbo$Ci$QeAryoTNB~)SdWm6FFIHI=DFX=?_B=87?FF%*`<>9ED>)CnR_256XgC(rOh(0Z1t+d+ zhRpP=NRSLGbin)WdJZBoL}-TqG+_AZK2Lj#T*QUtiR+JJRte`V>3CE%(_X)!!R;Ug zAsB2C-~cp^;5y-r&$aX=G@$6oN~K5?&~MUT+cc! zu0CRem=J~rKR#3i-IA;ko~m~r4LKl&3P4_GC8&tZ=*>u&4LXoJm^oZDKk0Iu%Jdo& z46UunapI+5%gu@$DV!XrFHEe@a84WCuWZv71H2dGT%IWKXU`y*P+SyYKpw zrM9`!x?*g;ak%UC(Gu4Wpl4uNsN1SRq9D=GuFA{_@FC(LSfI}DyUW6eV|0|`8os(i zzOTGgoA{~05|@YsJUml>W%_%8uAa%3G|b;x{uQWVj$*-wM+i1Zh6cO?;>ZzX**gZT zQ35R2rlJu6BgoJ^DFr-W1t=5K>v6WqkPC}a!{A8rO-;P$qD_f42kTD)4pqKulq`u>qj7FIIb0cIawbJ{Oy0?3-Lb*xzE7I_~>&HcxOvBr- z?4R6Om1~q$!crq7eu+q2q`f{=Uw4ufe zf|sj3)Q0XRuH?BcL{9u0z>=^DiM;#!5YdZqH(|AetfI1hB8A@u8R2Sj zzWv)LRO0A^K_|HSun9*MA<9zzk5cBB8#uDn>I2u}cqzbyYZlS8f?{fHQPL2QgPRQiP=&+r|Z|B~QU@4a}s`KPTX`O%Eh$giviJIJ_0l>Du1B;@`;wGa@7g&#Hvf6_( zgU(7j2=>0WtHoncKe+nU+ZX>i&x{qaqwO;Za{3Sq9NxE%%Q~XlQ)&b<5L6d?!SAVL z>&m7^r|U}DKoAkx%lFdasuP)420!qB{Q6_^un+f)A|P9$~>T{`KHVU$;4*|tU-S{}L&l77#YQ8ZrjMUN>XdQu?M{%CyxcCcnt zPOM1X14>ALl`28Zt;)L>@n-Y)ZJ_bavv?hEu)2?QHx@zne-_siX-Wt;e2CN${FXST zFH56{MSuA|m|cx6@3E&d-<2vBuev}k85bh2@at2@9g~$IX@{P?$%5C7pne?zLN&WD zV~5`kqSmKK;|ANUmd?JU+Q?kzy&A%-`Ilu#)X;qTQxq^yT|PCoKa3yERuLbp{e{oW zP=AmU`P)l#J0tkMgANiItwA8qGxn1$!WZYw>Q`sc*VIhp7|bm$@&HTjDM8HJWB?RHTWT13SX@aau$fsINTJP+xmh2! z!-O9Lxrb7dC0~Z#u|~a3FoCqzbJ#bU93ZW|I$6Z*SBJliW;EZt;f^Z>{G!yxa(J0m zbO{`!8jBnLSWoBXqcQ;H-^{eIT|y2rzzyE4?Jb?b6WFkBKSKB>uR5|-It8u9fCK*B zz)PBpVt0Lv8wHVCOz5NVcF97>yQAZ6SfB4dQ9GY$$CghPElTfjGE|*rD3#L@#q^}w zBRm<$n*0sF4)oB~=)CIz^_>5>%0xgM6^{S*4~J(?^s&mXc-0=Ex?r0Yohrj#NTdJy zN>v249f(l}Jk(Ou;;orG^h(nw0C6-9zH3$L*Uf)hFHn~YPu zN^qq7dIT9W?AEk3+f*tSW?_i#g>LROX-uU$QlP-Lz%|wcGE5YJ#%^3X1}Nbdp=0|u zn47tR3Wr0u9vUKt{4fFABEN&tya$&8pUS~dkqmrxunL{9o!ElERef|w*e+Bh(K+aabvhh%hlrbxy zV#doUPwn^L~O|7*X+7UyOCFp~~NQ%}9@yI3%^!j@%M|kl2Q_MS5m+$AV z3XlLus3}C3?ANS02`d9eQ%W=tb{jLMnk+v(b$<0;b2kG0gW0!$FO?&>G|5vADBm$q zeR_~aAnqONl96DV!%$hS$Fz}8I>ygS$p`r&FVYjadzD|o^W0;TD_Q^toXBbGtD29( znmNB<;>DljFBMW$U<|JEQ9KMLM0@gPa*Ah%W!_o`5!gy=fqyvDD=YD87(Ms(keJnV zM>H{!I*Z%ttv|gie~|i5k_SQS+ZGfH^)K&rs;9IkXIVi)+;eo()+%Xk0z({af9w+V zC?@EWFVxuGe~rhfPYJM2y&jgYPjax&U6WBlQE@59C#Ue2glqQG#3h{A!^dME1u|Jn zSL#w9VA8zt4bV#3->YmT(GD#C)$YBK1 z3Nz^8lZ?BM_81+H$nJ2q4k>>-0TCc`?So0O&LM^_g~kU7(H|O+CUJkXxNS$r+hk7g zl8S?gyqu2W^0`EucSJg{u-l3BuSk_b!{;sD2t66cQUn!)c$z_ug+KV{aWj-o56PTl zr1^Q8yogTs*Q4B+jKkX|nYxQ=Cvg9yrOtTt3LtTX$HTn#kjUZ2TJCbI); z#g-<1gs~+7u@WgXEly{5P7FWCK&oE3U4gJp{zcfIlaNaT{UNy{#g?IVPG8 z7Q^qp0m&itu?ht8ARWuIZg4*Bwi^okOf5l>JHr6rveyR@_(>LUr|F_(MO|g2@0j8F z((4-nxI(0>q#G`hpE_G_@#Z3jhVC>EQY#W=YXS|J5v`YVhxKxGgaVdm5fmjNAq=T^7CU@Tr3q?*w za7wH+3?o6rvLtX8znrG`&HQq@O~z55m`R~fEzZgqYX2C0$a>x2>gYe^nRXLOOyRgk8;<=uMOavQ14Y2(g*h zjA8VkN*h=GoMTbD@w9KluWq*=D|U5Iok;_P2GH*B1$T@|O8EAH+g5s+2-C=}b2aTU z;+V-+KcWjE!MRN3J{jF7-DpXA;3Y9))D8(%DpM9CM@Oi@O7E|iT1iqMe@>YQWrBh3 zA(N)kwh?W}ucGj@ZwjF%V1jJU0ATR{OeB z7K%im#@%wsCr&T0S~by#)8Oe)+IAuCGCsOzkzF ze1ciZAE3s8AuEUAC-gDgZ8AK3z!u1ssRj+*JrsYhrmyUfrT1Or>3o_3DJiDM8p~mo zlRU3i_+tN-e53m5uhr1HlVeJ@<6M?~!i=tdp%QO7>2OH6Z6?L@29f=Ck}|7dbqvr( zV|H+S&40Z!YLJln#@L;Y-B!;+QGKK<<7n=okXOyV<~cratNG?zXpL6ZgQ=~DoD(T2 z6;<4vY#4nslt`^)F&IeTSE!>yd;zeJU?2X~Nn1r_9?5-^#~Ja+O_VyLQ%Q$lwD8 zWr=%;AoGv`M3BhIU|XeQW{9z_MEKm{PF^pGY?sr#ysHt*oiNeu%fU)dfs)20HGkoY ztGJDcDU0u!PPmA?wl$|8i8<&yZo|UK2my+m8rZ&W3;$s!a{6WT$shv|`Y)1lSQ2&{ z{U1>r(ybU1*f^6m`~GUOSUa1TyIL-iVDh{w&2J&Y5QS`Xg~bCK{Ck3XVMJeiMLZQV zG_=ZnJM61v-Z4Yp%|)mG*^)8DSMsbs>nNQ^MFF1JhUVBIJnWCNX3+cdVp8#B&*H| z4@P(aima#+lbgV^Iw#wAAK_A7-oj+|IjTQca{SjbRZ6DdaUC3=TLN4tPX8kc&1nzs zZ={HPTqK>1Lj}4Kj7mJSJwYeZoxHzcAV;dI$`Pm{IbvgWiBKE5X^W@BGLNQV;DLpe z^S2o53LfOchPgN8g-FX6=+Xo7Be1V#s`u*?adYR|9|lPoX(l>8Vv3-8@L*#!J#R)3 z3ghLeKd}fijW}Ji@aMvaHE0-lrvoJnpFeWu8Hck6cZ295%7AKUUZ8o~&qc`dW8c41 z7CW;L<#QC+6iyT`;V5=;#jLkyshy^}2=UCwihoz;EBl)`RbF6+u}sS5yn26cjqHD; zs*5c-ee0}$o>%rxvKqv(+OWR5CmVBl$NnYR8{cMj4vz(*^y+>u);e_;6A+-HQUcGv z@V`D{x6TC$|Gq|5oB#rk=93{oDcnn7;!WkTc2Zm6a)3=-ygy2WU@y=s8Kq6udh z6O*2h?fs&QQNX*mTVaXfqkJ>|40;wJNMwoqy$LJF#LweB%g~ncz>?yoYJ@-~`%g3f z5sumw<#+J?tgNysakiMP@)oVLLC4g)HA07gTxT8mYeo zAhV_7B^Z^9j@v_>*Z_wP3?wOKJ)sYH*Y0v-*o}s%eb*Nt#XdXWOtoyR+B1=ACopNV zI4KMHcRFCLSJTJZKfz0=b{1IRt%^nYf1R9XQxn|N#;Fo|?+Bp^CelHgAi+>YDGH$} z2^~a0x(J~Kq)AHv3%yHdN^jDU(2JoXAOR$FkRrv0d*=TMo;T;ko;fo+v$H#McK7

MJ4Xv|-9GS91>Sj0VLu7N=w!gZDZfcaHVu>V?%RaMIcnFqr!f;FnqNWs-^p|__2 zR&Ltv=gvP*h?VPJgK1XjJV{Se0c5~#uhXzA>OLpVgXzY#iJqSoTzYQ0kF*_QMAZ=z zS}-t0*rT`@ zI0>hU`Qzbs+ZiLcmU+4xS>48Pe6e_j1x?Hw6=r<^+=_>qwJ4 z5kRsvg}=Du*Y;%18peA$3EYrSxooM-8vVkkJvvWQ-Ot!-L20dxc_f=~1J!9I*QPs?SXW7~z$Lboz`b50@ z?1ky>k9j`qjNJNBmp+Au45FVbu1A-$d~h);Sz_eu@%=~7{wZYCV!^_CmGMwS4=ASM zL8qf>nLA0rQEJJLy&tcWA9wtWP8d09>6b8zlTdJAHAUb`i#`EXZ$XupIizl!0T}g% z*djRt_y%&|B-I)D6pQX(^;RZ+$#sC7?Ch*9kC&W(_U_^E!Vs*ul%8KIPzZ0ML7n;)(*a{V9R^;SV9o+zWev*as1Arjq2p=EZWu}oyo?=M&)^7OU8`uV)VL; zsc9;dl^9{3GAOa4xdc0EHwO=?qf>#^OWZ89nTRpkjaoG)$b^7!M6(XDZfkxtsC&%% z-sMkLVw5!#Ex-hPw@5Yv_jvCXp3*6+-i>h48l2xeH}GXb{iUJqeeYm`iVeLu>Vw{W znasf00tugUY4WBUHd;dHTLLB2e94w$@2f|P=3b1|1x%Zd_WIp^Fx|owNvT_tLFn(N z7UI={Jhk*Y+*$Cos`J=r&9Z9P^@#h^o@d()S%-+E0R_C3=rAXLrD9bGvu@c)yY(z} zw2K30QDKi@%8@&#&gU@x=G414 zby}L;&$8OW!WpFS1|^S}wjbsS9icIFQZq>czIk@q z+Fy}4CeM;P#NFL!fvDu% z#o5+&EoZzBxvyMqWwFyjlX{dd@pZ5N#p!t+eXG+!L)&qLh*=DKb|b8TeTAI|U#;q# zuTKmhyjrZ`^ZGpjs^7lw8;HKQx7{&S-x|}=^IE9j(6k!ldj&*4;`>0t@|4!n#9>f%%S<^@!ZtMyT~?f zo+V=C@>_VDK3iU**$7{gYKQO(v zA0Jz&$VcRx<7zy!+%c`v){7*${wyhP+&f;{?Mz4+fRpqdv*A@-M$Gy|TEE z#bGUCpmvsnw(TZyi8RxVBh9a;FvWXoksNC8kmyDy^L1KB&gv&zIkF3vFP3~$BndPn zSN@-D+%ZGiU=02~Z;jaC!Yir7h+iZO%4?V>VZn;mfAWH4d1YyTLh`%_$vbjoVjRmu zydtQ2bWzok-Q`vB{Gce956N6+0{r;2yOS=1rbX6_w;YrBioA}G>aBv=9rm4T4O2L` zopi}V%R${@#LM#()rLPiO2?dKg_f~aPQo0qu-hq5xC`*ux{;mLw2jq0LPpw?!4I`e z@7W7rmhmF=1^DG&hj8rXNY+x3)vMFkr#neBlO6M$D9Ve zZz-AG%v`A*n5ySx8Vwqjtr!HVqcp*9juC>9#sO)~<*R-><4JbeFoTB~HlZya%3(^9 zZ&RRz=KbZl^;b?>@AMv(Bq98`MRqmgP(iI?zzP1veoH8f%fD8Xsj*jT1!Oy(FkWs2)~iz&m*qBLWA z+5~9qEtR$v6BarO_xR#rV!01PRdk#Zm=cp~`#s-UgmbC*_UF&PmG8^mS}^qBg>tp; zKh*;PP(>_!MnJNcPZ~9yU6@x4+0mS(1QI~$xSCwFg-cD@7@v0Y*J9XWTyQDdk2FRv zHY@dRPEh@+-1OZ?ziYGeZaGesx|Qe|dQNj@WxsV7n)*EX&9ARnRaFlr<1`uUd0dr2 zERyRSFE;9J9b(+yiFGdLCbg^ZU8~|c)MYU{*q{{KN>snPV7+*Ks!@-BvQ+eaCXip* z*tb;1(ZjRFi&|&@pPO5)3v6Ji$=bDab33Xvd6jaY|2rk$ZwFjdPbpD0?!qbyx-Co* z1_-D;Kel?la5dcD>-PNFE2A|0Ujsngcrl!Evd95BCM)JT6_vkC7!Y`~x1%NiOXoZ} z(D44XvBKCtp+M!(6-7Bf2Ld=Bgj1x}N;2?f4m%?&#*Cf(;a%GK%4Nr7L0-+@rhf9e ztBA8If_rT0YN`OW<6lx97hufFAQC~bU2KWMJ%I-Zbp=Y>f6?RsQUsha_&G7U$!|>a zeH9$~DOoh38Z4VE52ZF347n4^-ANYLrH0Vg7aYer3P(<$6tU5a!8Sn)nlrGnp25t> zTJYCkix=uw^71T$T8`3b=m!!Mrbke?sKXiKM=pH$0XKdy>h|{S@(zc{BG~3x`*#<| zpS|-w^_IC9iPt=k?3Z7nJXD+oQ2@|QZ&3kV)Beg^fMBspLQSseXVtSvWra+Zv<2&q zE+&3w4!W+~Sg9(kY5@^5J+oU*#Nrp~E$%2h*Z+Gv>l0?#JoAA2y_N zu)l_s*ep{3IvV-mFbh2?LqF5ic_W13N}=iM8!u98I%zDFT^8F&ML*28kr&$6&W=1v zj`)&14D#XD>q5jEo6soUCiU9wzr}#l<>9D?8}jS3aF{~ww+0iR{ugzE)>)^JwXU(p zuY#>DEWIXE3KmpvIQN`5b`c|F)1BaSs~@=I%CYW3H{%@BLt+81zAXJOYwY3vr3aWfnv z1Lwp%{f} zt@O7lq@nfkIK0;qARmuI5QHThLh8K*Y?(1z6>NL zu|m&K(0(~RmmFtEVli0doM*ypLKYqHkCuw?Ju^AV zCq`qL<7J1KKERner*?JwRs&A2qUCiy!;L&$DwGvO`Rys{~vdt+OLJHTDcv5iAc@r%saMQn#L6aSO8v=}>X{d5| zpYOqkmMgn^jypBp?-T-F>y&GjYk33gPA)8N;_16X_B&UAz*v;bzD$VlU~XCdPM8^` zS|K@5B(c!=a_)o=t!kbaZQHqmf{Ho|qa#}{4H$6QwCU<|3bRtPbka;8XzvJ(&39J3 za<%(fe3^sE64_U?;>r#s2-2R`~bXLN3_%LnbPaAz5b38jpCV*O{n@O)xi zDAUSJ#Vd_zG7>=)y+H!wFZ}|)~v|oyV1v}K8@BCUzB{JZe9}Aq+c$SrCa=hPZ=Ca_Z zla|e14;&L{wg4_6(C6+{xuR>EHw-Q(?TQ)8G5v+HjZ{>3iJ(%P_fW-4g3PMufb_!1b!PhFf_3Y&5nf{+ z+c!>?G`o?cLyN*31S1dB3=F-7;ng;|^g4U1UFa24pq7RSQ`F~0;*UDdm#(A>0-x=h z^WHFx>sCt#LcTk#wXCC*3L-NS?jDoAk=8Er`|2Hk*F`)JWWKY*5CrEU3ytK|a~+fL zhJ187%GS%2E>;bUW|KDHrQZ(m_V@JulUWup+n8Ziv2YnMTJooSmiEZ>7&`G;^h2>L z*tua&ndhdVXywUud!^NHd+l=s&DP>wk7pND&z?_zq-{k0!SO5S3 literal 0 HcmV?d00001 diff --git a/mkdocs.yml b/mkdocs.yml index f65bf86701..c7892ab8aa 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -1,867 +1,869 @@ copyright: Copyright © 2023 - Sekoia.io edit_uri: edit/main/docs/ extra: - social: - - icon: fontawesome/brands/twitter - link: https://twitter.com/sekoia_io + social: + - icon: fontawesome/brands/twitter + link: https://twitter.com/sekoia_io extra_css: - - stylesheets/sekoiaio.css - - stylesheets/lightgallery.min.css - - stylesheets/poppins.min.css - - stylesheets/inter.min.css +- stylesheets/sekoiaio.css +- stylesheets/lightgallery.min.css +- stylesheets/poppins.min.css +- stylesheets/inter.min.css extra_javascript: - - javascript/sekoiaio.js - - javascript/lightgallery.min.js - - javascript/hotjar.js - - javascript/posthog.js +- javascript/sekoiaio.js +- javascript/lightgallery.min.js +- javascript/hotjar.js +- javascript/posthog.js markdown_extensions: - - admonition - - attr_list - - md_in_html - - codehilite - - pymdownx.details - - pymdownx.highlight: - linenums: true - linenums_style: pymdownx-inline - - pymdownx.superfences - - pymdownx.tabbed: - alternate_style: true - - markdown_include.include - - lightgallery +- admonition +- attr_list +- md_in_html +- codehilite +- pymdownx.details +- pymdownx.highlight: + linenums: true + linenums_style: pymdownx-inline +- pymdownx.superfences +- pymdownx.tabbed: + alternate_style: true +- markdown_include.include +- lightgallery nav: - - Getting Started: - - Overview: getting_started/index.md - - 1. Set up account: - - Join a community: getting_started/join_community.md - - Create your account: getting_started/create_account.md - - Set up account security: - - Two-Factor Authentication: getting_started/account_security.md - - Security tokens: getting_started/securitytokens.md - - 2. Manage communities: - - Edit a community: getting_started/community-edit.md - - Create a sub-community: getting_started/community-create_sub_com.md - - Set up community security: - - SSO with OpenID Connect: getting_started/SSO_openid_connect.md - - SSO with Microsoft Entra ID (Azure AD): getting_started/sso/azure.md - - SSO with Okta: getting_started/sso/okta.md - - 3. Navigate on the platform: getting_started/navigation.md - - 4. Manage users: - - Invite users: getting_started/invite_users.md - - Manage users: getting_started/manage_users.md - - Deactivate inactive users: getting_started/inactive_users.md - - Roles: getting_started/roles.md - - 5. Manage notifications: - - Listing and creation: getting_started/notifications-Listing_Creation.md - - Notification examples: getting_started/notifications-Examples.md - - 6. Manage API Keys: getting_started/manage_api_keys.md - - 7. Sekoia regions: getting_started/regions.md - - Sekoia.io XDR: - - Introduction: xdr/index.md - - Quick start guide: xdr/xdr_quick_start.md - - Features: - - Collect: - - Ingestion methods: - - Overview: xdr/features/collect/ingestion_methods/index.md - - Https: - - Overview: xdr/features/collect/ingestion_methods/https/overview.md - - Formatting options: xdr/features/collect/ingestion_methods/https/format.md - - Forwarding logs using a third-party application: xdr/features/collect/ingestion_methods/https/third_part.md - - Syslog: - - Overview: xdr/features/collect/ingestion_methods/syslog/overview.md - - Sekoia.io Forwarder: xdr/features/collect/ingestion_methods/syslog/sekoiaio_forwarder.md - - Third-party syslog services: xdr/features/collect/ingestion_methods/syslog/syslog_service.md - - Cloud & SaaS: - - Overview: xdr/features/collect/ingestion_methods/cloud_saas/overview.md - - AWS S3: xdr/features/collect/ingestion_methods/cloud_saas/aws.md - - Azure Event Hub: xdr/features/collect/ingestion_methods/cloud_saas/azure.md - - Google Pub/Sub: xdr/features/collect/ingestion_methods/cloud_saas/gcp.md - - Integrations: - - Overview: xdr/features/collect/integrations/index.md - - Custom Format: xdr/features/collect/integrations/custom_format.md - - Application: - - Alsid / Tenable.ad: xdr/features/collect/integrations/application/alsid.md - - Apache HTTP Server: xdr/features/collect/integrations/application/apache.md - - BIND: xdr/features/collect/integrations/application/bind.md - - FreeRADIUS: xdr/features/collect/integrations/application/freeradius.md - - HAProxy: xdr/features/collect/integrations/application/haproxy.md - - ISC DHCP: xdr/features/collect/integrations/application/dhcpd.md - - ManageEngine ADAudit Plus: xdr/features/collect/integrations/application/manageengine_adauditplus.md - - Microsoft IIS: xdr/features/collect/integrations/application/microsoft_iis.md - - Nginx: xdr/features/collect/integrations/application/nginx.md - - OpenLDAP: xdr/features/collect/integrations/application/openldap.md - - OpenSSH: xdr/features/collect/integrations/application/openssh.md - - OpenVPN: xdr/features/collect/integrations/application/openvpn.md - - RSA SecurID: xdr/features/collect/integrations/application/rsa_securid.md - - SEKOIA.IO activity logs: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md - - Unbound: xdr/features/collect/integrations/application/unbound.md - - Veeam Backup & Replication: xdr/features/collect/integrations/application/veeam_backup.md - - Cloud and SaaS: - - AWS: - - CloudTrail: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md - - GuardDuty: xdr/features/collect/integrations/cloud_and_saas/aws/aws_guardduty.md - - VPC Flow Logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md - - S3 for logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md - - WAF logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_waf.md - - CloudFront logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudfront.md - - Cisco Umbrella: - - Cisco Umbrella Proxy: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md - - Cisco Umbrella IP: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md - - Cisco Umbrella DNS: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md - - Cloudflare: - - Access requests: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-access-requests.md - - Audit logs: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-audit-logs.md - - DNS logs: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-dns-logs.md - - Firewall events: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-firewall-events.md - - Gateway DNS: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-dns.md - - Gateway HTTP: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-http.md - - Gateway Network: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-network.md - - HTTP requests: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md - - Broadcom Cloud Secure Web Gateway: xdr/features/collect/integrations/cloud_and_saas/broadcom_cloud_swg.md - - Cato SASE: xdr/features/collect/integrations/cloud_and_saas/cato_sase.md - - Digital Shadows SearchLight: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md - - Cisco Duo Security: xdr/features/collect/integrations/cloud_and_saas/cisco_duo_security.md - - Claroty xDome: xdr/features/collect/integrations/cloud_and_saas/claroty_xdome.md - - ExtraHop Reveal(x) 360: xdr/features/collect/integrations/cloud_and_saas/extrahop_revealx_360.md - - Github Audit Logs: xdr/features/collect/integrations/cloud_and_saas/github_audit_logs.md - - Google Cloud: - - Google Cloud Audit Logs: xdr/features/collect/integrations/cloud_and_saas/google/google_cloud_audit.md - - Google Kubernetes Engine: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md - - Google Cloud VPC Flow Logs: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md - - Google Workspace: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md - - Imperva WAF: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md - - Jumpcloud Directory Insights: xdr/features/collect/integrations/cloud_and_saas/jumpcloud_directory_insights.md - - Microsoft Azure: - - Microsoft Entra ID (Azure AD): xdr/features/collect/integrations/cloud_and_saas/azure/entra_id.md - - Azure Front Door: xdr/features/collect/integrations/cloud_and_saas/azure/azure_front_door.md - - Azure Database for MySQL: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md - - Azure Linux: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md - - Azure Files: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md - - Azure