diff --git a/Packs/Doppel/Author_image.png b/Packs/Doppel/Author_image.png index e69de29bb2d1..d0bec8a28888 100644 Binary files a/Packs/Doppel/Author_image.png and b/Packs/Doppel/Author_image.png differ diff --git a/Packs/Doppel/Classifiers/classifier-Doppel_Incoming.json b/Packs/Doppel/Classifiers/classifier-Doppel_Incoming.json new file mode 100644 index 000000000000..eacb08169580 --- /dev/null +++ b/Packs/Doppel/Classifiers/classifier-Doppel_Incoming.json @@ -0,0 +1,298 @@ +{ + "brands": null, + "cacheVersn": 0, + "defaultIncidentType": "", + "definitionId": "", + "description": "", + "feed": false, + "fromServerVersion": "", + "id": "d1d1bfa4-c898-4eae-8a72-1e36d11ebbf2", + "incidentSamples": null, + "indicatorSamples": null, + "instanceIds": null, + "itemVersion": "", + "keyTypeMap": {}, + "locked": false, + "logicalVersion": 13, + "mapping": { + "Doppel Alert": { + "dontMapEventToLabels": false, + "internalMapping": { + "Additional Indicators": { + "simple": "entity" + }, + "Alert ID": { + "simple": "id" + }, + "Alert Source": { + "simple": "source" + }, + "Alert tags": { + "simple": "tags" + }, + "Audit Log History": { + "simple": "audit_logs" + }, + "Block Indicators Status": { + "simple": "entity_state" + }, + "External Link": { + "simple": "doppel_link" + }, + "External Severity": { + "simple": "severity" + }, + "Selected Indicators": { + "simple": "entity" + }, + "Source Created By": { + "simple": "uploaded_by" + }, + "State": { + "simple": "queue_state" + }, + "Vulnerable Product": { + "simple": "brand" + }, + "created_at": { + "simple": "created_at" + }, + "entity": { + "simple": "entity" + }, + "entity_content.root_domain.contact_email": { + "simple": "entity_content.root_domain.contact_email" + }, + "entity_content.root_domain.country_code": { + "simple": "entity_content.root_domain.country_code" + }, + "entity_content.root_domain.domain": { + "simple": "entity_content.root_domain.domain" + }, + "entity_content.root_domain.hosting_provider": { + "simple": "entity_content.root_domain.hosting_provider" + }, + "entity_content.root_domain.ip_address": { + "simple": "entity_content.root_domain.ip_address" + }, + "entity_content.root_domain.mx_records": { + "simple": "mx_records" + }, + "entity_content.root_domain.nameservers\t": { + "simple": "nameservers" + }, + "entity_content.root_domain.registrar\t": { + "simple": "entity_content.root_domain.registrar" + }, + "entity_state": { + "simple": "entity_state" + }, + "notes": { + "simple": "notes" + }, + "platform": { + "simple": "platform" + }, + "product": { + "simple": "product" + }, + "queue_state": { + "simple": "queue_state" + }, + "severity": { + "simple": "severity" + }, + "source": { + "simple": "source" + }, + "sourceBrand": { + "simple": "brand" + }, + "uploaded_by": { + "simple": "uploaded_by" + } + } + }, + "dbot_classification_incident_type_all": { + "dontMapEventToLabels": true, + "internalMapping": { + "Additional Indicators": { + "simple": "entity" + }, + "Audit Logs": { + "simple": "audit_logs.[]." + }, + "Audit_logs_History": { + "simple": "audit_logs.[]" + }, + "Audit_logs_info": { + "simple": "audit_logs.[]" + }, + "Block Indicators Status": { + "simple": "entity_state" + }, + "Created At": { + "simple": "created_at" + }, + "Doppel Alert Brand": { + "simple": "brand" + }, + "Doppel Alert ID": { + "simple": "id" + }, + "Doppel Audit Logs": { + "simple": "audit_logs.[]." + }, + "Doppel Brand": { + "simple": "brand" + }, + "Doppel Created At": { + "simple": "created_at" + }, + "Doppel Entity": { + "simple": "entity" + }, + "Doppel Entity Content": { + "simple": "entity_content" + }, + "Doppel Entity State": { + "simple": "entity_state" + }, + "Doppel Link": { + "simple": "doppel_link" + }, + "Doppel Notes": { + "simple": "notes" + }, + "Doppel Platform": { + "simple": "platform" + }, + "Doppel Product": { + "simple": "product" + }, + "Doppel Queue State": { + "simple": "queue_state" + }, + "Doppel Severity": { + "simple": "severity" + }, + "Doppel Source": { + "simple": "source" + }, + "Doppel Tags": { + "simple": "tags" + }, + "Doppel Uploaded By": { + "simple": "uploaded_by" + }, + "Entity": { + "simple": "entity" + }, + "Entity Content": { + "simple": "entity_content" + }, + "Entity State": { + "simple": "entity_state" + }, + "External Link": { + "simple": "doppel_link" + }, + "External Severity": { + "simple": "severity" + }, + "Notes": { + "simple": "notes" + }, + "Platform": { + "simple": "platform" + }, + "Product": { + "simple": "product" + }, + "Queue State": { + "simple": "queue_state" + }, + "Selected Indicators": { + "simple": "entity" + }, + "Source