Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrathon documentation improvement #1896

Merged
merged 239 commits into from
Jul 31, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
239 commits
Select commit Hold shift + click to select a range
10b0298
Integration folder creation and move of integration related folders
Adamowoc Jul 16, 2024
e14fdbf
regulation
Adamowoc Jul 16, 2024
2be3fa9
add integration button on documentation home page
Adamowoc Jul 16, 2024
dd7ba3c
add index.md in integraiton folder
Adamowoc Jul 16, 2024
edca424
create integration asset folder and move everything from operation_ce…
Adamowoc Jul 16, 2024
7a8671c
change links
Adamowoc Jul 16, 2024
422cb05
create a shared content for integration doc
pbivic Jul 16, 2024
e15bfbc
Add a shared content for playbook creation
pbivic Jul 16, 2024
be61f91
add shared content for intake creation
pbivic Jul 16, 2024
08b3a80
change name and add intake_conf
pbivic Jul 16, 2024
ad66b3c
new template
Jul 16, 2024
65cf04a
add shared content for forwarder
pbivic Jul 16, 2024
65ce907
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 16, 2024
f4762b0
updated template
Jul 16, 2024
4c1f882
use the shared content
pbivic Jul 16, 2024
32685b9
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
Jul 16, 2024
a9dfd3e
updated_template_again
Jul 16, 2024
7b5c664
Fix the note
pbivic Jul 16, 2024
49674b0
fix note boxe
pbivic Jul 16, 2024
489188a
change header level
pbivic Jul 16, 2024
d3e2cb8
template_go_to
Jul 16, 2024
d72832d
Update ioccollections image
CharlesLR-sekoia Jul 16, 2024
4511df7
add new image
Jul 16, 2024
ab8da5f
add index.md in integraiton folder
Adamowoc Jul 16, 2024
cb1b5ad
create integration asset folder and move everything from operation_ce…
Adamowoc Jul 16, 2024
37e9a02
change links
Adamowoc Jul 16, 2024
3f3ad8b
create a shared content for integration doc
pbivic Jul 16, 2024
ee6383d
Add a shared content for playbook creation
pbivic Jul 16, 2024
b0666d3
add shared content for intake creation
pbivic Jul 16, 2024
b5b7dd6
change name and add intake_conf
pbivic Jul 16, 2024
d2be01c
new template
Jul 16, 2024
0ee9fe8
updated template
Jul 16, 2024
f375e86
add shared content for forwarder
pbivic Jul 16, 2024
643520f
use the shared content
pbivic Jul 16, 2024
8a1816b
updated_template_again
Jul 16, 2024
951a579
Fix the note
pbivic Jul 16, 2024
3415ba4
fix note boxe
pbivic Jul 16, 2024
5d27dff
change header level
pbivic Jul 16, 2024
014dbb2
new folders
Jul 16, 2024
eefbf1b
new folders
Jul 16, 2024
6d0273e
Add some files
TOUFIKIzakarya Jul 16, 2024
2af9e96
Merge remote-tracking branch 'upstream/feature/integration-rework' in…
TOUFIKIzakarya Jul 16, 2024
840a0d6
first_integration_with_new_template
Jul 16, 2024
1a523dd
add structre to mkdocs
TOUFIKIzakarya Jul 17, 2024
b20a940
add structre of integration list
TOUFIKIzakarya Jul 17, 2024
35f3176
updated design to discuss
Jul 17, 2024
078c9aa
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
Jul 17, 2024
937a2ce
update first
Jul 17, 2024
96aee9d
add vendor and coverage score
Jul 17, 2024
63d07d4
fix_image_display
Jul 17, 2024
48b79a5
update doc integration dev
rombernier Jul 16, 2024
3e0c32d
update develop an integration reorg
rombernier Jul 17, 2024
e615820
update develop an integration reorg
rombernier Jul 17, 2024
b4d5c6d
Merge branch 'feature/integration-rework' into integrathon/custom_format
rombernier Jul 17, 2024
afbb2fe
update develop an integration reorg
rombernier Jul 17, 2024
a587f4b
Merge pull request #1905 from SEKOIA-IO/integrathon/custom_format_v2
rombernier Jul 17, 2024
f23756d
Improve guide documentation
Jul 17, 2024
67005aa
new apache doc
pbivic Jul 17, 2024
0721a71
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
0945d10
Remove parser_python
Jul 17, 2024
9817d5a
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
Jul 17, 2024
f33d664
typo in examples
pbivic Jul 17, 2024
13e4f47
delete useless repo that was added
pbivic Jul 17, 2024
eb15b11
update link custom format
rombernier Jul 17, 2024
69566e4
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
cd2cd35
Mention pull request creation
Jul 17, 2024
42c95d7
Remove python_parser from mkdoc
Jul 17, 2024
a58fd15
update doc link
rombernier Jul 17, 2024
782ced7
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
c2b4892
add spamassassin
pbivic Jul 17, 2024
749a958
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
4cab35b
add arubaos
pbivic Jul 17, 2024
9187789
remove graylog.md duplicate
Adamowoc Jul 17, 2024
f96ca83
Merge remote-tracking branch 'refs/remotes/origin/feature/integration…
Adamowoc Jul 17, 2024
55607f7
add bind and broadcam_edge_swg
pbivic Jul 17, 2024
c98847b
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
b06265a
add spamassassin
pbivic Jul 17, 2024
5a5b9eb
update doc link
rombernier Jul 17, 2024
aa7ac9f
Remove python_parser from mkdoc