Network Watcher: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md - - Azure Windows: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md - - Microsoft Office 365: - - Office365: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md - - Microsoft Defender for Office 365: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md - - Microsoft 365 Defender: xdr/features/collect/integrations/cloud_and_saas/office365/microsoft_365_defender.md - - Message trace: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md - - Netskope: - - Netskope Events: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_events.md - - Netskope Transaction Events: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_transaction.md - - OGO Shield WAF: xdr/features/collect/integrations/cloud_and_saas/ogo_shield.md - - Okta system log: xdr/features/collect/integrations/cloud_and_saas/okta_system_log.md - - Salesforce: xdr/features/collect/integrations/cloud_and_saas/salesforce.md - - Sophos Threat Analysis Center: xdr/features/collect/integrations/cloud_and_saas/sophos_threat_analysis_center.md - - Ubika WAAP Gateway: xdr/features/collect/integrations/cloud_and_saas/ubika_waap.md - - Zscaler ZIA: xdr/features/collect/integrations/cloud_and_saas/zscaler_zia.md - - Email: - - Apache Spamassassin: xdr/features/collect/integrations/email/spamassassin.md - - Cisco ESA: xdr/features/collect/integrations/email/cisco_esa.md - - Fortinet Fortimail: xdr/features/collect/integrations/email/fortimail.md - - Postfix: xdr/features/collect/integrations/email/postfix.md - - Proofpoint: - - Proofpoint PoD: xdr/features/collect/integrations/email/proofpoint_pod.md - - Proofpoint TAP: xdr/features/collect/integrations/email/proofpoint_tap.md - - Trend Micro Email Security: xdr/features/collect/integrations/email/trend_micro_email_security.md - - Retarus Email Security: xdr/features/collect/integrations/email/retarus_email_security.md - - Vade Cloud: xdr/features/collect/integrations/email/vade_cloud.md - - Vade for M365: xdr/features/collect/integrations/email/vade.md - - Endpoint: - - Beats: - - Auditbeat Linux: xdr/features/collect/integrations/endpoint/auditbeat_linux.md - - Winlogbeat: xdr/features/collect/integrations/endpoint/winlogbeat.md - - Check Point Harmony Mobile: xdr/features/collect/integrations/endpoint/checkpoint_harmony_mobile.md - - CrowdStrike Falcon: xdr/features/collect/integrations/endpoint/crowdstrike_falcon.md - - CrowdStrike Falcon Telemetry: xdr/features/collect/integrations/endpoint/crowdstrike_falcon_telemetry.md - - Cybereason MalOp: xdr/features/collect/integrations/endpoint/cybereason_malop.md - - Cybereason MalOp activity: xdr/features/collect/integrations/endpoint/cybereason_malop_activity.md - - Darktrace Threat Visualizer: xdr/features/collect/integrations/endpoint/darktrace_threat_visualizer.md - - HarfangLab: xdr/features/collect/integrations/endpoint/harfanglab.md - - IBM AIX: xdr/features/collect/integrations/endpoint/ibm_aix.md - - Linux: xdr/features/collect/integrations/endpoint/linux.md - - Microsoft Intune: xdr/features/collect/integrations/endpoint/microsoft_intune.md - - Panda Security Aether: xdr/features/collect/integrations/endpoint/panda_security_aether.md - - Palo Alto Cortex EDR: xdr/features/collect/integrations/endpoint/paloalto_cortex_edr.md - - Sekoia.io Endpoint Agent: xdr/features/collect/integrations/endpoint/sekoiaio.md - - SentinelOne EDR: xdr/features/collect/integrations/endpoint/sentinelone.md - - SentinelOne Cloud Funnel 1.0 [Deprecated]: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md - - SentinelOne Cloud Funnel 2.0: xdr/features/collect/integrations/endpoint/sentinelone_cloudfunnel2.0.md - - Sophos EDR: xdr/features/collect/integrations/endpoint/sophos_edr.md - - Stormshield SES: xdr/features/collect/integrations/endpoint/stormshield_endpoint.md - - Symantec/Broadcom Endpoint Security: xdr/features/collect/integrations/endpoint/symantec_epp.md - - Tanium: xdr/features/collect/integrations/endpoint/tanium.md - - TEHTRIS EDR: xdr/features/collect/integrations/endpoint/tehtris_edr.md - - Trend Micro: - - Trend Micro Apex One: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_apex_one.md - - Trend Micro Cloud One / Deep Security: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_deep_security.md - - Trellix ePO: xdr/features/collect/integrations/endpoint/trellix_epo.md - - VMware ESXi: xdr/features/collect/integrations/endpoint/vmware/vmware_esxi.md - - VMware VCenter: xdr/features/collect/integrations/endpoint/vmware/vmware_vcenter.md - - Windows: xdr/features/collect/integrations/endpoint/windows.md - - Windows Log Insight: xdr/features/collect/integrations/endpoint/log_insight_windows.md - - WithSecure Elements: xdr/features/collect/integrations/endpoint/withsecure_elements.md - - Kaspersky Endpoint Security: xdr/features/collect/integrations/endpoint/kaspersky_endpoint_security.md - - Network: - - ArubaOS Switch: xdr/features/collect/integrations/network/arubaos.md - - Check Point Firewall: xdr/features/collect/integrations/network/checkpoint.md - - Cisco: - - Cisco Secure Firewall: xdr/features/collect/integrations/network/cisco/cisco_asa.md - - Cisco Secure Web Appliance: xdr/features/collect/integrations/network/cisco/cisco_wsa.md - - Cisco IOS: xdr/features/collect/integrations/network/cisco/cisco_ios.md - - Cisco Identity Services Engine (ISE): xdr/features/collect/integrations/network/cisco/cisco_identity_services_engine_ise.md - - Cisco NX-OS: xdr/features/collect/integrations/network/cisco/cisco_nx_os.md - - Cisco Meraki MX: xdr/features/collect/integrations/network/cisco/cisco_meraki_mx.md - - Citrix Netscaler / ADC: xdr/features/collect/integrations/network/citrix_netscaler_adc.md - - Gatewatcher AionIQ: xdr/features/collect/integrations/network/gatewatcher_aioniq.md - - F5 BIG-IP: xdr/features/collect/integrations/network/f5-big-ip.md - - Forcepoint Secure Web Gateway: xdr/features/collect/integrations/network/forcepoint_web_gateway.md - - Fortinet: - - Fortinet Fortigate: xdr/features/collect/integrations/network/fortigate.md - - Fortinet Fortiproxy: xdr/features/collect/integrations/network/fortiproxy.md - - Fortinet Fortiweb: xdr/features/collect/integrations/network/fortiweb.md - - Infoblox DDI: xdr/features/collect/integrations/network/infoblox_ddi.md - - Sophos Firewall: xdr/features/collect/integrations/network/sophos_fw.md - - Mc Afee/Skyhigh Secure Web Gateway: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md - - Microsoft Always On VPN: xdr/features/collect/integrations/network/microsoft_always_on_vpn.md - - NetFilter: xdr/features/collect/integrations/network/netfilter.md - - OPNSense: xdr/features/collect/integrations/network/opnsense.md - - Palo Alto Next-Generation Firewall: xdr/features/collect/integrations/network/paloalto.md - - pfSense: xdr/features/collect/integrations/network/pfsense.md - - Pulse / Ivanti Secure Connect: xdr/features/collect/integrations/network/pulse.md - - Rubycat PROVE IT: xdr/features/collect/integrations/network/rubycat_prove_it.md - - SonicWall Firewall: xdr/features/collect/integrations/network/sonicwall_fw.md - - SonicWall SMA: xdr/features/collect/integrations/network/sonicwall_sma.md - - Squid: xdr/features/collect/integrations/network/squid.md - - Stormshield SNS: xdr/features/collect/integrations/network/stormshield_network_security.md - - Suricata: xdr/features/collect/integrations/network/suricata.md - - Trellix Network Security: xdr/features/collect/integrations/network/trellix_nx.md - - Varonis Data Security: xdr/features/collect/integrations/network/varonis_data_security.md - - Vectra Cognito Detect: xdr/features/collect/integrations/network/vectra.md - - Wallix: xdr/features/collect/integrations/network/wallix.md - - WatchGuard Firebox: xdr/features/collect/integrations/network/watchguard_firebox.md - - Zeek: xdr/features/collect/integrations/network/zeek.md - - Generic: - - CEF: xdr/features/collect/integrations/generic/cef.md - - Raw events: xdr/features/collect/integrations/generic/raw.md - - Intakes: xdr/features/collect/intakes.md - - Entities: xdr/features/collect/entities.md - - Assets: xdr/features/collect/assets.md - - Detect: - - Rules Catalog: xdr/features/detect/rules_catalog.md - - Built-in Rules: xdr/features/detect/built_in_detection_rules.md - - Sigma: xdr/features/detect/sigma.md - - Anomaly Detection: xdr/features/detect/anomaly.md - - IOCs Collections: xdr/features/detect/ioccollections.md - - Investigate: - - Alerts: xdr/features/investigate/alerts.md - - Events: xdr/features/investigate/events.md - - Cases: xdr/features/investigate/cases.md - - Events Query Language: xdr/features/investigate/events_query_language.md - - Querying Events: xdr/features/investigate/querying_events.md - - Query Builder (beta): xdr/features/investigate/query_builder.md - - Report: - - Dashboards: xdr/features/report/dashboards.md - - Automate: - - Playbooks: xdr/features/automate/index.md - - Playbooks On-premises: xdr/features/automate/playbooks-on-premises.md - - Manage accounts: xdr/features/automate/manage-accounts.md - - Navigate playbooks: xdr/features/automate/navigate-playbooks.md - - Build playbooks: xdr/features/automate/build-playbooks.md - - Triggers: xdr/features/automate/triggers.md - - Operators: xdr/features/automate/operators.md - - Actions: xdr/features/automate/actions.md - - Actions Library: - - AWS: xdr/features/automate/library/aws.md - - Atlassian JIRA: xdr/features/automate/library/atlassian-jira.md - - BinaryEdge's API: xdr/features/automate/library/binaryedge-s-api.md - - Broadcom Cloud Secure Web Gateway: xdr/features/automate/library/broadcom-cloud-secure-web-gateway.md - - Cato Networks: xdr/features/automate/library/cato-networks.md - - Censys: xdr/features/automate/library/censys.md - - Certificate Transparency: xdr/features/automate/library/certificate-transparency.md - - Check Point: xdr/features/automate/library/check-point.md - - CrowdStrike: xdr/features/automate/library/crowdstrike.md - - CrowdStrike Falcon: xdr/features/automate/library/crowdstrike-falcon.md - - Cybereason: xdr/features/automate/library/cybereason.md - - Darktrace: xdr/features/automate/library/darktrace.md - - Detection Rules: xdr/features/automate/library/detection-rules.md - - Digital Shadows: xdr/features/automate/library/digital-shadows.md - - Duo: xdr/features/automate/library/duo.md - - Fortigate Firewalls: xdr/features/automate/library/fortigate-firewalls.md - - GLIMPS: xdr/features/automate/library/glimps.md - - Git: xdr/features/automate/library/git.md - - Github: xdr/features/automate/library/github.md - - Google: xdr/features/automate/library/google.md - - HTTP: xdr/features/automate/library/http.md - - HarfangLab: xdr/features/automate/library/harfanglab.md - - IKnowWhatYouDownload: xdr/features/automate/library/iknowwhatyoudownload.md - - IPInfo: xdr/features/automate/library/ipinfo.md - - IPtoASN: xdr/features/automate/library/iptoasn.md - - Imperva: xdr/features/automate/library/imperva.md - - Jumpcloud Directory Insights: xdr/features/automate/library/jumpcloud-directory-insights.md - - MISP: xdr/features/automate/library/misp.md - - MWDB: xdr/features/automate/library/mwdb.md - - Mandrill: xdr/features/automate/library/mandrill.md - - Mattermost: xdr/features/automate/library/mattermost.md - - Microsoft Active Directory: xdr/features/automate/library/microsoft-active-directory.md - - Microsoft Azure: xdr/features/automate/library/microsoft-azure.md - - Microsoft Entra ID: xdr/features/automate/library/microsoft-entra-id.md - - Microsoft Office365: xdr/features/automate/library/microsoft-office365.md - - Microsoft Windows Server: xdr/features/automate/library/microsoft-windows-server.md - - Netskope: xdr/features/automate/library/netskope.md - - OSINT: xdr/features/automate/library/osint.md - - Okta: xdr/features/automate/library/okta.md - - Onyphe: xdr/features/automate/library/onyphe.md - - OpenAI: xdr/features/automate/library/openai.md - - PagerDuty: xdr/features/automate/library/pagerduty.md - - Panda Security: xdr/features/automate/library/panda-security.md - - Proofpoint: xdr/features/automate/library/proofpoint.md - - Public Suffix: xdr/features/automate/library/public-suffix.md - - RSS: xdr/features/automate/library/rss.md - - RiskIQ: xdr/features/automate/library/riskiq.md - - STIX: xdr/features/automate/library/stix.md - - Salesforce: xdr/features/automate/library/salesforce.md - - Sekoia.io: xdr/features/automate/library/sekoia-io.md - - SentinelOne: xdr/features/automate/library/sentinelone.md - - ServiceNow: xdr/features/automate/library/servicenow.md - - Shodan: xdr/features/automate/library/shodan.md - - Skyhigh Security: xdr/features/automate/library/skyhigh-security.md - - Sophos: xdr/features/automate/library/sophos.md - - TEHTRIS: xdr/features/automate/library/tehtris.md - - The Hive: xdr/features/automate/library/the-hive.md - - Tranco: xdr/features/automate/library/tranco.md - - Trellix: xdr/features/automate/library/trellix.md - - Trend Micro: xdr/features/automate/library/trend-micro.md - - Triage: xdr/features/automate/library/triage.md - - Utils: xdr/features/automate/library/utils.md - - Vade Cloud: xdr/features/automate/library/vade-cloud.md - - Vade Secure: xdr/features/automate/library/vade-secure.md - - VirusTotal: xdr/features/automate/library/virustotal.md - - Whois: xdr/features/automate/library/whois.md - - WithSecure: xdr/features/automate/library/withsecure.md - - Zscaler: xdr/features/automate/library/zscaler.md - - Debug playbooks: xdr/features/automate/debug-playbooks.md - - External integrations: - - FortiSOAR: xdr/features/integrations/fortisoar.md - - Palo Alto Cortex XSOAR: xdr/features/integrations/interconnect_sekoia_with_xsoar.md - - Usecases: - - Implement a blocklist in Sekoia.io: xdr/usecases/playbook/implement_blocklist.md - - Synchronize Alerts with an external tool: xdr/usecases/playbook/synchronize_alerts.md - - Send notifications to a Webhook using a playbook: xdr/usecases/playbook/notifications_using_playbooks.md - - FAQ: - - General: xdr/FAQ.md - - Alerts: xdr/FAQ/Alerts_qa.md - - Events: - - Events QA: xdr/FAQ/Events_qa.md - - Facing issues with logs collection: xdr/FAQ/Log_collection_Troubleshoot.md - - Rules: xdr/FAQ/Rules_qa.md - - Assets: xdr/FAQ/Assets_qa.md - - Sekoia.io Endpoint agent: xdr/FAQ/SEKOIA_Endpoint_Agent.md - - Datetime representation: xdr/FAQ/datetime.md - - Develop: - - Quickstart: xdr/develop/quickstart.md - - Guides: - - Filtering: xdr/develop/guides/filtering.md - - Automation: - - Overview: xdr/develop/guides/automation/overview.md - - Create a Module: xdr/develop/guides/automation/create_a_module.md - - Format: - - Overview: xdr/develop/guides/formats/overview.md - - Create a Format: xdr/develop/guides/formats/create_a_format.md - - Datasources: xdr/develop/guides/formats/datasources.md - - Definition of a structured event: xdr/develop/guides/formats/structured_event.md - - Definition of the taxonomy: xdr/develop/guides/formats/taxonomy.md - - How to write a parser: xdr/develop/guides/formats/parser.md - - How to write smart descriptions: xdr/develop/guides/formats/smartdescriptions.md - - Best Practices: - - Overview: xdr/develop/guides/formats/best_practices/overview.md - - Authentications: xdr/develop/guides/formats/best_practices/authentications.md - - REST API: - - Authentication and Community: xdr/develop/rest_api/community.md - - Dashboard: xdr/develop/rest_api/dashboard.md - - Configuration: xdr/develop/rest_api/configuration.md - - Parser: xdr/develop/rest_api/parser.md - - Alert: xdr/develop/rest_api/alert.md - - Assets: xdr/develop/rest_api/assets.md - - Assets v2 [beta]: xdr/develop/rest_api/assets_v2.md - - Playbooks: xdr/develop/rest_api/playbooks.md - - Telemetry: xdr/develop/rest_api/telemetry.md - - Sekoia.io CTI: - - Introduction: cti/index.md - - Features: - - Data Models: cti/features/data_model.md - - Consume: - - Intelligence: cti/features/consume/intelligence.md - - Observables: cti/features/consume/observables.md - - Telemetry: cti/features/consume/telemetry.md - - Outgoing Feeds: cti/features/consume/feeds.md - - Graph Explorations: cti/features/consume/graph_explorations.md - - Enrichers: cti/features/consume/enrichers.md - - Export: cti/features/consume/export.md - - IOCs Collections: cti/features/consume/ioccollections.md - - Monitor: - - Dashboards: cti/features/monitor/dashboard.md - - External Integrations: - - Overview: cti/features/integrations/index.md - - API: cti/features/integrations/api.md - - TAXII: cti/features/integrations/taxii.md - - Cortex Analyzer: cti/features/integrations/thehive.md - - MISP Feed: cti/features/integrations/misp.md - - Microsoft Sentinel: cti/features/integrations/microsoft-sentinel.md - - OpenCTI: cti/features/integrations/opencti.md - - Splunk: cti/features/integrations/splunk.md - - Splunk SOAR: cti/features/integrations/splunk_soar.md - - Anomali ThreatStream: cti/features/integrations/anomali.md - - PaloAlto Cortex XSOAR: cti/features/integrations/paloalto_xsoar.md - - Develop: - - Overview: cti/develop/index.md - - Guides: - - Filtering: cti/develop/guides/filtering.md - - REST API: - - Authentication and Community: cti/develop/rest_api/community.md - - Intelligence: cti/develop/rest_api/intelligence.md - - Enrichment: cti/develop/rest_api/enrichments.md - - Telemetry: cti/develop/rest_api/telemetry.md - - Dashboard: cti/develop/rest_api/dashboard.md - - Playbooks: cti/develop/rest_api/playbooks.md - - External Dynamic List: cti/develop/rest_api/edl-gateway.md - - Sekoia.io TIP: - - Introduction: tip/index.md - - Features: - - Data Models: tip/features/data_model.md - - Consume: - - Intelligence: tip/features/consume/intelligence.md - - Observables: tip/features/consume/observables.md - - Outgoing Feeds: tip/features/consume/feeds.md - - Graph Explorations: tip/features/consume/graph_explorations.md - - Enrichers: tip/features/consume/enrichers.md - - Export: tip/features/consume/export.md - - IOCs Collections: tip/features/consume/ioccollections.md - - Produce and investigate: - - Content Proposals: tip/features/produce/content_proposals.md - - Incoming Feeds: tip/features/produce/incoming_feeds.md - - Warning Rules: tip/features/produce/warning_rules.md - - Expiration Rules: tip/features/produce/expiration_rules.md - - Monitor: - - Dashboards: tip/features/monitor/dashboard.md - - External Integrations: - - Overview: tip/features/integrations/index.md - - API: tip/features/integrations/api.md - - TAXII: tip/features/integrations/taxii.md - - Cortex Analyzer: tip/features/integrations/thehive.md - - MISP Feed: tip/features/integrations/misp.md - - Microsoft Sentinel: tip/features/integrations/microsoft-sentinel.md - - OpenCTI: tip/features/integrations/opencti.md - - Splunk: tip/features/integrations/splunk.md - - PaloAlto Cortex XSOAR: tip/features/integrations/paloalto_xsoar.md - - Automate: - - Playbooks: tip/features/automate/index.md - - Manage accounts: xdr/features/automate/manage-accounts.md - - Navigate playbooks: tip/features/automate/navigate-playbooks.md - - Build playbooks: tip/features/automate/build-playbooks.md - - Triggers: tip/features/automate/triggers.md - - Operators: tip/features/automate/operators.md - - Actions: tip/features/automate/actions.md - - Actions Library: - - AWS: tip/features/automate/library/aws.md - - Atlassian JIRA: tip/features/automate/library/atlassian-jira.md - - BinaryEdge's API: tip/features/automate/library/binaryedge-s-api.md - - Broadcom Cloud Secure Web Gateway: tip/features/automate/library/broadcom-cloud-secure-web-gateway.md - - Cato Networks: tip/features/automate/library/cato-networks.md - - Censys: tip/features/automate/library/censys.md - - Certificate Transparency: tip/features/automate/library/certificate-transparency.md - - Check Point: tip/features/automate/library/check-point.md - - CrowdStrike: tip/features/automate/library/crowdstrike.md - - CrowdStrike Falcon: tip/features/automate/library/crowdstrike-falcon.md - - Cybereason: tip/features/automate/library/cybereason.md - - Darktrace: tip/features/automate/library/darktrace.md - - Detection Rules: tip/features/automate/library/detection-rules.md - - Digital Shadows: tip/features/automate/library/digital-shadows.md - - Duo: tip/features/automate/library/duo.md - - Fortigate Firewalls: tip/features/automate/library/fortigate-firewalls.md - - GLIMPS: tip/features/automate/library/glimps.md - - Git: tip/features/automate/library/git.md - - Github: tip/features/automate/library/github.md - - Google: tip/features/automate/library/google.md - - HTTP: tip/features/automate/library/http.md - - HarfangLab: tip/features/automate/library/harfanglab.md - - IKnowWhatYouDownload: tip/features/automate/library/iknowwhatyoudownload.md - - IPInfo: tip/features/automate/library/ipinfo.md - - IPtoASN: tip/features/automate/library/iptoasn.md - - Imperva: tip/features/automate/library/imperva.md - - Jumpcloud Directory Insights: tip/features/automate/library/jumpcloud-directory-insights.md - - MISP: tip/features/automate/library/misp.md - - MWDB: tip/features/automate/library/mwdb.md - - Mandrill: tip/features/automate/library/mandrill.md - - Mattermost: tip/features/automate/library/mattermost.md - - Microsoft Active Directory: tip/features/automate/library/microsoft-active-directory.md - - Microsoft Azure: tip/features/automate/library/microsoft-azure.md - - Microsoft Entra ID (Azure AD): tip/features/automate/library/entra-id.md - - Microsoft Office365: tip/features/automate/library/microsoft-office365.md - - Microsoft Windows Server: tip/features/automate/library/microsoft-windows-server.md - - Netskope: tip/features/automate/library/netskope.md - - OSINT: tip/features/automate/library/osint.md - - Okta: tip/features/automate/library/okta.md - - Onyphe: tip/features/automate/library/onyphe.md - - OpenAI: tip/features/automate/library/openai.md - - PagerDuty: tip/features/automate/library/pagerduty.md - - Panda Security: tip/features/automate/library/panda-security.md - - Proofpoint: tip/features/automate/library/proofpoint.md - - Public Suffix: tip/features/automate/library/public-suffix.md - - RSS: tip/features/automate/library/rss.md - - RiskIQ: tip/features/automate/library/riskiq.md - - STIX: tip/features/automate/library/stix.md - - Salesforce: tip/features/automate/library/salesforce.md - - Sekoia.io: tip/features/automate/library/sekoia-io.md - - SentinelOne: tip/features/automate/library/sentinelone.md - - ServiceNow: tip/features/automate/library/servicenow.md - - Shodan: tip/features/automate/library/shodan.md - - Skyhigh Security: tip/features/automate/library/skyhigh-security.md - - Sophos: tip/features/automate/library/sophos.md - - TEHTRIS: tip/features/automate/library/tehtris.md - - The Hive: tip/features/automate/library/the-hive.md - - Tranco: tip/features/automate/library/tranco.md - - Trellix: tip/features/automate/library/trellix.md - - Trend Micro: tip/features/automate/library/trend-micro.md - - Triage: tip/features/automate/library/triage.md - - Utils: tip/features/automate/library/utils.md - - Vade Cloud: tip/features/automate/library/vade-cloud.md - - Vade Secure: tip/features/automate/library/vade-secure.md - - VirusTotal: tip/features/automate/library/virustotal.md - - Whois: tip/features/automate/library/whois.md - - WithSecure: tip/features/automate/library/withsecure.md - - Zscaler: tip/features/automate/library/zscaler.md - - Develop: - - Overview: tip/develop/index.md - - Guides: - - Filtering: tip/develop/guides/filtering.md - - Playbooks: - - Overview: tip/develop/guides/automation/overview.md - - Quick start: tip/develop/guides/automation/create_a_module.md - - REST API: - - Authentication and Community: tip/develop/rest_api/community.md - - Intelligence: tip/develop/rest_api/intelligence.md - - Enrichment: tip/develop/rest_api/enrichments.md - - Dashboard: tip/develop/rest_api/dashboard.md - - Playbooks: tip/develop/rest_api/playbooks.md +- Getting Started: + - Overview: getting_started/index.md + - 1. Set up account: + - Join a community: getting_started/join_community.md + - Create your account: getting_started/create_account.md + - Set up account security: + - Two-Factor Authentication: getting_started/account_security.md + - Security tokens: getting_started/securitytokens.md + - 2. Manage communities: + - Edit a community: getting_started/community-edit.md + - Create a sub-community: getting_started/community-create_sub_com.md + - Set up community security: + - SSO with OpenID Connect: getting_started/SSO_openid_connect.md + - SSO with Microsoft Entra ID (Azure AD): getting_started/sso/azure.md + - SSO with Okta: getting_started/sso/okta.md + - 3. Navigate on the platform: getting_started/navigation.md + - 4. Manage users: + - Invite users: getting_started/invite_users.md + - Manage users: getting_started/manage_users.md + - Deactivate inactive users: getting_started/inactive_users.md + - Roles: getting_started/roles.md + - 5. Manage notifications: + - Listing and creation: getting_started/notifications-Listing_Creation.md + - Notification examples: getting_started/notifications-Examples.md + - 6. Manage API Keys: getting_started/manage_api_keys.md + - 7. Sekoia regions: getting_started/regions.md +- Sekoia.io XDR: + - Introduction: xdr/index.md + - Quick start guide: xdr/xdr_quick_start.md + - Features: + - Collect: + - Ingestion methods: + - Overview: xdr/features/collect/ingestion_methods/index.md + - Https: + - Overview: xdr/features/collect/ingestion_methods/https/overview.md + - Formatting options: xdr/features/collect/ingestion_methods/https/format.md + - Forwarding logs using a third-party application: xdr/features/collect/ingestion_methods/https/third_part.md + - Syslog: + - Overview: xdr/features/collect/ingestion_methods/syslog/overview.md + - Sekoia.io Forwarder: xdr/features/collect/ingestion_methods/syslog/sekoiaio_forwarder.md + - Third-party syslog services: xdr/features/collect/ingestion_methods/syslog/syslog_service.md + - Cloud & SaaS: + - Overview: xdr/features/collect/ingestion_methods/cloud_saas/overview.md + - AWS S3: xdr/features/collect/ingestion_methods/cloud_saas/aws.md + - Azure Event Hub: xdr/features/collect/ingestion_methods/cloud_saas/azure.md + - Google Pub/Sub: xdr/features/collect/ingestion_methods/cloud_saas/gcp.md + - Integrations: + - Overview: xdr/features/collect/integrations/index.md + - Custom Format: xdr/features/collect/integrations/custom_format.md + - Application: + - Alsid / Tenable.ad: xdr/features/collect/integrations/application/alsid.md + - Apache HTTP Server: xdr/features/collect/integrations/application/apache.md + - BIND: xdr/features/collect/integrations/application/bind.md + - FreeRADIUS: xdr/features/collect/integrations/application/freeradius.md + - HAProxy: xdr/features/collect/integrations/application/haproxy.md + - ISC DHCP: xdr/features/collect/integrations/application/dhcpd.md + - ManageEngine ADAudit Plus: xdr/features/collect/integrations/application/manageengine_adauditplus.md + - Microsoft IIS: xdr/features/collect/integrations/application/microsoft_iis.md + - Nginx: xdr/features/collect/integrations/application/nginx.md + - OpenLDAP: xdr/features/collect/integrations/application/openldap.md + - OpenSSH: xdr/features/collect/integrations/application/openssh.md + - OpenVPN: xdr/features/collect/integrations/application/openvpn.md + - RSA SecurID: xdr/features/collect/integrations/application/rsa_securid.md + - SEKOIA.IO activity logs: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md + - Unbound: xdr/features/collect/integrations/application/unbound.md + - Veeam Backup & Replication: xdr/features/collect/integrations/application/veeam_backup.md + - Cloud and SaaS: + - AWS: + - CloudTrail: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md + - GuardDuty: xdr/features/collect/integrations/cloud_and_saas/aws/aws_guardduty.md + - VPC Flow Logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md + - S3 for logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md + - WAF logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_waf.md + - CloudFront logs: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudfront.md + - Cisco Umbrella: + - Cisco Umbrella Proxy: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md + - Cisco Umbrella IP: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md + - Cisco Umbrella DNS: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md + - Cloudflare: + - Access requests: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-access-requests.md + - Audit logs: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-audit-logs.md + - DNS logs: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-dns-logs.md + - Firewall events: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-firewall-events.md + - Gateway DNS: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-dns.md + - Gateway HTTP: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-http.md + - Gateway Network: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-gateway-network.md + - HTTP requests: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md + - Broadcom Cloud Secure Web Gateway: xdr/features/collect/integrations/cloud_and_saas/broadcom_cloud_swg.md + - Cato SASE: xdr/features/collect/integrations/cloud_and_saas/cato_sase.md + - Digital Shadows SearchLight: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md + - Cisco Duo Security: xdr/features/collect/integrations/cloud_and_saas/cisco_duo_security.md + - Claroty xDome: xdr/features/collect/integrations/cloud_and_saas/claroty_xdome.md + - ExtraHop Reveal(x) 360: xdr/features/collect/integrations/cloud_and_saas/extrahop_revealx_360.md + - Github Audit Logs: xdr/features/collect/integrations/cloud_and_saas/github_audit_logs.md + - Google Cloud: + - Google Cloud Audit Logs: xdr/features/collect/integrations/cloud_and_saas/google/google_cloud_audit.md + - Google Kubernetes Engine: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md + - Google Cloud VPC Flow Logs: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md + - Google Workspace: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md + - Imperva WAF: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md + - Jumpcloud Directory Insights: xdr/features/collect/integrations/cloud_and_saas/jumpcloud_directory_insights.md + - Microsoft Azure: + - Microsoft Entra ID (Azure AD): xdr/features/collect/integrations/cloud_and_saas/azure/entra_id.md + - Azure Front Door: xdr/features/collect/integrations/cloud_and_saas/azure/azure_front_door.md + - Azure Database for MySQL: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md + - Azure Linux: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md + - Azure Files: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md + - Azure Network Watcher: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md + - Azure Windows: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md + - Microsoft Office 365: + - Office365: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md + - Microsoft Defender for Office 365: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md + - Microsoft 365 Defender: xdr/features/collect/integrations/cloud_and_saas/office365/microsoft_365_defender.md + - Message trace: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md + - Netskope: + - Netskope Events: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_events.md + - Netskope Transaction Events: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_transaction.md + - OGO Shield WAF: xdr/features/collect/integrations/cloud_and_saas/ogo_shield.md + - Okta system log: xdr/features/collect/integrations/cloud_and_saas/okta_system_log.md + - Salesforce: xdr/features/collect/integrations/cloud_and_saas/salesforce.md + - Sophos Threat Analysis Center: xdr/features/collect/integrations/cloud_and_saas/sophos_threat_analysis_center.md + - Ubika WAAP Gateway: xdr/features/collect/integrations/cloud_and_saas/ubika_waap.md + - Zscaler ZIA: xdr/features/collect/integrations/cloud_and_saas/zscaler_zia.md + - Email: + - Apache Spamassassin: xdr/features/collect/integrations/email/spamassassin.md + - Cisco ESA: xdr/features/collect/integrations/email/cisco_esa.md + - Fortinet Fortimail: xdr/features/collect/integrations/email/fortimail.md + - Postfix: xdr/features/collect/integrations/email/postfix.md + - Proofpoint: + - Proofpoint PoD: xdr/features/collect/integrations/email/proofpoint_pod.md + - Proofpoint TAP: xdr/features/collect/integrations/email/proofpoint_tap.md + - Trend Micro Email Security: xdr/features/collect/integrations/email/trend_micro_email_security.md + - Retarus Email Security: xdr/features/collect/integrations/email/retarus_email_security.md + - Vade Cloud: xdr/features/collect/integrations/email/vade_cloud.md + - Vade for M365: xdr/features/collect/integrations/email/vade.md + - Endpoint: + - Beats: + - Auditbeat Linux: xdr/features/collect/integrations/endpoint/auditbeat_linux.md + - Winlogbeat: xdr/features/collect/integrations/endpoint/winlogbeat.md + - Check Point Harmony Mobile: xdr/features/collect/integrations/endpoint/checkpoint_harmony_mobile.md + - CrowdStrike Falcon: xdr/features/collect/integrations/endpoint/crowdstrike_falcon.md + - CrowdStrike Falcon Telemetry: xdr/features/collect/integrations/endpoint/crowdstrike_falcon_telemetry.md + - Cybereason MalOp: xdr/features/collect/integrations/endpoint/cybereason_malop.md + - Cybereason MalOp activity: xdr/features/collect/integrations/endpoint/cybereason_malop_activity.md + - Darktrace Threat Visualizer: xdr/features/collect/integrations/endpoint/darktrace_threat_visualizer.md + - HarfangLab: xdr/features/collect/integrations/endpoint/harfanglab.md + - IBM AIX: xdr/features/collect/integrations/endpoint/ibm_aix.md + - Linux: xdr/features/collect/integrations/endpoint/linux.md + - Microsoft Intune: xdr/features/collect/integrations/endpoint/microsoft_intune.md + - Panda Security Aether: xdr/features/collect/integrations/endpoint/panda_security_aether.md + - Palo Alto Cortex EDR: xdr/features/collect/integrations/endpoint/paloalto_cortex_edr.md + - Sekoia.io Endpoint Agent: xdr/features/collect/integrations/endpoint/sekoiaio.md + - SentinelOne EDR: xdr/features/collect/integrations/endpoint/sentinelone.md + - SentinelOne Cloud Funnel 1.0 [Deprecated]: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md + - SentinelOne Cloud Funnel 2.0: xdr/features/collect/integrations/endpoint/sentinelone_cloudfunnel2.0.md + - Sophos EDR: xdr/features/collect/integrations/endpoint/sophos_edr.md + - Stormshield SES: xdr/features/collect/integrations/endpoint/stormshield_endpoint.md + - Symantec/Broadcom Endpoint Security: xdr/features/collect/integrations/endpoint/symantec_epp.md + - Tanium: xdr/features/collect/integrations/endpoint/tanium.md + - TEHTRIS EDR: xdr/features/collect/integrations/endpoint/tehtris_edr.md + - Trend Micro: + - Trend Micro Apex One: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_apex_one.md + - Trend Micro Cloud One / Deep Security: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_deep_security.md + - Trellix ePO: xdr/features/collect/integrations/endpoint/trellix_epo.md + - VMware ESXi: xdr/features/collect/integrations/endpoint/vmware/vmware_esxi.md + - VMware VCenter: xdr/features/collect/integrations/endpoint/vmware/vmware_vcenter.md + - Windows: xdr/features/collect/integrations/endpoint/windows.md + - Windows Log Insight: xdr/features/collect/integrations/endpoint/log_insight_windows.md + - WithSecure Elements: xdr/features/collect/integrations/endpoint/withsecure_elements.md + - Kaspersky Endpoint Security: xdr/features/collect/integrations/endpoint/kaspersky_endpoint_security.md + - Network: + - ArubaOS Switch: xdr/features/collect/integrations/network/arubaos.md + - Check Point Firewall: xdr/features/collect/integrations/network/checkpoint.md + - Cisco: + - Cisco Secure Firewall: xdr/features/collect/integrations/network/cisco/cisco_asa.md + - Cisco Secure Web Appliance: xdr/features/collect/integrations/network/cisco/cisco_wsa.md + - Cisco IOS: xdr/features/collect/integrations/network/cisco/cisco_ios.md + - Cisco Identity Services Engine (ISE): xdr/features/collect/integrations/network/cisco/cisco_identity_services_engine_ise.md + - Cisco NX-OS: xdr/features/collect/integrations/network/cisco/cisco_nx_os.md + - Cisco Meraki MX: xdr/features/collect/integrations/network/cisco/cisco_meraki_mx.md + - Citrix Netscaler / ADC: xdr/features/collect/integrations/network/citrix_netscaler_adc.md + - Gatewatcher AionIQ: xdr/features/collect/integrations/network/gatewatcher_aioniq.md + - F5 BIG-IP: xdr/features/collect/integrations/network/f5-big-ip.md + - Forcepoint Secure Web Gateway: xdr/features/collect/integrations/network/forcepoint_web_gateway.md + - Fortinet: + - Fortinet Fortigate: xdr/features/collect/integrations/network/fortigate.md + - Fortinet Fortiproxy: xdr/features/collect/integrations/network/fortiproxy.md + - Fortinet Fortiweb: xdr/features/collect/integrations/network/fortiweb.md + - Infoblox DDI: xdr/features/collect/integrations/network/infoblox_ddi.md + - Sophos Firewall: xdr/features/collect/integrations/network/sophos_fw.md + - Mc Afee/Skyhigh Secure Web Gateway: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md + - Microsoft Always On VPN: xdr/features/collect/integrations/network/microsoft_always_on_vpn.md + - NetFilter: xdr/features/collect/integrations/network/netfilter.md + - OPNSense: xdr/features/collect/integrations/network/opnsense.md + - Palo Alto Next-Generation Firewall: xdr/features/collect/integrations/network/paloalto.md + - pfSense: xdr/features/collect/integrations/network/pfsense.md + - Pulse / Ivanti Secure Connect: xdr/features/collect/integrations/network/pulse.md + - Rubycat PROVE IT: xdr/features/collect/integrations/network/rubycat_prove_it.md + - SonicWall Firewall: xdr/features/collect/integrations/network/sonicwall_fw.md + - SonicWall SMA: xdr/features/collect/integrations/network/sonicwall_sma.md + - Squid: xdr/features/collect/integrations/network/squid.md + - Stormshield SNS: xdr/features/collect/integrations/network/stormshield_network_security.md + - Suricata: xdr/features/collect/integrations/network/suricata.md + - Trellix Network Security: xdr/features/collect/integrations/network/trellix_nx.md + - Varonis Data Security: xdr/features/collect/integrations/network/varonis_data_security.md + - Vectra Cognito Detect: xdr/features/collect/integrations/network/vectra.md + - Wallix: xdr/features/collect/integrations/network/wallix.md + - WatchGuard Firebox: xdr/features/collect/integrations/network/watchguard_firebox.md + - Zeek: xdr/features/collect/integrations/network/zeek.md + - Generic: + - CEF: xdr/features/collect/integrations/generic/cef.md + - Raw events: xdr/features/collect/integrations/generic/raw.md + - Intakes: xdr/features/collect/intakes.md + - Entities: xdr/features/collect/entities.md + - Assets: xdr/features/collect/assets.md + - Detect: + - Rules Catalog: xdr/features/detect/rules_catalog.md + - Built-in Rules: xdr/features/detect/built_in_detection_rules.md + - Sigma: xdr/features/detect/sigma.md + - Anomaly Detection: xdr/features/detect/anomaly.md + - IOCs Collections: xdr/features/detect/ioccollections.md + - Investigate: + - Alerts: xdr/features/investigate/alerts.md + - Events: xdr/features/investigate/events.md + - Cases: xdr/features/investigate/cases.md + - Events Query Language: xdr/features/investigate/events_query_language.md + - Querying Events: xdr/features/investigate/querying_events.md + - Query Builder (beta): xdr/features/investigate/query_builder.md + - Report: + - Dashboards: xdr/features/report/dashboards.md + - Automate: + - Playbooks: xdr/features/automate/index.md + - Playbooks On-premises: xdr/features/automate/playbooks-on-premises.md + - Manage accounts: xdr/features/automate/manage-accounts.md + - Navigate playbooks: xdr/features/automate/navigate-playbooks.md + - Build playbooks: xdr/features/automate/build-playbooks.md + - Triggers: xdr/features/automate/triggers.md + - Operators: xdr/features/automate/operators.md + - Actions: xdr/features/automate/actions.md + - Actions Library: + - AWS: xdr/features/automate/library/aws.md + - Atlassian JIRA: xdr/features/automate/library/atlassian-jira.md + - BinaryEdge's API: xdr/features/automate/library/binaryedge-s-api.md + - Broadcom Cloud Secure Web Gateway: xdr/features/automate/library/broadcom-cloud-secure-web-gateway.md + - Cato Networks: xdr/features/automate/library/cato-networks.md + - Censys: xdr/features/automate/library/censys.md + - Certificate Transparency: xdr/features/automate/library/certificate-transparency.md + - Check Point: xdr/features/automate/library/check-point.md + - CrowdStrike: xdr/features/automate/library/crowdstrike.md + - CrowdStrike Falcon: xdr/features/automate/library/crowdstrike-falcon.md + - Cybereason: xdr/features/automate/library/cybereason.md + - Darktrace: xdr/features/automate/library/darktrace.md + - Detection Rules: xdr/features/automate/library/detection-rules.md + - Digital Shadows: xdr/features/automate/library/digital-shadows.md + - Duo: xdr/features/automate/library/duo.md + - ExtraHop: xdr/features/automate/library/extrahop.md + - Fortigate Firewalls: xdr/features/automate/library/fortigate-firewalls.md + - GLIMPS: xdr/features/automate/library/glimps.md + - Git: xdr/features/automate/library/git.md + - Github: xdr/features/automate/library/github.md + - Google: xdr/features/automate/library/google.md + - HTTP: xdr/features/automate/library/http.md + - HarfangLab: xdr/features/automate/library/harfanglab.md + - IKnowWhatYouDownload: xdr/features/automate/library/iknowwhatyoudownload.md + - IPInfo: xdr/features/automate/library/ipinfo.md + - IPtoASN: xdr/features/automate/library/iptoasn.md + - Imperva: xdr/features/automate/library/imperva.md + - Jumpcloud Directory Insights: xdr/features/automate/library/jumpcloud-directory-insights.md + - MISP: xdr/features/automate/library/misp.md + - MWDB: xdr/features/automate/library/mwdb.md + - Mandrill: xdr/features/automate/library/mandrill.md + - Mattermost: xdr/features/automate/library/mattermost.md + - Microsoft Active Directory: xdr/features/automate/library/microsoft-active-directory.md + - Microsoft Azure: xdr/features/automate/library/microsoft-azure.md + - Microsoft Entra ID: xdr/features/automate/library/microsoft-entra-id.md + - Microsoft Office365: xdr/features/automate/library/microsoft-office365.md + - Microsoft Windows Server: xdr/features/automate/library/microsoft-windows-server.md + - Netskope: xdr/features/automate/library/netskope.md + - OSINT: xdr/features/automate/library/osint.md + - Okta: xdr/features/automate/library/okta.md + - Onyphe: xdr/features/automate/library/onyphe.md + - OpenAI: xdr/features/automate/library/openai.md + - PagerDuty: xdr/features/automate/library/pagerduty.md + - Panda Security: xdr/features/automate/library/panda-security.md + - Proofpoint: xdr/features/automate/library/proofpoint.md + - Public Suffix: xdr/features/automate/library/public-suffix.md + - RSS: xdr/features/automate/library/rss.md + - RiskIQ: xdr/features/automate/library/riskiq.md + - STIX: xdr/features/automate/library/stix.md + - Salesforce: xdr/features/automate/library/salesforce.md + - Sekoia.io: xdr/features/automate/library/sekoia-io.md + - SentinelOne: xdr/features/automate/library/sentinelone.md + - ServiceNow: xdr/features/automate/library/servicenow.md + - Shodan: xdr/features/automate/library/shodan.md + - Skyhigh Security: xdr/features/automate/library/skyhigh-security.md + - Sophos: xdr/features/automate/library/sophos.md + - TEHTRIS: xdr/features/automate/library/tehtris.md + - The Hive: xdr/features/automate/library/the-hive.md + - Tranco: xdr/features/automate/library/tranco.md + - Trellix: xdr/features/automate/library/trellix.md + - Trend Micro: xdr/features/automate/library/trend-micro.md + - Triage: xdr/features/automate/library/triage.md + - Utils: xdr/features/automate/library/utils.md + - Vade Cloud: xdr/features/automate/library/vade-cloud.md + - Vade Secure: xdr/features/automate/library/vade-secure.md + - VirusTotal: xdr/features/automate/library/virustotal.md + - Whois: xdr/features/automate/library/whois.md + - WithSecure: xdr/features/automate/library/withsecure.md + - Zscaler: xdr/features/automate/library/zscaler.md + - Debug playbooks: xdr/features/automate/debug-playbooks.md + - External integrations: + - FortiSOAR: xdr/features/integrations/fortisoar.md + - Palo Alto Cortex XSOAR: xdr/features/integrations/interconnect_sekoia_with_xsoar.md + - Usecases: + - Implement a blocklist in Sekoia.io: xdr/usecases/playbook/implement_blocklist.md + - Synchronize Alerts with an external tool: xdr/usecases/playbook/synchronize_alerts.md + - Send notifications to a Webhook using a playbook: xdr/usecases/playbook/notifications_using_playbooks.md + - FAQ: + - General: xdr/FAQ.md + - Alerts: xdr/FAQ/Alerts_qa.md + - Events: + - Events QA: xdr/FAQ/Events_qa.md + - Facing issues with logs collection: xdr/FAQ/Log_collection_Troubleshoot.md + - Rules: xdr/FAQ/Rules_qa.md + - Assets: xdr/FAQ/Assets_qa.md + - Sekoia.io Endpoint agent: xdr/FAQ/SEKOIA_Endpoint_Agent.md + - Datetime representation: xdr/FAQ/datetime.md + - Develop: + - Quickstart: xdr/develop/quickstart.md + - Guides: + - Filtering: xdr/develop/guides/filtering.md + - Automation: + - Overview: xdr/develop/guides/automation/overview.md + - Create a Module: xdr/develop/guides/automation/create_a_module.md + - Format: + - Overview: xdr/develop/guides/formats/overview.md + - Create a Format: xdr/develop/guides/formats/create_a_format.md + - Datasources: xdr/develop/guides/formats/datasources.md + - Definition of a structured event: xdr/develop/guides/formats/structured_event.md + - Definition of the taxonomy: xdr/develop/guides/formats/taxonomy.md + - How to write a parser: xdr/develop/guides/formats/parser.md + - How to write smart descriptions: xdr/develop/guides/formats/smartdescriptions.md + - Best Practices: + - Overview: xdr/develop/guides/formats/best_practices/overview.md + - Authentications: xdr/develop/guides/formats/best_practices/authentications.md + - REST API: + - Authentication and Community: xdr/develop/rest_api/community.md + - Dashboard: xdr/develop/rest_api/dashboard.md + - Configuration: xdr/develop/rest_api/configuration.md + - Parser: xdr/develop/rest_api/parser.md + - Alert: xdr/develop/rest_api/alert.md + - Assets: xdr/develop/rest_api/assets.md + - Assets v2 [beta]: xdr/develop/rest_api/assets_v2.md + - Playbooks: xdr/develop/rest_api/playbooks.md + - Telemetry: xdr/develop/rest_api/telemetry.md +- Sekoia.io CTI: + - Introduction: cti/index.md + - Features: + - Data Models: cti/features/data_model.md + - Consume: + - Intelligence: cti/features/consume/intelligence.md + - Observables: cti/features/consume/observables.md + - Telemetry: cti/features/consume/telemetry.md + - Outgoing Feeds: cti/features/consume/feeds.md + - Graph Explorations: cti/features/consume/graph_explorations.md + - Enrichers: cti/features/consume/enrichers.md + - Export: cti/features/consume/export.md + - IOCs Collections: cti/features/consume/ioccollections.md + - Monitor: + - Dashboards: cti/features/monitor/dashboard.md + - External Integrations: + - Overview: cti/features/integrations/index.md + - API: cti/features/integrations/api.md + - TAXII: cti/features/integrations/taxii.md + - Cortex Analyzer: cti/features/integrations/thehive.md + - MISP Feed: cti/features/integrations/misp.md + - Microsoft Sentinel: cti/features/integrations/microsoft-sentinel.md + - OpenCTI: cti/features/integrations/opencti.md + - Splunk: cti/features/integrations/splunk.md + - Splunk SOAR: cti/features/integrations/splunk_soar.md + - Anomali ThreatStream: cti/features/integrations/anomali.md + - PaloAlto Cortex XSOAR: cti/features/integrations/paloalto_xsoar.md + - Develop: + - Overview: cti/develop/index.md + - Guides: + - Filtering: cti/develop/guides/filtering.md + - REST API: + - Authentication and Community: cti/develop/rest_api/community.md + - Intelligence: cti/develop/rest_api/intelligence.md + - Enrichment: cti/develop/rest_api/enrichments.md + - Telemetry: cti/develop/rest_api/telemetry.md + - Dashboard: cti/develop/rest_api/dashboard.md + - Playbooks: cti/develop/rest_api/playbooks.md + - External Dynamic List: cti/develop/rest_api/edl-gateway.md +- Sekoia.io TIP: + - Introduction: tip/index.md + - Features: + - Data Models: tip/features/data_model.md + - Consume: + - Intelligence: tip/features/consume/intelligence.md + - Observables: tip/features/consume/observables.md + - Outgoing Feeds: tip/features/consume/feeds.md + - Graph Explorations: tip/features/consume/graph_explorations.md + - Enrichers: tip/features/consume/enrichers.md + - Export: tip/features/consume/export.md + - IOCs Collections: tip/features/consume/ioccollections.md + - Produce and investigate: + - Content Proposals: tip/features/produce/content_proposals.md + - Incoming Feeds: tip/features/produce/incoming_feeds.md + - Warning Rules: tip/features/produce/warning_rules.md + - Expiration Rules: tip/features/produce/expiration_rules.md + - Monitor: + - Dashboards: tip/features/monitor/dashboard.md + - External Integrations: + - Overview: tip/features/integrations/index.md + - API: tip/features/integrations/api.md + - TAXII: tip/features/integrations/taxii.md + - Cortex Analyzer: tip/features/integrations/thehive.md + - MISP Feed: tip/features/integrations/misp.md + - Microsoft Sentinel: tip/features/integrations/microsoft-sentinel.md + - OpenCTI: tip/features/integrations/opencti.md + - Splunk: tip/features/integrations/splunk.md + - PaloAlto Cortex XSOAR: tip/features/integrations/paloalto_xsoar.md + - Automate: + - Playbooks: tip/features/automate/index.md + - Manage accounts: xdr/features/automate/manage-accounts.md + - Navigate playbooks: tip/features/automate/navigate-playbooks.md + - Build playbooks: tip/features/automate/build-playbooks.md + - Triggers: tip/features/automate/triggers.md + - Operators: tip/features/automate/operators.md + - Actions: tip/features/automate/actions.md + - Actions Library: + - AWS: tip/features/automate/library/aws.md + - Atlassian JIRA: tip/features/automate/library/atlassian-jira.md + - BinaryEdge's API: tip/features/automate/library/binaryedge-s-api.md + - Broadcom Cloud Secure Web Gateway: tip/features/automate/library/broadcom-cloud-secure-web-gateway.md + - Cato Networks: tip/features/automate/library/cato-networks.md + - Censys: tip/features/automate/library/censys.md + - Certificate Transparency: tip/features/automate/library/certificate-transparency.md + - Check Point: tip/features/automate/library/check-point.md + - CrowdStrike: tip/features/automate/library/crowdstrike.md + - CrowdStrike Falcon: tip/features/automate/library/crowdstrike-falcon.md + - Cybereason: tip/features/automate/library/cybereason.md + - Darktrace: tip/features/automate/library/darktrace.md + - Detection Rules: tip/features/automate/library/detection-rules.md + - Digital Shadows: tip/features/automate/library/digital-shadows.md + - Duo: tip/features/automate/library/duo.md + - ExtraHop: tip/features/automate/library/extrahop.md + - Fortigate Firewalls: tip/features/automate/library/fortigate-firewalls.md + - GLIMPS: tip/features/automate/library/glimps.md + - Git: tip/features/automate/library/git.md + - Github: tip/features/automate/library/github.md + - Google: tip/features/automate/library/google.md + - HTTP: tip/features/automate/library/http.md + - HarfangLab: tip/features/automate/library/harfanglab.md + - IKnowWhatYouDownload: tip/features/automate/library/iknowwhatyoudownload.md + - IPInfo: tip/features/automate/library/ipinfo.md + - IPtoASN: tip/features/automate/library/iptoasn.md + - Imperva: tip/features/automate/library/imperva.md + - Jumpcloud Directory Insights: tip/features/automate/library/jumpcloud-directory-insights.md + - MISP: tip/features/automate/library/misp.md + - MWDB: tip/features/automate/library/mwdb.md + - Mandrill: tip/features/automate/library/mandrill.md + - Mattermost: tip/features/automate/library/mattermost.md + - Microsoft Active Directory: tip/features/automate/library/microsoft-active-directory.md + - Microsoft Azure: tip/features/automate/library/microsoft-azure.md + - Microsoft Entra ID (Azure AD): tip/features/automate/library/entra-id.md + - Microsoft Office365: tip/features/automate/library/microsoft-office365.md + - Microsoft Windows Server: tip/features/automate/library/microsoft-windows-server.md + - Netskope: tip/features/automate/library/netskope.md + - OSINT: tip/features/automate/library/osint.md + - Okta: tip/features/automate/library/okta.md + - Onyphe: tip/features/automate/library/onyphe.md + - OpenAI: tip/features/automate/library/openai.md + - PagerDuty: tip/features/automate/library/pagerduty.md + - Panda Security: tip/features/automate/library/panda-security.md + - Proofpoint: tip/features/automate/library/proofpoint.md + - Public Suffix: tip/features/automate/library/public-suffix.md + - RSS: tip/features/automate/library/rss.md + - RiskIQ: tip/features/automate/library/riskiq.md + - STIX: tip/features/automate/library/stix.md + - Salesforce: tip/features/automate/library/salesforce.md + - Sekoia.io: tip/features/automate/library/sekoia-io.md + - SentinelOne: tip/features/automate/library/sentinelone.md + - ServiceNow: tip/features/automate/library/servicenow.md + - Shodan: tip/features/automate/library/shodan.md + - Skyhigh Security: tip/features/automate/library/skyhigh-security.md + - Sophos: tip/features/automate/library/sophos.md + - TEHTRIS: tip/features/automate/library/tehtris.md + - The Hive: tip/features/automate/library/the-hive.md + - Tranco: tip/features/automate/library/tranco.md + - Trellix: tip/features/automate/library/trellix.md + - Trend Micro: tip/features/automate/library/trend-micro.md + - Triage: tip/features/automate/library/triage.md + - Utils: tip/features/automate/library/utils.md + - Vade Cloud: tip/features/automate/library/vade-cloud.md + - Vade Secure: tip/features/automate/library/vade-secure.md + - VirusTotal: tip/features/automate/library/virustotal.md + - Whois: tip/features/automate/library/whois.md + - WithSecure: tip/features/automate/library/withsecure.md + - Zscaler: tip/features/automate/library/zscaler.md + - Develop: + - Overview: tip/develop/index.md + - Guides: + - Filtering: tip/develop/guides/filtering.md + - Playbooks: + - Overview: tip/develop/guides/automation/overview.md + - Quick start: tip/develop/guides/automation/create_a_module.md + - REST API: + - Authentication and Community: tip/develop/rest_api/community.md + - Intelligence: tip/develop/rest_api/intelligence.md + - Enrichment: tip/develop/rest_api/enrichments.md + - Dashboard: tip/develop/rest_api/dashboard.md + - Playbooks: tip/develop/rest_api/playbooks.md plugins: - - search: null - - redirects: - redirect_maps: - "api/automation: symphony orchestrator": xdr/develop/rest_api/playbooks.md - api/dashboards: xdr/develop/rest_api/dashboard.md - api/identity & authentication: xdr/develop/rest_api/community.md - "api/ingest: manage and test event parsers": xdr/develop/rest_api/parser.md - "api/intelligence center: cyber threat intelligence database": cti/develop/rest_api/intelligence.md - "api/intelligence center: enrichment": cti/develop/rest_api/enrichments.md - "api/operation center: alerts & case management": xdr/develop/rest_api/alert.md - "api/operation center: asset management": xdr/develop/rest_api/assets.md - "api/operation center: rules, entities, intakes, events.md": xdr/develop/rest_api/configuration.md - api/profile & permissions: xdr/develop/rest_api/community.md - apis.md: xdr/develop/index.md - cti/develop/rest_api/identity_and_authentication.md: cti/develop/rest_api/community.md - develop.md: xdr/develop/index.md - develop/guides/filtering.md: xdr/develop/guides/filtering.md - develop/guides/get_started.md: xdr/develop/guides/get_started.md - develop/rest_api/community.md: xdr/develop/rest_api/community.md - develop/rest_api/dashboard.md: xdr/develop/rest_api/community.md - develop/rest_api/identity_and_authentication.md: xdr/develop/rest_api/community.md - develop/rest_api/intelligence_center/enrichments.md: cti/develop/rest_api/enrichments.md - develop/rest_api/intelligence_center/intelligence.md: cti/develop/rest_api/intelligence.md - develop/rest_api/operation_center/alert.md: xdr/develop/rest_api/alert.md - develop/rest_api/operation_center/assets.md: xdr/develop/rest_api/assets.md - develop/rest_api/operation_center/configuration.md: xdr/develop/rest_api/configuration.md - develop/rest_api/operation_center/parser.md: xdr/develop/rest_api/parser.md - develop/rest_api/playbooks.md: xdr/develop/rest_api/playbooks.md - getting_started/2fa.md: getting_started/account_security.md - getting_started/apikey_creation.md: getting_started/manage_api_keys.md - getting_started/first_steps.md: getting_started/index.md - getting_started/inviting_users_to_join_your_community.md: getting_started/invite_users.md - integrations/alsid.md: xdr/features/collect/integrations/application/alsid.md - integrations/apache.md: xdr/features/collect/integrations/application/apache.md - integrations/auditbeat.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md - integrations/auditbeat_linux.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md - integrations/aws-cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md - integrations/aws-flow-logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md - integrations/aws-s3-logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md - integrations/aws_cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md - integrations/aws_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md - integrations/aws_s3_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md - integrations/azure-ad.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md - integrations/azure-files.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md - integrations/azure-linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md - integrations/azure-mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md - integrations/azure-network-watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md - integrations/azure-windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md - integrations/azure_files.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md - integrations/azure_front_door.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_front_door.md - integrations/azure_linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md - integrations/azure_mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md - integrations/azure_network_watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md - integrations/azure_windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md - integrations/bind.md: xdr/features/collect/integrations/application/bind.md - integrations/cef.md: xdr/features/collect/integrations/generic/cef.md - integrations/checkpoint.md: xdr/features/collect/integrations/network/checkpoint.md - integrations/cisco-asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md - integrations/cisco_asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md - integrations/dhcpd.md: xdr/features/collect/integrations/application/dhcpd.md - integrations/digital_shadows.md: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md - integrations/f5-big-ip.md: xdr/features/collect/integrations/network/f5-big-ip.md - integrations/forcepoint-swg.md: xdr/features/collect/integrations/network/forcepoint_web_gateway.md - integrations/fortigate.md: xdr/features/collect/integrations/network/fortigate.md - integrations/fortimail.md: xdr/features/collect/integrations/email/fortimail.md - integrations/fortiproxy.md: xdr/features/collect/integrations/network/fortiproxy.md - integrations/fortiweb.md: xdr/features/collect/integrations/network/fortiweb.md - integrations/freeradius.md: xdr/index.md - integrations/fsecure.md: xdr/index.md - integrations/github_audit_logs.md: xdr/features/collect/integrations/cloud_and_saas/github_audit_logs.md - integrations/google_drive_reports.md: xdr/features/collect/integrations/cloud_and_saas/google/google_drive_reports.md - integrations/google_kubernetes_engine.md: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md - integrations/google_vpc_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md - integrations/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_workspace.md - integrations/haproxy.md: xdr/features/collect/integrations/application/haproxy.md - integrations/harfanglab.md: xdr/features/collect/integrations/endpoint/harfanglab.md - integrations/imperva_waf.md: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md - integrations/index.md: xdr/features/collect/integrations/index.md - integrations/infoblox-ddi.md: xdr/features/collect/integrations/network/infoblox_ddi.md - integrations/infoblox_ddi.md: xdr/features/collect/integrations/network/infoblox_ddi.md - integrations/intra_id.