Created By": { + "simple": "uploaded_by" + }, + "State": { + "simple": "queue_state" + }, + "Tags": { + "simple": "tags" + }, + "Uploaded By": { + "simple": "uploaded_by" + }, + "Vulnerable Product": { + "simple": "brand" + }, + "created_at": { + "simple": "created_at" + }, + "dbotMirrorDirection": { + "simple": "mirror_direction" + }, + "dbotMirrorId": { + "simple": "id" + }, + "dbotMirrorInstance": { + "simple": "mirror_instance" + }, + "entity": { + "simple": "entity" + }, + "entity_content.root_domain.registrar\t": { + "simple": "entity_content.root_domain.registrar" + }, + "entity_state": { + "simple": "entity_state" + }, + "notes": { + "simple": "notes" + }, + "occurred": { + "simple": "created_at" + }, + "platform": { + "simple": "platform" + }, + "product": { + "simple": "product" + }, + "queue_state": { + "simple": "queue_state" + }, + "severity": { + "simple": "severity" + }, + "source": { + "simple": "source" + }, + "sourceBrand": { + "simple": "brand" + }, + "uploaded_by": { + "simple": "uploaded_by" + } + } + } + }, + "name": "Doppel Incoming", + "nameRaw": "Doppel Incoming", + "packID": "c3beb3d4-5d11-46e9-85ec-87a0586dd624", + "packName": "Fields", + "propagationLabels": [ + "all" + ], + "sourceClassifierId": "", + "system": false, + "toServerVersion": "", + "transformer": {}, + "type": "mapping-incoming", + "unclassifiedCases": null, + "version": -1 +} \ No newline at end of file diff --git a/Packs/Doppel/Classifiers/classifier-Doppel_Outgoing.json b/Packs/Doppel/Classifiers/classifier-Doppel_Outgoing.json new file mode 100644 index 000000000000..33f35ea9daf4 --- /dev/null +++ b/Packs/Doppel/Classifiers/classifier-Doppel_Outgoing.json @@ -0,0 +1,49 @@ +{ + "brands": null, + "cacheVersn": 0, + "defaultIncidentType": "", + "definitionId": "", + "description": "", + "feed": false, + "fromServerVersion": "", + "id": "602a520c-d5d3-45c8-8cd8-5fbbaa6e93ed", + "incidentSamples": null, + "indicatorSamples": null, + "instanceIds": null, + "itemVersion": "", + "keyTypeMap": {}, + "locked": false, + "logicalVersion": 2, + "mapping": { + "Doppel Alert": { + "dontMapEventToLabels": false, + "internalMapping": { + "queue_state": { + "simple": "queuestate" + } + } + }, + "dbot_classification_incident_type_all": { + "dontMapEventToLabels": false, + "internalMapping": { + "Queue State": { + "simple": "labels.queue_state" + } + } + } + }, + "name": "Doppel Outgoing", + "nameRaw": "Doppel Outgoing", + "packID": "c3beb3d4-5d11-46e9-85ec-87a0586dd624", + "packName": "Fields", + "propagationLabels": [ + "all" + ], + "sourceClassifierId": "", + "system": false, + "toServerVersion": "", + "transformer": {}, + "type": "mapping-outgoing", + "unclassifiedCases": null, + "version": -1 +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Alert_ID.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Alert_ID.json new file mode 100644 index 000000000000..279899577437 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Alert_ID.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelalertid", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelalertid", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Alert ID", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Audit_Logs.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Audit_Logs.json new file mode 100644 index 000000000000..890055660a28 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Audit_Logs.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelauditlogs", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelauditlogs", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Audit Logs", + "neverSetAsRequired": false, + "openEnded": true, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "multiSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Brand.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Brand.json new file mode 100644 index 000000000000..8baaa1a4d0fc --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Brand.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": [], + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelbrand", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelbrand", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Brand", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "shortText", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "Doppel Brand", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Created_At.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Created_At.json new file mode 100644 index 000000000000..285a9ac7bec8 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Created_At.