Jul 17, 2024
48eece2
add arubaos
pbivic Jul 17, 2024
15ad3a6
beginning of index for ingestion_methods
Adamowoc Jul 17, 2024
104480c
update doc automation
rombernier Jul 17, 2024
abc19e1
Merge remote-tracking branch 'refs/remotes/origin/feature/integration…
Adamowoc Jul 17, 2024
8f58d40
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
58a6d61
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
6b1a776
add symantec endpoint protection
pbivic Jul 17, 2024
4e9cc05
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
00da60d
add cisco_esa ciscp_ise cisco_ios and checkpoint
pbivic Jul 17, 2024
ba6efaa
add cisco nx and meraki
pbivic Jul 17, 2024
5553afd
update doc
rombernier Jul 17, 2024
c7e4e97
update doc
rombernier Jul 17, 2024
5d2e1bd
add citrix cisco asa wsa et claroty
pbivic Jul 17, 2024
c8628e7
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
f71063a
update doc
rombernier Jul 17, 2024
b95d84e
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
0d20787
normalize daspren
pbivic Jul 17, 2024
03357c2
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
479b533
add cyberwatch detection
pbivic Jul 17, 2024
d083901
put text before detection rule
pbivic Jul 17, 2024
889870a
add text before detection rule
pbivic Jul 17, 2024
dffcd44
add apache spamassassin aruba bin eset haproxy
Jul 17, 2024
6eed449
add copy code
rombernier Jul 17, 2024
ea7ea1a
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 17, 2024
0341712
add auditbeat winlogbeat ekinops big-ip and nginx
pbivic Jul 17, 2024
c943532
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
f1c3675
move the forwarder to new dir
pbivic Jul 17, 2024
dde24df
add link for visibility
pbivic Jul 17, 2024
0f4507b
Add definition of parsing warning and error. Some fixes
Jul 17, 2024
740faf5
Fix compliance command line
Jul 17, 2024
6a8aa28
add raw events images and details doc
Jul 17, 2024
c723cc9
Reorder items in menu
Jul 17, 2024
8609591
remove TODO
Jul 17, 2024
fcf5b73
mkdocs update
Adamowoc Jul 17, 2024
606c080
raw sample
Jul 17, 2024
cd94720
add raw events
Jul 17, 2024
f2123a2
add forcepoint and fortigate
pbivic Jul 17, 2024
27aa5e0
add auditbeat winlogbeat
Jul 17, 2024
c4a1df8
add forti all and freeradius
pbivic Jul 17, 2024
19a6fcb
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 17, 2024
978f8f8
Modify: ekinops, f5bigip, nginx, daspren
TOUFIKIzakarya Jul 17, 2024
d7598be
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
TOUFIKIzakarya Jul 17, 2024
0943e41
Add fortimail, freeradius, checkpoint, fortigate and fortiweb
TOUFIKIzakarya Jul 17, 2024
4da95d8
Add claroty and cyberwatch detection
TOUFIKIzakarya Jul 18, 2024
595b72b
add new docs
pbivic Jul 18, 2024
c9567ad
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
13839f3
Modify orders
TOUFIKIzakarya Jul 18, 2024
34f9e34
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
TOUFIKIzakarya Jul 18, 2024
073b32f
add kapersky
pbivic Jul 18, 2024
3808190
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
34e60fc
add F5 big ip and nginx
Jul 18, 2024
9e506b4
modify orders 1
TOUFIKIzakarya Jul 18, 2024
6add79e
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
TOUFIKIzakarya Jul 18, 2024
3c6cf49
Add infoblox_ddi
TOUFIKIzakarya Jul 18, 2024
4b9874c
Modify ibm aix
TOUFIKIzakarya Jul 18, 2024
c4ac679
checkpoint and claroty schemes
pbivic Jul 18, 2024
8c0776a
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
2605917
mkdocs remake
Adamowoc Jul 18, 2024
58456f0
l is not equal t
Adamowoc Jul 18, 2024
d9040ee
path correction
Adamowoc Jul 18, 2024
760f443
add claroty cyberwatch dapsren and ekinops schemes
pbivic Jul 18, 2024
a4e1217
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
249fc6d
add action library in integration
rombernier Jul 18, 2024
e6887fc
add scheme for fortimail ibmAIX freeradius infoblox fortigate fortiweb
pbivic Jul 18, 2024
0838c12
fix conflict
rombernier Jul 18, 2024
9f63c4c
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 18, 2024
9511289
add overview
rombernier Jul 18, 2024
7124a0b
Detailed more usecase. Harmonize sub-chapters
Jul 18, 2024
801641e
fix link
rombernier Jul 18, 2024
753f722
fix link
rombernier Jul 18, 2024
865bd52
Update docs/integration/develop_integration/overview.md
Adamowoc Jul 18, 2024
c4de5a2
Update docs/integration/develop_integration/overview.md
Adamowoc Jul 18, 2024
9318da2
add AWS
pbivic Jul 18, 2024
fa1a409
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
e356db9
Improve format section. Delete contribute and testing pages
Jul 18, 2024
e624393
fix name
rombernier Jul 18, 2024
17594e9
azure new doc
pbivic Jul 18, 2024
b87a737
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
885fd6b
introduction landing page and overview for catego
Jul 18, 2024
b6ef3f1
Add email and network docs
TOUFIKIzakarya Jul 18, 2024
766cb2c
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