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md - integrations/linux.md: xdr/features/collect/integrations/endpoint/linux.md - integrations/log-insight-windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md - integrations/log_insight_windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md - integrations/netfilter.md: xdr/features/collect/integrations/network/netfilter.md - integrations/nginx.md: xdr/features/collect/integrations/application/nginx.md - integrations/o365-message-trace.md: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md - integrations/o365.md: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md - integrations/openldap.md: xdr/features/collect/integrations/application/openldap.md - integrations/openssh.md: xdr/features/collect/integrations/application/openssh.md - integrations/paloalto.md: xdr/features/collect/integrations/network/paloalto.md - integrations/panda-security-aether.md: xdr/features/collect/integrations/endpoint/panda_security_aether.md - integrations/postfix.md: xdr/features/collect/integrations/email/postfix.md - integrations/proofpoint-tap.md: xdr/features/collect/integrations/email/proofpoint_tap.md - integrations/proofpoint_tap.md: xdr/features/collect/integrations/email/proofpoint_tap.md - integrations/prove-it.md: xdr/index.md - integrations/pulse-connect-secure.md: xdr/features/collect/integrations/network/pulse.md - integrations/pulse.md: xdr/features/collect/integrations/network/pulse.md - integrations/raw.md: xdr/features/collect/integrations/generic/raw.md - integrations/retarus-email-security.md: xdr/features/collect/integrations/email/retarus_email_security.md - integrations/salesforce.md: xdr/features/collect/integrations/cloud_and_saas/salesforce.md - integrations/sekoiaio-activity-logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md - integrations/sekoiaio_activity_logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md - integrations/sentinelone-deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md - integrations/sentinelone.md: xdr/features/collect/integrations/endpoint/sentinelone.md - integrations/sentinelone_deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md - integrations/sophos_edr.md: xdr/features/collect/integrations/endpoint/sophos_edr.md - integrations/sophos_fw.md: xdr/features/collect/integrations/network/sophos_fw.md - integrations/spamassassin.md: xdr/features/collect/integrations/email/spamassassin.md - integrations/squid.md: xdr/features/collect/integrations/network/squid.md - integrations/stormshield_endpoint.md: xdr/features/collect/integrations/network/stormshield_endpoint.md - integrations/stormshield_network_security.md: xdr/features/collect/integrations/network/stormshield_network_security.md - integrations/suricata.md: xdr/features/collect/integrations/network/suricata.md - integrations/symantec-endpoint-protection.md: xdr/features/collect/integrations/endpoint/symantec_epp.md - integrations/symantec_endpoint_protection.md: xdr/features/collect/integrations/endpoint/symantec_epp.md - integrations/tanium.md: xdr/features/collect/integrations/endpoint/tanium.md - integrations/thehive.md: xdr/features/collect/integrations/application/thehive.md - integrations/transport.md: xdr/features/collect/ingestion_methods/index.md - integrations/transport/graylog.md: xdr/features/collect/ingestion_methods/graylog.md - integrations/transport/https.md: xdr/features/collect/ingestion_methods/https.md - integrations/transport/logstash.md: xdr/features/collect/ingestion_methods/logstash.md - integrations/transport/rsyslog.md: xdr/features/collect/ingestion_methods/rsyslog.md - integrations/transport/syslog-ng.md: xdr/features/collect/ingestion_methods/syslog-ng.md - integrations/umbrella-dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md - integrations/umbrella-ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md - integrations/umbrella-proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md - integrations/umbrella_dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md - integrations/umbrella_ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md - integrations/umbrella_proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md - integrations/unbound.md: xdr/features/collect/integrations/application/unbound.md - integrations/vade.md: xdr/features/collect/integrations/email/vade.md - integrations/vectra-cognito-detect.md: xdr/features/collect/integrations/network/vectra.md - integrations/wallix-bastion.md: xdr/features/collect/integrations/network/wallix.md - integrations/wazuh.md: xdr/index.md - integrations/windows.md: xdr/features/collect/integrations/endpoint/windows.md - integrations/zeek.md: xdr/features/collect/integrations/network/zeek.md - intelligence_center.md: cti/index.md - intelligence_center/api.md: cti/develop/index.md - intelligence_center/dashboard.md: cti/features/monitor/dashboard.md - intelligence_center/data_export.md: cti/features/consume/export.md - intelligence_center/data_model.md: cti/features/data_model.md - intelligence_center/enricher.md: cti/features/consume/enrichers.md - intelligence_center/graph_explorations.md: cti/features/consume/graph_explorations.md - intelligence_center/integrations.md: cti/features/integrations/index.md - intelligence_center/integrations/anomali.md: cti/features/integrations/anomali.md - intelligence_center/integrations/microsoft-sentinel.md: cti/features/integrations/microsoft-sentinel.md - intelligence_center/integrations/misp.md: cti/features/integrations/misp.md - intelligence_center/integrations/opencti.md: cti/features/integrations/opencti.md - intelligence_center/integrations/splunk.md: cti/features/integrations/splunk.md - intelligence_center/integrations/thehive.md: cti/features/integrations/thehive.md - intelligence_center/intelligence.md: cti/features/consume/intelligence.md - intelligence_center/observables.md: cti/features/consume/observables.md - operation_center.md: xdr/index.md - operation_center/actions.md: xdr/features/automate/actions.md - operation_center/alerts.md: xdr/features/investigate/alerts.md - operation_center/assets.md: xdr/features/collect/assets.md - operation_center/cases.md: xdr/features/investigate/cases.md - operation_center/data_collection/index.md: xdr/features/collect/ingestion_methods/index.md - operation_center/data_collection/ingestion_methods.md: xdr/features/collect/ingestion_methods/index.md - operation_center/data_collection/ingestion_methods/graylog.md: xdr/features/collect/ingestion_methods/graylog.md - operation_center/data_collection/ingestion_methods/https.md: xdr/features/collect/ingestion_methods/https.md - operation_center/data_collection/ingestion_methods/logstash.md: xdr/features/collect/ingestion_methods/logstash.md - operation_center/data_collection/ingestion_methods/rsyslog.md: xdr/features/collect/ingestion_methods/rsyslog.md - operation_center/data_collection/ingestion_methods/sekoiaio.md: xdr/features/collect/integrations/endpoint/sekoiaio.md - operation_center/data_collection/ingestion_methods/syslog-ng.md: xdr/features/collect/ingestion_methods/syslog-ng.md - operation_center/entities.md: xdr/features/collect/entities.md - operation_center/events.md: xdr/features/investigate/events.md - operation_center/faq.md: xdr/FAQ.md - operation_center/intakes.md: xdr/features/collect/intakes.md - operation_center/intakes_customformat.md: xdr/features/collect/integrations/custom_format.md - operation_center/integration_catalog/application/alsid.md: xdr/features/collect/integrations/application/alsid.md - operation_center/integration_catalog/application/apache.md: xdr/features/collect/integrations/application/apache.md - operation_center/integration_catalog/application/bind.md: xdr/features/collect/integrations/application/bind.md - operation_center/integration_catalog/application/dhcpd.md: xdr/features/collect/integrations/application/dhcpd.md - operation_center/integration_catalog/application/haproxy.md: xdr/features/collect/integrations/application/haproxy.md - operation_center/integration_catalog/application/nginx.md: xdr/features/collect/integrations/application/nginx.md - operation_center/integration_catalog/application/openldap.md: xdr/features/collect/integrations/application/openldap.md - operation_center/integration_catalog/application/openssh.md: xdr/features/collect/integrations/application/openssh.md - operation_center/integration_catalog/application/prove-it.md: xdr/features/collect/integrations/application/prove-it.md - operation_center/integration_catalog/application/sekoiaio_activity_logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md - operation_center/integration_catalog/application/thehive.md: xdr/features/collect/integrations/application/thehive.md - operation_center/integration_catalog/application/unbound.md: xdr/features/collect/integrations/application/unbound.md - operation_center/integration_catalog/cloud_and_saas/aws/aws_cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md - operation_center/integration_catalog/cloud_and_saas/aws/aws_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md - operation_center/integration_catalog/cloud_and_saas/azure/azure_linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md - operation_center/integration_catalog/cloud_and_saas/azure/azure_mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md - operation_center/integration_catalog/cloud_and_saas/azure/azure_network_watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md - operation_center/integration_catalog/cloud_and_saas/azure/azure_windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md - operation_center/integration_catalog/cloud_and_saas/azure/intra_id.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md - operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md - operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md - operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md - operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-dns-logs.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-dns-logs.md - operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-firewall-events.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-firewall-events.md - operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-http-requests.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md - operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md - operation_center/integration_catalog/cloud_and_saas/digital_shadows.md: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md - operation_center/integration_catalog/cloud_and_saas/google/google_drive_reports.md: xdr/features/collect/integrations/cloud_and_saas/google/google_drive_reports.md - operation_center/integration_catalog/cloud_and_saas/google/google_kubernetes_engine.md: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md - operation_center/integration_catalog/cloud_and_saas/google/google_vpc_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md - operation_center/integration_catalog/cloud_and_saas/google/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md - operation_center/integration_catalog/cloud_and_saas/imperva_waf.md: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md - operation_center/integration_catalog/cloud_and_saas/o365-message-trace.md: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md - operation_center/integration_catalog/cloud_and_saas/o365.md: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md - operation_center/integration_catalog/email/fortimail.md: xdr/features/collect/integrations/email/fortimail.md - operation_center/integration_catalog/email/postfix.md: xdr/features/collect/integrations/email/postfix.md - operation_center/integration_catalog/email/retarus_email_security.md: xdr/features/collect/integrations/email/retarus_email_security.md - operation_center/integration_catalog/email/spamassassin.md: xdr/features/collect/integrations/email/spamassassin.md - operation_center/integration_catalog/email/vade.md: xdr/features/collect/integrations/email/vade.md - operation_center/integration_catalog/endpoint/auditbeat_linux.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md - operation_center/integration_catalog/endpoint/cybereason_malop_activity.md: xdr/features/collect/integrations/endpoint/cybereason_malop_activity.md - operation_center/integration_catalog/endpoint/harfanglab.md: xdr/features/collect/integrations/endpoint/harfanglab.md - operation_center/integration_catalog/endpoint/linux.md: xdr/features/collect/integrations/endpoint/linux.md - operation_center/integration_catalog/endpoint/log_insight_windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md - operation_center/integration_catalog/endpoint/microsoft_defender_for_endpoints.md: xdr/features/collect/integrations/endpoint/microsoft_defender_for_endpoints.md - operation_center/integration_catalog/endpoint/panda_security_aether.md: xdr/features/collect/integrations/endpoint/panda_security_aether.md - operation_center/integration_catalog/endpoint/sentinelone.md: xdr/features/collect/integrations/endpoint/sentinelone.md - operation_center/integration_catalog/endpoint/sentinelone_deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md - operation_center/integration_catalog/endpoint/sophos_edr.md: xdr/features/collect/integrations/endpoint/sophos_edr.md - operation_center/integration_catalog/endpoint/tanium.md: xdr/features/collect/integrations/endpoint/tanium.md - operation_center/integration_catalog/endpoint/windows.md: xdr/features/collect/integrations/endpoint/windows.md - operation_center/integration_catalog/generic/cef.md: xdr/features/collect/integrations/generic/cef.md - operation_center/integration_catalog/network/checkpoint.md: xdr/features/collect/integrations/network/checkpoint.md - operation_center/integration_catalog/network/cisco_asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md - operation_center/integration_catalog/network/cisco_wsa.md: xdr/features/collect/integrations/network/cisco/cisco_wsa.md - operation_center/integration_catalog/network/f5-big-ip.md: xdr/features/collect/integrations/network/f5-big-ip.md - operation_center/integration_catalog/network/forcepoint_web_gateway.md: xdr/features/collect/integrations/network/forcepoint_web_gateway.md - operation_center/integration_catalog/network/fortigate.md: xdr/features/collect/integrations/network/fortigate.md - operation_center/integration_catalog/network/fortiproxy.md: xdr/features/collect/integrations/network/fortiproxy.md - operation_center/integration_catalog/network/fortiweb.md: xdr/features/collect/integrations/network/fortiweb.md - operation_center/integration_catalog/network/mcafee_web_gateway.md: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md - operation_center/integration_catalog/network/netfilter.md: xdr/features/collect/integrations/network/netfilter.md - operation_center/integration_catalog/network/paloalto.md: xdr/features/collect/integrations/network/paloalto.md - operation_center/integration_catalog/network/pulse.md: xdr/features/collect/integrations/network/pulse.md - operation_center/integration_catalog/network/skyhigh_secure_web_gateway.md: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md - operation_center/integration_catalog/network/sophos_fw.md: xdr/features/collect/integrations/network/sophos_fw.md - operation_center/integration_catalog/network/squid.md: xdr/features/collect/integrations/network/squid.md - operation_center/integration_catalog/network/stormshield_network_security.md: xdr/features/collect/integrations/network/stormshield_network_security.md - operation_center/integration_catalog/network/suricata.md: xdr/features/collect/integrations/network/suricata.md - operation_center/integration_catalog/network/vectra.md: xdr/features/collect/integrations/network/vectra.md - operation_center/integration_catalog/network/wallix.md: xdr/features/collect/integrations/network/wallix.md - operation_center/integration_catalog/network/zeek.md: xdr/features/collect/integrations/network/zeek.md - operation_center/operators.md: xdr/features/automate/operators.md - operation_center/playbook_overview.md: xdr/features/automate/index.md - operation_center/rules.md: xdr/features/detect/rules_catalog.md - operation_center/rules_catalog.md: xdr/features/detect/rules_catalog.md - operation_center/templates.md: xdr/features/detect/rules_catalog.md - operation_center/threat_exposition.md: xdr/features/report/dashboards.md - operation_center/triggers.md: xdr/features/automate/triggers.md - playbooks/actions.md: xdr/features/automate/actions.md - playbooks/library/aws.md: xdr/features/automate/library/aws.md - playbooks/library/binaryedge-s-api.md: xdr/features/automate/library/binaryedge-s-api.md - playbooks/library/censys.md: xdr/features/automate/library/censys.md - playbooks/library/certificate-transparency.md: xdr/features/automate/library/certificate-transparency.md - playbooks/library/detection-rules.md: xdr/features/automate/library/detection-rules.md - playbooks/library/digital-shadows.md: xdr/features/automate/library/digital-shadows.md - playbooks/library/fileutils.md: xdr/features/automate/library/fileutils.md - playbooks/library/fortigate-fw.md: xdr/features/automate/library/fortigate-fw.md - playbooks/library/git.md: xdr/features/automate/library/git.md - playbooks/library/glimps.md: xdr/features/automate/library/glimps.md - playbooks/library/google.md: xdr/features/automate/library/google.md - playbooks/library/harfanglab.md: xdr/features/automate/library/harfanglab.md - playbooks/library/http.md: xdr/features/automate/library/http.md - playbooks/library/iknowwhatyoudownload.md: xdr/features/automate/library/iknowwhatyoudownload.md - playbooks/library/imperva.md: xdr/features/automate/library/imperva.md - playbooks/library/iptoasn.md: xdr/features/automate/library/iptoasn.md - playbooks/library/mandrill.md: xdr/features/automate/library/mandrill.md - playbooks/library/mattermost.md: xdr/features/automate/library/mattermost.md - playbooks/library/misp.md: xdr/features/automate/library/misp.md - playbooks/library/mwdb.md: xdr/features/automate/library/mwdb.md - playbooks/library/onyphe.md: xdr/features/automate/library/onyphe.md - playbooks/library/osint.md: xdr/features/automate/library/osint.md - playbooks/library/pagerduty.md: xdr/features/automate/library/pagerduty.md - playbooks/library/panda-security.md: xdr/features/automate/library/panda-security.md - playbooks/library/public-suffix.md: xdr/features/automate/library/public-suffix.md - playbooks/library/riskiq.md: xdr/features/automate/library/riskiq.md - playbooks/library/rss.md: xdr/features/automate/library/rss.md - playbooks/library/sekoia-io.md: xdr/features/automate/library/sekoia-io.md - playbooks/library/servicenow.md: xdr/features/automate/library/servicenow.md - playbooks/library/shodan.md: xdr/features/automate/library/shodan.md - playbooks/library/stix.md: xdr/features/automate/library/stix.md - playbooks/library/the-hive.md: xdr/features/automate/library/the-hive.md - playbooks/library/tranco.md: xdr/features/automate/library/tranco.md - playbooks/library/triage.md: xdr/features/automate/library/triage.md - playbooks/library/vade-secure.md: xdr/features/automate/library/vade-secure.md - playbooks/library/virustotal.md: xdr/features/automate/library/virustotal.md - playbooks/library/whois.md: xdr/features/automate/library/whois.md - playbooks/operators.md: xdr/features/automate/operators.md - playbooks/overview.md: xdr/features/automate/index.md - playbooks/triggers.md: xdr/features/automate/triggers.md - searching/dork.md: xdr/features/investigate/dork_language.md - searching/search_events.md: xdr/features/investigate/events.md - tip/develop/rest_api/identity_and_authentication.md: tip/develop/rest_api/community.md - user_center.md: getting_started/index.md - user_center/apikeys.md: getting_started/manage_api_keys.md - user_center/multi_factor_authentication.md: getting_started/account_security.md - xdr/develop/rest_api/identity_and_authentication.md: xdr/develop/rest_api/community.md - xdr/features/collect/ingestion_methods/sekoiaio.md: xdr/features/collect/integrations/endpoint/sekoiaio.md - xdr/features/collect/integrations/cloud_and_saas/google/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md - xdr/features/collect/integrations/cloud_and_saas/netskope_events.md: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_events.md - xdr/features/collect/integrations/endpoint/checkpoint_harmony.md: xdr/features/collect/integrations/endpoint/checkpoint_harmony_mobile.md - xdr/features/collect/integrations/endpoint/trend_micro_deep_security.md: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_deep_security.md - xdr/features/investigate/dork_language.md: xdr/features/investigate/events_query_language.md - - redoc - - intakes_by_uuid +- search: null +- redirects: + redirect_maps: + 'api/automation: symphony orchestrator': xdr/develop/rest_api/playbooks.md + api/dashboards: xdr/develop/rest_api/dashboard.md + api/identity & authentication: xdr/develop/rest_api/community.md + 'api/ingest: manage and test event parsers': xdr/develop/rest_api/parser.md + 'api/intelligence center: cyber threat intelligence database': cti/develop/rest_api/intelligence.md + 'api/intelligence center: enrichment': cti/develop/rest_api/enrichments.md + 'api/operation center: alerts & case management': xdr/develop/rest_api/alert.md + 'api/operation center: asset management': xdr/develop/rest_api/assets.md + 'api/operation center: rules, entities, intakes, events.md': xdr/develop/rest_api/configuration.md + api/profile & permissions: xdr/develop/rest_api/community.md + apis.md: xdr/develop/index.md + cti/develop/rest_api/identity_and_authentication.md: cti/develop/rest_api/community.md + develop.md: xdr/develop/index.md + develop/guides/filtering.md: xdr/develop/guides/filtering.md + develop/guides/get_started.md: xdr/develop/guides/get_started.md + develop/rest_api/community.md: xdr/develop/rest_api/community.md + develop/rest_api/dashboard.md: xdr/develop/rest_api/community.md + develop/rest_api/identity_and_authentication.md: xdr/develop/rest_api/community.md + develop/rest_api/intelligence_center/enrichments.md: cti/develop/rest_api/enrichments.md + develop/rest_api/intelligence_center/intelligence.md: cti/develop/rest_api/intelligence.md + develop/rest_api/operation_center/alert.md: xdr/develop/rest_api/alert.md + develop/rest_api/operation_center/assets.md: xdr/develop/rest_api/assets.md + develop/rest_api/operation_center/configuration.md: xdr/develop/rest_api/configuration.md + develop/rest_api/operation_center/parser.md: xdr/develop/rest_api/parser.md + develop/rest_api/playbooks.md: xdr/develop/rest_api/playbooks.md + getting_started/2fa.md: getting_started/account_security.md + getting_started/apikey_creation.md: getting_started/manage_api_keys.md + getting_started/first_steps.md: getting_started/index.md + getting_started/inviting_users_to_join_your_community.md: getting_started/invite_users.md + integrations/alsid.md: xdr/features/collect/integrations/application/alsid.md + integrations/apache.md: xdr/features/collect/integrations/application/apache.md + integrations/auditbeat.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md + integrations/auditbeat_linux.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md + integrations/aws-cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md + integrations/aws-flow-logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md + integrations/aws-s3-logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md + integrations/aws_cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md + integrations/aws_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md + integrations/aws_s3_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_s3_logs.md + integrations/azure-ad.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md + integrations/azure-files.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md + integrations/azure-linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md + integrations/azure-mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md + integrations/azure-network-watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md + integrations/azure-windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md + integrations/azure_files.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_files.md + integrations/azure_front_door.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_front_door.md + integrations/azure_linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md + integrations/azure_mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md + integrations/azure_network_watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md + integrations/azure_windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md + integrations/bind.md: xdr/features/collect/integrations/application/bind.md + integrations/cef.md: xdr/features/collect/integrations/generic/cef.md + integrations/checkpoint.md: xdr/features/collect/integrations/network/checkpoint.md + integrations/cisco-asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md + integrations/cisco_asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md + integrations/dhcpd.md: xdr/features/collect/integrations/application/dhcpd.md + integrations/digital_shadows.md: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md + integrations/f5-big-ip.md: xdr/features/collect/integrations/network/f5-big-ip.md + integrations/forcepoint-swg.md: xdr/features/collect/integrations/network/forcepoint_web_gateway.md + integrations/fortigate.md: xdr/features/collect/integrations/network/fortigate.md + integrations/fortimail.md: xdr/features/collect/integrations/email/fortimail.md + integrations/fortiproxy.md: xdr/features/collect/integrations/network/fortiproxy.md + integrations/fortiweb.md: xdr/features/collect/integrations/network/fortiweb.md + integrations/freeradius.md: xdr/index.md + integrations/fsecure.md: xdr/index.md + integrations/github_audit_logs.md: xdr/features/collect/integrations/cloud_and_saas/github_audit_logs.md + integrations/google_drive_reports.md: xdr/features/collect/integrations/cloud_and_saas/google/google_drive_reports.md + integrations/google_kubernetes_engine.md: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md + integrations/google_vpc_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md + integrations/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_workspace.md + integrations/haproxy.md: xdr/features/collect/integrations/application/haproxy.md + integrations/harfanglab.md: xdr/features/collect/integrations/endpoint/harfanglab.md + integrations/imperva_waf.md: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md + integrations/index.md: xdr/features/collect/integrations/index.md + integrations/infoblox-ddi.md: xdr/features/collect/integrations/network/infoblox_ddi.md + integrations/infoblox_ddi.md: xdr/features/collect/integrations/network/infoblox_ddi.md + integrations/intra_id.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md + integrations/linux.md: xdr/features/collect/integrations/endpoint/linux.md + integrations/log-insight-windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md + integrations/log_insight_windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md + integrations/netfilter.md: xdr/features/collect/integrations/network/netfilter.md + integrations/nginx.md: xdr/features/collect/integrations/application/nginx.md + integrations/o365-message-trace.md: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md + integrations/o365.md: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md + integrations/openldap.md: xdr/features/collect/integrations/application/openldap.md + integrations/openssh.md: xdr/features/collect/integrations/application/openssh.md + integrations/paloalto.md: xdr/features/collect/integrations/network/paloalto.md + integrations/panda-security-aether.md: xdr/features/collect/integrations/endpoint/panda_security_aether.md + integrations/postfix.md: xdr/features/collect/integrations/email/postfix.md + integrations/proofpoint-tap.md: xdr/features/collect/integrations/email/proofpoint_tap.md + integrations/proofpoint_tap.md: xdr/features/collect/integrations/email/proofpoint_tap.md + integrations/prove-it.md: xdr/index.md + integrations/pulse-connect-secure.md: xdr/features/collect/integrations/network/pulse.md + integrations/pulse.md: xdr/features/collect/integrations/network/pulse.md + integrations/raw.md: xdr/features/collect/integrations/generic/raw.md + integrations/retarus-email-security.md: xdr/features/collect/integrations/email/retarus_email_security.md + integrations/salesforce.md: xdr/features/collect/integrations/cloud_and_saas/salesforce.md + integrations/sekoiaio-activity-logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md + integrations/sekoiaio_activity_logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md + integrations/sentinelone-deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md + integrations/sentinelone.md: xdr/features/collect/integrations/endpoint/sentinelone.md + integrations/sentinelone_deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md + integrations/sophos_edr.md: xdr/features/collect/integrations/endpoint/sophos_edr.md + integrations/sophos_fw.md: xdr/features/collect/integrations/network/sophos_fw.md + integrations/spamassassin.md: xdr/features/collect/integrations/email/spamassassin.md + integrations/squid.md: xdr/features/collect/integrations/network/squid.md + integrations/stormshield_endpoint.md: xdr/features/collect/integrations/network/stormshield_endpoint.md + integrations/stormshield_network_security.md: xdr/features/collect/integrations/network/stormshield_network_security.md + integrations/suricata.md: xdr/features/collect/integrations/network/suricata.md + integrations/symantec-endpoint-protection.md: xdr/features/collect/integrations/endpoint/symantec_epp.md + integrations/symantec_endpoint_protection.md: xdr/features/collect/integrations/endpoint/symantec_epp.md + integrations/tanium.md: xdr/features/collect/integrations/endpoint/tanium.md + integrations/thehive.md: xdr/features/collect/integrations/application/thehive.md + integrations/transport.md: xdr/features/collect/ingestion_methods/index.md + integrations/transport/graylog.md: xdr/features/collect/ingestion_methods/graylog.md + integrations/transport/https.md: xdr/features/collect/ingestion_methods/https.md + integrations/transport/logstash.md: xdr/features/collect/ingestion_methods/logstash.md + integrations/transport/rsyslog.md: xdr/features/collect/ingestion_methods/rsyslog.md + integrations/transport/syslog-ng.md: xdr/features/collect/ingestion_methods/syslog-ng.md + integrations/umbrella-dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md + integrations/umbrella-ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md + integrations/umbrella-proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md + integrations/umbrella_dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md + integrations/umbrella_ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md + integrations/umbrella_proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md + integrations/unbound.md: xdr/features/collect/integrations/application/unbound.md + integrations/vade.md: xdr/features/collect/integrations/email/vade.md + integrations/vectra-cognito-detect.md: xdr/features/collect/integrations/network/vectra.md + integrations/wallix-bastion.md: xdr/features/collect/integrations/network/wallix.md + integrations/wazuh.md: xdr/index.md + integrations/windows.md: xdr/features/collect/integrations/endpoint/windows.md + integrations/zeek.md: xdr/features/collect/integrations/network/zeek.md + intelligence_center.md: cti/index.md + intelligence_center/api.md: cti/develop/index.md + intelligence_center/dashboard.md: cti/features/monitor/dashboard.md + intelligence_center/data_export.md: cti/features/consume/export.md + intelligence_center/data_model.md: cti/features/data_model.md + intelligence_center/enricher.md: cti/features/consume/enrichers.md + intelligence_center/graph_explorations.md: cti/features/consume/graph_explorations.md + intelligence_center/integrations.md: cti/features/integrations/index.md + intelligence_center/integrations/anomali.md: cti/features/integrations/anomali.md + intelligence_center/integrations/microsoft-sentinel.md: cti/features/integrations/microsoft-sentinel.md + intelligence_center/integrations/misp.md: cti/features/integrations/misp.md + intelligence_center/integrations/opencti.md: cti/features/integrations/opencti.md + intelligence_center/integrations/splunk.md: cti/features/integrations/splunk.md + intelligence_center/integrations/thehive.md: cti/features/integrations/thehive.md + intelligence_center/intelligence.md: cti/features/consume/intelligence.md + intelligence_center/observables.md: cti/features/consume/observables.md + operation_center.md: xdr/index.md + operation_center/actions.md: xdr/features/automate/actions.md + operation_center/alerts.md: xdr/features/investigate/alerts.md + operation_center/assets.md: xdr/features/collect/assets.md + operation_center/cases.md: xdr/features/investigate/cases.md + operation_center/data_collection/index.md: xdr/features/collect/ingestion_methods/index.md + operation_center/data_collection/ingestion_methods.md: xdr/features/collect/ingestion_methods/index.md + operation_center/data_collection/ingestion_methods/graylog.md: xdr/features/collect/ingestion_methods/graylog.md + operation_center/data_collection/ingestion_methods/https.md: xdr/features/collect/ingestion_methods/https.md + operation_center/data_collection/ingestion_methods/logstash.md: xdr/features/collect/ingestion_methods/logstash.md + operation_center/data_collection/ingestion_methods/rsyslog.md: xdr/features/collect/ingestion_methods/rsyslog.md + operation_center/data_collection/ingestion_methods/sekoiaio.md: xdr/features/collect/integrations/endpoint/sekoiaio.md + operation_center/data_collection/ingestion_methods/syslog-ng.md: xdr/features/collect/ingestion_methods/syslog-ng.md + operation_center/entities.md: xdr/features/collect/entities.md + operation_center/events.md: xdr/features/investigate/events.md + operation_center/faq.md: xdr/FAQ.md + operation_center/intakes.md: xdr/features/collect/intakes.md + operation_center/intakes_customformat.md: xdr/features/collect/integrations/custom_format.md + operation_center/integration_catalog/application/alsid.md: xdr/features/collect/integrations/application/alsid.md + operation_center/integration_catalog/application/apache.md: xdr/features/collect/integrations/application/apache.md + operation_center/integration_catalog/application/bind.md: xdr/features/collect/integrations/application/bind.md + operation_center/integration_catalog/application/dhcpd.md: xdr/features/collect/integrations/application/dhcpd.md + operation_center/integration_catalog/application/haproxy.md: xdr/features/collect/integrations/application/haproxy.md + operation_center/integration_catalog/application/nginx.md: xdr/features/collect/integrations/application/nginx.md + operation_center/integration_catalog/application/openldap.md: xdr/features/collect/integrations/application/openldap.md + operation_center/integration_catalog/application/openssh.md: xdr/features/collect/integrations/application/openssh.md + operation_center/integration_catalog/application/prove-it.md: xdr/features/collect/integrations/application/prove-it.md + operation_center/integration_catalog/application/sekoiaio_activity_logs.md: xdr/features/collect/integrations/application/sekoiaio_activity_logs.md + operation_center/integration_catalog/application/thehive.md: xdr/features/collect/integrations/application/thehive.md + operation_center/integration_catalog/application/unbound.md: xdr/features/collect/integrations/application/unbound.md + operation_center/integration_catalog/cloud_and_saas/aws/aws_cloudtrail.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_cloudtrail.md + operation_center/integration_catalog/cloud_and_saas/aws/aws_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/aws/aws_flow_logs.md + operation_center/integration_catalog/cloud_and_saas/azure/azure_linux.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_linux.md + operation_center/integration_catalog/cloud_and_saas/azure/azure_mysql.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_mysql.md + operation_center/integration_catalog/cloud_and_saas/azure/azure_network_watcher.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_network_watcher.md + operation_center/integration_catalog/cloud_and_saas/azure/azure_windows.md: xdr/features/collect/integrations/cloud_and_saas/azure/azure_windows.md + operation_center/integration_catalog/cloud_and_saas/azure/intra_id.md: xdr/features/collect/integrations/cloud_and_saas/azure/intra_id.md + operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_dns.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_dns.md + operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_ip.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_ip.md + operation_center/integration_catalog/cloud_and_saas/cisco_umbrella/umbrella_proxy.md: xdr/features/collect/integrations/cloud_and_saas/cisco_umbrella/umbrella_proxy.md + operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-dns-logs.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-dns-logs.md + operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-firewall-events.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-firewall-events.md + operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare-http-requests.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md + operation_center/integration_catalog/cloud_and_saas/cloudflare/cloudflare.md: xdr/features/collect/integrations/cloud_and_saas/cloudflare/cloudflare-http-requests.md + operation_center/integration_catalog/cloud_and_saas/digital_shadows.md: xdr/features/collect/integrations/cloud_and_saas/digital_shadows.md + operation_center/integration_catalog/cloud_and_saas/google/google_drive_reports.md: xdr/features/collect/integrations/cloud_and_saas/google/google_drive_reports.md + operation_center/integration_catalog/cloud_and_saas/google/google_kubernetes_engine.md: xdr/features/collect/integrations/cloud_and_saas/google/google_kubernetes_engine.md + operation_center/integration_catalog/cloud_and_saas/google/google_vpc_flow_logs.md: xdr/features/collect/integrations/cloud_and_saas/google/google_vpc_flow_logs.md + operation_center/integration_catalog/cloud_and_saas/google/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md + operation_center/integration_catalog/cloud_and_saas/imperva_waf.md: xdr/features/collect/integrations/cloud_and_saas/imperva_waf.md + operation_center/integration_catalog/cloud_and_saas/o365-message-trace.md: xdr/features/collect/integrations/cloud_and_saas/office365/message_trace.md + operation_center/integration_catalog/cloud_and_saas/o365.md: xdr/features/collect/integrations/cloud_and_saas/office365/o365.md + operation_center/integration_catalog/email/fortimail.md: xdr/features/collect/integrations/email/fortimail.md + operation_center/integration_catalog/email/postfix.md: xdr/features/collect/integrations/email/postfix.md + operation_center/integration_catalog/email/retarus_email_security.md: xdr/features/collect/integrations/email/retarus_email_security.md + operation_center/integration_catalog/email/spamassassin.md: xdr/features/collect/integrations/email/spamassassin.md + operation_center/integration_catalog/email/vade.md: xdr/features/collect/integrations/email/vade.md + operation_center/integration_catalog/endpoint/auditbeat_linux.md: xdr/features/collect/integrations/endpoint/auditbeat_linux.md + operation_center/integration_catalog/endpoint/cybereason_malop_activity.md: xdr/features/collect/integrations/endpoint/cybereason_malop_activity.md + operation_center/integration_catalog/endpoint/harfanglab.md: xdr/features/collect/integrations/endpoint/harfanglab.md + operation_center/integration_catalog/endpoint/linux.md: xdr/features/collect/integrations/endpoint/linux.md + operation_center/integration_catalog/endpoint/log_insight_windows.md: xdr/features/collect/integrations/endpoint/log_insight_windows.md + operation_center/integration_catalog/endpoint/microsoft_defender_for_endpoints.md: xdr/features/collect/integrations/endpoint/microsoft_defender_for_endpoints.md + operation_center/integration_catalog/endpoint/panda_security_aether.md: xdr/features/collect/integrations/endpoint/panda_security_aether.md + operation_center/integration_catalog/endpoint/sentinelone.md: xdr/features/collect/integrations/endpoint/sentinelone.md + operation_center/integration_catalog/endpoint/sentinelone_deepvisibility.md: xdr/features/collect/integrations/endpoint/sentinelone_deepvisibility.md + operation_center/integration_catalog/endpoint/sophos_edr.md: xdr/features/collect/integrations/endpoint/sophos_edr.md + operation_center/integration_catalog/endpoint/tanium.md: xdr/features/collect/integrations/endpoint/tanium.md + operation_center/integration_catalog/endpoint/windows.md: xdr/features/collect/integrations/endpoint/windows.md + operation_center/integration_catalog/generic/cef.md: xdr/features/collect/integrations/generic/cef.md + operation_center/integration_catalog/network/checkpoint.md: xdr/features/collect/integrations/network/checkpoint.md + operation_center/integration_catalog/network/cisco_asa.md: xdr/features/collect/integrations/network/cisco/cisco_asa.md + operation_center/integration_catalog/network/cisco_wsa.md: xdr/features/collect/integrations/network/cisco/cisco_wsa.md + operation_center/integration_catalog/network/f5-big-ip.md: xdr/features/collect/integrations/network/f5-big-ip.md + operation_center/integration_catalog/network/forcepoint_web_gateway.md: xdr/features/collect/integrations/network/forcepoint_web_gateway.md + operation_center/integration_catalog/network/fortigate.md: xdr/features/collect/integrations/network/fortigate.md + operation_center/integration_catalog/network/fortiproxy.md: xdr/features/collect/integrations/network/fortiproxy.md + operation_center/integration_catalog/network/fortiweb.md: xdr/features/collect/integrations/network/fortiweb.md + operation_center/integration_catalog/network/mcafee_web_gateway.md: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md + operation_center/integration_catalog/network/netfilter.md: xdr/features/collect/integrations/network/netfilter.md + operation_center/integration_catalog/network/paloalto.md: xdr/features/collect/integrations/network/paloalto.md + operation_center/integration_catalog/network/pulse.md: xdr/features/collect/integrations/network/pulse.md + operation_center/integration_catalog/network/skyhigh_secure_web_gateway.md: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md + operation_center/integration_catalog/network/sophos_fw.md: xdr/features/collect/integrations/network/sophos_fw.md + operation_center/integration_catalog/network/squid.md: xdr/features/collect/integrations/network/squid.md + operation_center/integration_catalog/network/stormshield_network_security.md: xdr/features/collect/integrations/network/stormshield_network_security.md + operation_center/integration_catalog/network/suricata.md: xdr/features/collect/integrations/network/suricata.md + operation_center/integration_catalog/network/vectra.md: xdr/features/collect/integrations/network/vectra.md + operation_center/integration_catalog/network/wallix.md: xdr/features/collect/integrations/network/wallix.md + operation_center/integration_catalog/network/zeek.md: xdr/features/collect/integrations/network/zeek.md + operation_center/operators.md: xdr/features/automate/operators.md + operation_center/playbook_overview.md: xdr/features/automate/index.md + operation_center/rules.md: xdr/features/detect/rules_catalog.md + operation_center/rules_catalog.md: xdr/features/detect/rules_catalog.md + operation_center/templates.md: xdr/features/detect/rules_catalog.md + operation_center/threat_exposition.md: xdr/features/report/dashboards.md + operation_center/triggers.md: xdr/features/automate/triggers.md + playbooks/actions.md: xdr/features/automate/actions.md + playbooks/library/aws.md: xdr/features/automate/library/aws.md + playbooks/library/binaryedge-s-api.md: xdr/features/automate/library/binaryedge-s-api.md + playbooks/library/censys.md: xdr/features/automate/library/censys.md + playbooks/library/certificate-transparency.md: xdr/features/automate/library/certificate-transparency.md + playbooks/library/detection-rules.md: xdr/features/automate/library/detection-rules.md + playbooks/library/digital-shadows.md: xdr/features/automate/library/digital-shadows.md + playbooks/library/fileutils.md: xdr/features/automate/library/fileutils.md + playbooks/library/fortigate-fw.md: xdr/features/automate/library/fortigate-fw.md + playbooks/library/git.md: xdr/features/automate/library/git.md + playbooks/library/glimps.md: xdr/features/automate/library/glimps.md + playbooks/library/google.md: xdr/features/automate/library/google.md + playbooks/library/harfanglab.md: xdr/features/automate/library/harfanglab.md + playbooks/library/http.md: xdr/features/automate/library/http.md + playbooks/library/iknowwhatyoudownload.md: xdr/features/automate/library/iknowwhatyoudownload.md + playbooks/library/imperva.md: xdr/features/automate/library/imperva.md + playbooks/library/iptoasn.md: xdr/features/automate/library/iptoasn.md + playbooks/library/mandrill.md: xdr/features/automate/library/mandrill.md + playbooks/library/mattermost.md: xdr/features/automate/library/mattermost.md + playbooks/library/misp.md: xdr/features/automate/library/misp.md + playbooks/library/mwdb.md: xdr/features/automate/library/mwdb.md + playbooks/library/onyphe.md: xdr/features/automate/library/onyphe.md + playbooks/library/osint.md: xdr/features/automate/library/osint.md + playbooks/library/pagerduty.md: xdr/features/automate/library/pagerduty.md + playbooks/library/panda-security.md: xdr/features/automate/library/panda-security.md + playbooks/library/public-suffix.md: xdr/features/automate/library/public-suffix.md + playbooks/library/riskiq.md: xdr/features/automate/library/riskiq.md + playbooks/library/rss.md: xdr/features/automate/library/rss.md + playbooks/library/sekoia-io.md: xdr/features/automate/library/sekoia-io.md + playbooks/library/servicenow.md: xdr/features/automate/library/servicenow.md + playbooks/library/shodan.md: xdr/features/automate/library/shodan.md + playbooks/library/stix.md: xdr/features/automate/library/stix.md + playbooks/library/the-hive.md: xdr/features/automate/library/the-hive.md + playbooks/library/tranco.md: xdr/features/automate/library/tranco.md + playbooks/library/triage.md: xdr/features/automate/library/triage.md + playbooks/library/vade-secure.md: xdr/features/automate/library/vade-secure.md + playbooks/library/virustotal.md: xdr/features/automate/library/virustotal.md + playbooks/library/whois.md: xdr/features/automate/library/whois.md + playbooks/operators.md: xdr/features/automate/operators.md + playbooks/overview.md: xdr/features/automate/index.md + playbooks/triggers.md: xdr/features/automate/triggers.md + searching/dork.md: xdr/features/investigate/dork_language.md + searching/search_events.md: xdr/features/investigate/events.md + tip/develop/rest_api/identity_and_authentication.md: tip/develop/rest_api/community.md + user_center.md: getting_started/index.md + user_center/apikeys.md: getting_started/manage_api_keys.md + user_center/multi_factor_authentication.md: getting_started/account_security.md + xdr/develop/rest_api/identity_and_authentication.md: xdr/develop/rest_api/community.md + xdr/features/collect/ingestion_methods/sekoiaio.md: xdr/features/collect/integrations/endpoint/sekoiaio.md + xdr/features/collect/integrations/cloud_and_saas/google/google_workspace.md: xdr/features/collect/integrations/cloud_and_saas/google/google_reports.md + xdr/features/collect/integrations/cloud_and_saas/netskope_events.md: xdr/features/collect/integrations/cloud_and_saas/netskope/netskope_events.md + xdr/features/collect/integrations/endpoint/checkpoint_harmony.md: xdr/features/collect/integrations/endpoint/checkpoint_harmony_mobile.md + xdr/features/collect/integrations/endpoint/trend_micro_deep_security.md: xdr/features/collect/integrations/endpoint/trend_micro/trend_micro_deep_security.md + xdr/features/investigate/dork_language.md: xdr/features/investigate/events_query_language.md +- redoc +- intakes_by_uuid repo_url: https://github.com/SEKOIA-IO/documentation site_name: Sekoia.io Documentation site_url: https://docs.sekoia.io theme: - custom_dir: theme - favicon: assets/favicon.png - features: - - navigation.tabs - - navigation.top - - navigation.footer - - content.code.annotate - - content.action.edit - font: false - include_search_page: true - lang: en - logo: assets/sekoiaio.svg - name: material - search_index_only: false + custom_dir: theme + favicon: assets/favicon.png + features: + - navigation.tabs + - navigation.top + - navigation.footer + - content.code.annotate + - content.action.edit + font: false + include_search_page: true + lang: en + logo: assets/sekoiaio.svg + name: material + search_index_only: false