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelcreatedat", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelcreatedat", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Created At", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity.json new file mode 100644 index 000000000000..24ab6f94e169 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelentity", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelentity", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Entity", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "url", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_Content.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_Content.json new file mode 100644 index 000000000000..488c5c7f9304 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_Content.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelentitycontent", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelentitycontent", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Entity Content", + "neverSetAsRequired": false, + "openEnded": true, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "multiSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_State.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_State.json new file mode 100644 index 000000000000..a502d8b81194 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Entity_State.json @@ -0,0 +1,68 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": [], + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelentitystate", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelentitystate", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Entity State", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "singleSelect", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "Doppel Entity State", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [ + "", + "active", + "parked", + "down" + ], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "singleSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Link.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Link.json new file mode 100644 index 000000000000..611996069f0f --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Link.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppellink", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppellink", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Link", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "url", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Notes.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Notes.json new file mode 100644 index 000000000000..02b43d03d0ce --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Notes.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelnotes", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelnotes", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Notes", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Platform.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Platform.json new file mode 100644 index 000000000000..88534a30af60 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Platform.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelplatform", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelplatform", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Platform", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Product.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Product.json new file mode 100644 index 000000000000..3e13068fb11f --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Product.json @@ -0,0 +1,72 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": [], + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelproduct", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelproduct", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Product", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "singleSelect", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "Doppel Product", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [ + "", + "domains", + "social_media", + "mobile_apps", + "ecommerce", + "crypto", + "email", + "paid_ads" + ], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "singleSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Queue_State.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Queue_State.json new file mode 100644 index 000000000000..20bb352696ef --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Queue_State.json @@ -0,0 +1,71 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelqueuestate", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelqueuestate", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Queue State", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [ + "", + "doppel_review", + "needs_confirmation", + "actioned", + "archived", + "monitoring", + "taken_down" + ], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "singleSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Severity.