TOUFIKIzakarya Jul 18, 2024
8267078
del coverage score
pbivic Jul 18, 2024
b528658
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
48ca290
update apache and ekinops_oneos
Jul 18, 2024
340885d
apache
Jul 18, 2024
9922a85
Clean documentation menu
Jul 18, 2024
c65c8eb
add index
Jul 18, 2024
19a8079
add umbrella, cisco, cef
pbivic Jul 18, 2024
3ebc5a8
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
adec95a
add cloudflare
pbivic Jul 18, 2024
60d361d
add doc
rombernier Jul 18, 2024
b370fc5
add doc
rombernier Jul 18, 2024
aa1fc3b
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 18, 2024
b017971
updates yml
Jul 18, 2024
0d4528d
upadtes cloud providers
Jul 18, 2024
98d4d1a
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
Jul 18, 2024
ec3796e
add corwsdstrike
pbivic Jul 18, 2024
10c30d4
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 18, 2024
f61beaf
remove TODOs
Jul 18, 2024
478415f
remove_sase_from_iam
Jul 18, 2024
106100f
fix fortimail and review appli
Jul 19, 2024
e627da1
Automated migration to the new template
pbivic Jul 19, 2024
dfa0cbe
Revert to 10c30d4191383aadb247df92b952a6b9889b93f7
pbivic Jul 19, 2024
a2349ba
automate migration
pbivic Jul 19, 2024
b27882b
add deltas by correcting name delta in csv
pbivic Jul 19, 2024
cda0129
Put detection section in shared content for maintanability
pbivic Jul 19, 2024
40d3ad3
fix typo
pbivic Jul 19, 2024
569e34e
bad field fix
pbivic Jul 19, 2024
13713cd
commit with paul
Jul 19, 2024
1d6bb44
fixes
Jul 19, 2024
13a307d
somes fixes
Jul 19, 2024
f953984
remove toto template files
Jul 19, 2024
c231c7b
add the sample shared content by automated script
pbivic Jul 22, 2024
b698505
Merge branch 'main' into feature/integration-rework
pbivic Jul 22, 2024
8c5309b
add shared content
pbivic Jul 22, 2024
c38afef
del bad IAM dir
pbivic Jul 23, 2024
3895184
add new tree
pbivic Jul 23, 2024
256c709
run of update_mkdocs.py script
pbivic Jul 23, 2024
8eefd39
del bad shared content
pbivic Jul 23, 2024
7302f74
fix on detection section shared content
pbivic Jul 23, 2024
0d4fe10
fix typo and activity logs
Jul 23, 2024
6eb15af
divide logs by 2
pbivic Jul 24, 2024
8956d89
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 24, 2024
cc39ae5
update activity logs mysql and apache
Jul 24, 2024
914ca5c
apache azure mysql activity logs
Jul 24, 2024
b6341ed
Merge branch 'main' of https://github.com/SEKOIA-IO/documentation int…
pbivic Jul 25, 2024
5b1ef12
Update overview info
penhouetp Jul 25, 2024
4832b81
update overview applicative
rombernier Jul 25, 2024
02fe340
Merge branch 'feature/integration-rework' of github.com:SEKOIA-IO/doc…
rombernier Jul 25, 2024
145a75b
add overview
penhouetp Jul 25, 2024
bb68cdd
Change overviexs
pbivic Jul 25, 2024
f4f0957
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 25, 2024
46ebd46
fix images
pbivic Jul 25, 2024
46cecf2
fix broken images
pbivic Jul 25, 2024
9dbd5a9
fix image link
rombernier Jul 25, 2024
194fe68
fix images in shared content
pbivic Jul 25, 2024
6816482
Merge branch 'feature/integration-rework' of https://github.com/SEKOI…
pbivic Jul 25, 2024
ec4f5ba
Merge branch 'main' of https://github.com/SEKOIA-IO/documentation int…
pbivic Jul 25, 2024
d3f6fa9
fix link tip
rombernier Jul 25, 2024
06fd305
fix link
rombernier Jul 25, 2024
131ad51
feature/integration-rework: change rfc number
Jul 25, 2024
da129f8
AWS and Azure QA review
Jul 26, 2024
354853d
updates security network docs
Jul 26, 2024
31b18a4
update new batch of security network solutions doc
Jul 26, 2024
ff26466
new batch of doc for security network
Jul 26, 2024
87fb51b
almost forgot to commit
Jul 26, 2024
5d0f412
remaning
Jul 26, 2024
bc102f6
add symbolic link+ correct indent
pbivic Jul 30, 2024
e28e82b
clean useless files and update script
pbivic Jul 30, 2024
db840c6
del bad links
pbivic Jul 30, 2024
0745542
del bad links
pbivic Jul 30, 2024
f8b053a
Merge branch 'main' into feature/integration-rework
pbivic Jul 30, 2024
1a566aa
fix link images
pbivic Jul 30, 2024
a838fc0
fix dead links
pbivic Jul 30, 2024
6e6d7d3
Merge branch 'main' of https://github.com/SEKOIA-IO/documentation int…
pbivic Jul 30, 2024
29d68fb
add sentinelone cloudfunnel2,0
pbivic Jul 30, 2024
4763cba
Merge branch 'main' into feature/integration-rework
pbivic Jul 31, 2024
e6d551c
convert old doc to new template
pbivic Jul 31, 2024
6e8a8df
add path to new doc
pbivic Jul 31, 2024
c36559e
Merge branch 'main' into feature/integration-rework
pbivic Jul 31, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -22,4 +22,5 @@ docs/getting_started/inactive_users
.DS_Store
*.pyc
node_modules/
Icon?
Icon?
/docu
85 changes: 44 additions & 41 deletions _shared_content/automate/actions.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,11 @@ The Actions Library lists all available actions in playbooks with their detailed