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Severity.json new file mode 100644 index 000000000000..f87389ffdef4 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Severity.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelseverity", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelseverity", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Severity", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Source.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Source.json new file mode 100644 index 000000000000..665df198126f --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Source.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppelsource", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppelsource", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Source", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Tags.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Tags.json new file mode 100644 index 000000000000..24846e11fda8 --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Tags.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppeltags", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppeltags", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Tags", + "neverSetAsRequired": false, + "openEnded": true, + "orgType": "", + "ownerOnly": false, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": [], + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "multiSelect", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentFields/incidentfield-Doppel_Uploaded_By.json b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Uploaded_By.json new file mode 100644 index 000000000000..f3ea72f821ac --- /dev/null +++ b/Packs/Doppel/IncidentFields/incidentfield-Doppel_Uploaded_By.json @@ -0,0 +1,63 @@ +{ + "XDRBuiltInField": false, + "XsiamIncidentFieldExtraData": { + "incidentsFilter": null, + "slaGoals": null, + "slaTimer": null, + "timerConditions": null + }, + "aliasTo": "", + "aliases": null, + "associatedToAll": true, + "associatedTypes": null, + "autoCompleteTags": null, + "breachScript": "", + "cacheVersn": 0, + "caseInsensitive": true, + "cliName": "doppeluploadedby", + "closeForm": false, + "columns": null, + "content": false, + "defaultRows": null, + "definitionId": "", + "description": "", + "editForm": true, + "fieldCalcScript": "", + "fromServerVersion": "", + "group": 0, + "hidden": false, + "id": "incident_doppeluploadedby", + "ipVersion": "", + "isReadOnly": false, + "itemVersion": "", + "locked": false, + "mergeStrategy": "", + "name": "Doppel Uploaded By", + "neverSetAsRequired": false, + "openEnded": false, + "orgType": "", + "ownerOnly": true, + "packID": "aba8d875-96b4-472e-8608-84cba2ece652", + "packName": "Incident Fields", + "placeholder": "", + "pretty_name": "", + "required": false, + "runScriptAfterUpdate": false, + "script": "", + "selectValues": null, + "selectValuesMap": null, + "sla": 0, + "system": false, + "systemAssociatedTypes": null, + "template": "", + "threshold": 72, + "toServerVersion": "", + "type": "shortText", + "unmapped": false, + "unsearchable": false, + "useAsKpi": false, + "validatedError": "", + "validationRegex": "", + "version": -1, + "x2_fields": "" +} \ No newline at end of file diff --git a/Packs/Doppel/IncidentTypes/incidenttype-Doppel_Alert.json b/Packs/Doppel/IncidentTypes/incidenttype-Doppel_Alert.json new file mode 100644 index 000000000000..8fe0cd56c9e0 --- /dev/null +++ b/Packs/Doppel/IncidentTypes/incidenttype-Doppel_Alert.json @@ -0,0 +1,38 @@ +{ + "autorun": false, + "cacheVersn": 0, + "closureScript": "", + "color": "#C9C598", + "days": 0, + "daysR": 0, + "default": false, + "definitionId": "", + "detached": false, + "disabled": false, + "extractSettings": { + "fieldCliNameToExtractSettings": {}, + "mode": "Specific" + }, + "fromServerVersion": "", + "hours": 0, + "hoursR": 0, + "id": "Doppel Alert", + "itemVersion": "", + "layout": "acdb3cde-b78d-4fa0-86e3-ef0a01606a26", + "locked": false, + "name": "Doppel Alert", + "onChangeRepAlg": 0, + "packID": "c3beb3d4-5d11-46e9-85ec-87a0586dd624", + "packName": "Fields", + "preProcessingScript": "", + "propagationLabels": [ + "all" + ], + "readonly": false, + "reputationCalc": 0, + "system": false, + "toServerVersion": "", + "version": -1, + "weeks": 0, + "weeksR": 0 +} \ No newline at end of file diff --git