| Name | Description |
| --- | --- |
| [Get Event Field Common Values](../library/sekoia-io/#get-event-field-common-values) | Retrieve the most common values of an ECS field based on the time window |
| [List Assets](../library/sekoia-io/#list-assets) | Retrieve detailed information about assets based on a filter |
| [Search Alerts](../library/sekoia-io/#search-alerts) | Retrieve detailed information about alerts (such as the urgency, name of the rule, etc… except events) based on a filter. |
| [Get Alert](../library/sekoia-io/#get-alert) | Retrieve detailed alert information such as the urgency, name of the rule, pattern, etc… except events. |
| [Get Events](../library/sekoia-io/#get-events) | Retrieve events based on a search. This action is equivalent to a search on the event page and takes into consideration 3 parameters: a query with filters (`source.ip=xx.xxx.xx`), and earliest time/latest time: two dates to determine the date range of the search. |
| [Get Event Field Common Values](/integration/action_library/generic/sekoia-io/#get-event-field-common-values) | Retrieve the most common values of an ECS field based on the time window |
| [List Assets](/integration/action_library/generic/sekoia-io/#list-assets) | Retrieve detailed information about assets based on a filter |
| [Search Alerts](/integration/action_library/generic/sekoia-io/#search-alerts) | Retrieve detailed information about alerts (such as the urgency, name of the rule, etc… except events) based on a filter. |
| [Get Alert](/integration/action_library/generic/sekoia-io/#get-alert) | Retrieve detailed alert information such as the urgency, name of the rule, pattern, etc… except events. |
| [Get Events](/integration/action_library/generic/sekoia-io/#get-events) | Retrieve events based on a search. This action is equivalent to a search on the event page and takes into consideration 3 parameters: a query with filters (`source.ip=xx.xxx.xx`), and earliest time/latest time: two dates to determine the date range of the search. |

!!!note
`Get Events` can be used to retrieve events from an alert. Events associated to an alert contain the key `alert_short_ids` with the value of the ID of the alert.
Expand All @@ -31,15 +31,15 @@ The Actions Library lists all available actions in playbooks with their detailed

| Name | Description |
| --- | --- |
| [Create an asset](../library/sekoia-io/#create-asset) | Create an asset |
| [Delete an asset](../library/sekoia-io/#delete-an-asset) | Delete an asset |
| [Add attribute to asset](../library/sekoia-io/#add-attribute-to-asset) | Add attribute to asset |
| [Add key to asset](../library/sekoia-io/#add-key-to-asset) | Add key to asset |
| [Edit alert](../library/sekoia-io/#edit-alert) | Edit an alert details such as the urgency or the alert category |
| [Comment alert](../library/sekoia-io/#comment-alert) | Add a comment to the alert |
| [Update alert status](../library/sekoia-io/#update-alert-status) | Change the status of an alert |
| [Push Events to Intake](../library/sekoia-io/#push-events-to-intake) | Push one or more events to an Intake |
| [Attach Alerts to Case](../library/sekoia-io/#attach-alerts-to-case) | Attach one or more alerts to a case. |
| [Create an asset](/integration/action_library/generic/sekoia-io/#create-asset) | Create an asset |
| [Delete an asset](/integration/action_library/generic/sekoia-io/#delete-an-asset) | Delete an asset |
| [Add attribute to asset](/integration/action_library/generic/sekoia-io/#add-attribute-to-asset) | Add attribute to asset |
| [Add key to asset](/integration/action_library/generic/sekoia-io/#add-key-to-asset) | Add key to asset |
| [Edit alert](/integration/action_library/generic/sekoia-io/#edit-alert) | Edit an alert details such as the urgency or the alert category |
| [Comment alert](/integration/action_library/generic/sekoia-io/#comment-alert) | Add a comment to the alert |
| [Update alert status](/integration/action_library/generic/sekoia-io/#update-alert-status) | Change the status of an alert |
| [Push Events to Intake](/integration/action_library/generic/sekoia-io/#push-events-to-intake) | Push one or more events to an Intake |
| [Attach Alerts to Case](/integration/action_library/generic/sekoia-io/#attach-alerts-to-case) | Attach one or more alerts to a case. |


#### How to update an alert status
Expand All @@ -58,51 +58,54 @@ To update an alert status, you need to copy the `status_uuid` corresponding to t

To get notified, you can rely on these tools:

- [Mandrill](library/mandrill.md): Send Message
- [Mattermost](library/mattermost.md): Post message / Post Sekoia.io alert
- [Pagerduty](library/pagerduty.md): Trigger Alert
- [The Hive](library/the-hive.md): Create an alert in the Hive
- [Mandrill](/integration/action_library/applicative/mandrill.md): Send Message
- [Mattermost](/integration/action_library/applicative/mattermost.md): Post message / Post Sekoia.io alert
- [Pagerduty](/integration/action_library/applicative/pagerduty.md): Trigger Alert
- [The Hive](/integration/action_library/collaboration_tools/the-hive.md): Create an alert in the Hive
- ...

## Data collection

If you have an account in one of the listed tools below, you can easily extract data from there and import it to Sekoia.io. This is made possible with an API key.

- [BinaryEdge](library/binaryedge-s-api.md)
- [Censys](library/censys.md)
- [GLIMPS](library/glimps.md)
- [IKnowWhatYouDownloaded](library/iknowwhatyoudownload.md)
- [Onyphe](library/onyphe.md)
- [Public Suffix](library/public-suffix.md)
- [RiskIQ](library/riskiq.md)
- [Shodan](library/shodan.md)
- [VirusTotal](library/virustotal.md)
- [Whois](library/whois.md)
- [BinaryEdge](/integration/action_library/threat_intelligence/binaryedge-s-api.md)
- [Censys](/integration/action_library/threat_intelligence/censys.md)
- [GLIMPS](/integration/action_library/threat_intelligence/glimps.md)
- [IKnowWhatYouDownloaded](/integration/action_library/threat_intelligence/iknowwhatyoudownload.md)
- [Onyphe](/integration/action_library/threat_intelligence/onyphe.md)
- [Public Suffix](/integration/action_library/threat_intelligence/public-suffix.md)
- [RiskIQ](/integration/action_library/threat_intelligence/riskiq.md)
- [Shodan](/integration/action_library/threat_intelligence/shodan.md)
- [VirusTotal](/integration/action_library/threat_intelligence/virustotal.md)
- [Whois](/integration/action_library/threat_intelligence/whois.md)
- ...

## Helpers

| Name | Description |
| --- | --- |
| [fileutils](library/fileutils.md) | Extract data from XML or JSON files |
| [http](library/http.md) | Request HTTP resources (download file, request URL) |
| [STIX](library/stix.md) | Add source, add tags, create relationships, cryptolaemus to STIX, CVE to STIX, filter bundle, JSON objects to observables, VirusTotal LiveHunt to observables, MISP to STIX, observables to contextualized indicators, observables to indicators, remove orphan objects, STIX to MISP, string to observables |
| [fileutils](/integration/action_library/generic/fileutils.md) | Extract data from XML or JSON files |
| [http](/integration/action_library/generic/http.md) | Request HTTP resources (download file, request URL) |
| [STIX](/integration/action_library/threat_intelligence/stix.md) | Add source, add tags, create relationships, cryptolaemus to STIX, CVE to STIX, filter bundle, JSON objects to observables, VirusTotal LiveHunt to observables, MISP to STIX, observables to contextualized indicators, observables to indicators, remove orphan objects, STIX to MISP, string to observables |

These helpers need their associated trigger to function properly:

| Name | Description |
| --- | --- |
| [MISP](library/misp.md) | Gather, store, share and correlate threat intelligence. Convert from MISP to STIX, publish MISP event |
| [MWDB](library/mwdb.md) | Convert a MWDB config to a bundle of observables |
| [Triage](library/triage.md) | Triage raw results to observables |
| [MISP](/integration/action_library/threat_intelligence/misp.md) | Gather, store, share and correlate threat intelligence. Convert from MISP to STIX, publish MISP event |
| [MWDB](/integration/action_library/threat_intelligence/mwdb.md) | Convert a MWDB config to a bundle of observables |
| [Triage](/integration/action_library/threat_intelligence/triage.md) | Triage raw results to observables |

## Third-party applications

- [Microsoft Entra ID (Azure AD) ](library/microsoft-entra-id.md)
- [Microsoft Remote Server](library/microsoft-remote-server.md)
- [Fortigate Firewalls](library/fortigate-firewalls.md)
- [HarfangLab](library/harfanglab.md)
- [Panda Security](library/panda-security.md)
- [Sentinel One](library/sentinelone.md)
- [ServiceNow](library/servicenow.md)
- [Microsoft Entra ID (Azure AD) ](/integration/action_library/iam_sase/microsoft-entra-id.md)
- [Microsoft Remote Server](/integration/action_library/applicative/microsoft-remote-server.md)
- [Fortigate Firewalls](/integration/action_library/network/fortigate-firewalls.md)
- [HarfangLab](/integration/action_library/endpoint/harfanglab.md)
- [Panda Security](/integration/action_library/endpoint/panda-security.md)
- [Sentinel One](/integration/action_library/endpoint/sentinelone.md)
- [ServiceNow](/integration/action_library/collaboration_tools/servicenow.md)
- ...

More actions are available in the Actions Library. To learn how to set up an action, please refer to its documentation.

Expand Down
2 changes: 1 addition & 1 deletion _shared_content/automate/playbooks-on-premises.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

Our clients may find it necessary to execute Playbook actions within a local network that remains isolated from external internet access or rejects inbound connections. To meet this particular need, we enable users to select actions they want to perform on their local network directly from the Playbooks' user interface.

Clients must undertake a short installation process to harness the full potential of this security-enhancing feature. This involves installing our [dedicated agent](https://docs.sekoia.io/xdr/features/collect/integrations/endpoint/sekoiaio/) and Docker onto a Linux machine within their local network. The meticulous setup ensures that Playbook actions can be executed with the utmost reliability and security, maintaining the integrity of the local network environment.
Clients must undertake a short installation process to harness the full potential of this security-enhancing feature. This involves installing our [dedicated agent](https://docs.sekoia.io/integration/integrations/endpoint/sekoiaio/) and Docker onto a Linux machine within their local network. The meticulous setup ensures that Playbook actions can be executed with the utmost reliability and security, maintaining the integrity of the local network environment.

Below, we provide detailed instructions on how to accomplish the installation process.

Expand Down
2 changes: 0 additions & 2 deletions _shared_content/develop/guides/authentication_overview.md

This file was deleted.

19 changes: 0 additions & 19 deletions _shared_content/develop/guides/filtering.md

This file was deleted.

100 changes: 0 additions & 100 deletions _shared_content/develop/guides/formats/create_a_format.md

This file was deleted.

Loading
Loading