a/Packs/Doppel/Integrations/Doppel/Doppel.yml b/Packs/Doppel/Integrations/Doppel/Doppel.yml index fc504a858bcf..bf0d0267de68 100644 --- a/Packs/Doppel/Integrations/Doppel/Doppel.yml +++ b/Packs/Doppel/Integrations/Doppel/Doppel.yml @@ -76,7 +76,6 @@ detaileddescription: |- Once you have the URL and API Key, use the same for configuring the Doppel-XSOAR integration instance. display: Doppel -image:  name: Doppel script: commands: diff --git a/Packs/Doppel/Integrations/Doppel/Doppel_image.png b/Packs/Doppel/Integrations/Doppel/Doppel_image.png index a18ede6127e9..d0bec8a28888 100644 Binary files a/Packs/Doppel/Integrations/Doppel/Doppel_image.png and b/Packs/Doppel/Integrations/Doppel/Doppel_image.png differ diff --git a/Packs/Doppel/Integrations/Doppel/command_examples b/Packs/Doppel/Integrations/Doppel/command_examples index 87806dfb8688..5a4fc8ab41bf 100644 --- a/Packs/Doppel/Integrations/Doppel/command_examples +++ b/Packs/Doppel/Integrations/Doppel/command_examples @@ -1,7 +1,5 @@ -create-alert entity="http://example-entity-url.com" -get-alert id="entity-id" entity="http://example-entity-url.com" - -TODO -update-alert -create-abuse-alert -get-alerts \ No newline at end of file +doppel-create-alert entity="http://example-entity-url.com" +doppel-get-alert id="entity-id" entity="http://example-entity-url.com" +doppel-update-alert id="entity-id" +doppel-get-alerts +doppel-create-abuse-alert entity="http://example-entity-url.com" \ No newline at end of file diff --git a/Packs/Doppel/Layouts/layoutscontainer-Doppel_Alert_Layout.json b/Packs/Doppel/Layouts/layoutscontainer-Doppel_Alert_Layout.json new file mode 100644 index 000000000000..712177a6f0dd --- /dev/null +++ b/Packs/Doppel/Layouts/layoutscontainer-Doppel_Alert_Layout.json @@ -0,0 +1,624 @@ +{ + "cacheVersn": 0, + "close": null, + "definitionId": "", + "description": "", + "detached": false, + "details": null, + "detailsV2": { + "TypeName": "", + "tabs": [ + { + "id": "summary", + "name": "Legacy Summary", + "type": "summary" + }, + { + "id": "caseinfoid", + "name": "Incident Info", + "sections": [ + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8", + "isVisible": true, + "items": [ + { + "endCol": 2, + "fieldId": "type", + "height": 26, + "id": "incident-type-field", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "severity", + "height": 26, + "id": "incident-severity-field", + "index": 1, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "owner", + "height": 26, + "id": "incident-owner-field", + "index": 2, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "sourcebrand", + "height": 26, + "id": "incident-sourceBrand-field", + "index": 4, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "sourceinstance", + "height": 26, + "id": "incident-sourceInstance-field", + "index": 5, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "playbookid", + "height": 26, + "id": "incident-playbookId-field", + "index": 6, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Case Details", + "static": false, + "w": 1, + "x": 0, + "y": 0 + }, + { + "h": 2, + "i": "caseinfoid-61263cc0-98b1-11e9-97d7-ed26ef9e46c8", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Notes", + "static": false, + "type": "notes", + "w": 1, + "x": 2, + "y": 0 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-6aabad20-98b1-11e9-97d7-ed26ef9e46c8", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Work Plan", + "static": false, + "type": "workplan", + "w": 1, + "x": 1, + "y": 0 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-770ec200-98b1-11e9-97d7-ed26ef9e46c8", + "isVisible": true, + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Linked Incidents", + "static": false, + "type": "linkedIncidents", + "w": 1, + "x": 1, + "y": 6 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-842632c0-98b1-11e9-97d7-ed26ef9e46c8", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Child Incidents", + "static": false, + "type": "childInv", + "w": 1, + "x": 2, + "y": 4 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-4a31afa0-98ba-11e9-a519-93a53c759fe0", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Evidence", + "static": false, + "type": "evidence", + "w": 1, + "x": 2, + "y": 2 + }, + { + "displayType": "ROW", + "h": 2, + "hideName": false, + "i": "caseinfoid-7717e580-9bed-11e9-9a3f-8b4b2158e260", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Team Members", + "static": false, + "type": "team", + "w": 1, + "x": 2, + "y": 6 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-7ce69dd0-a07f-11e9-936c-5395a1acf11e", + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Indicators", + "query": "", + "queryType": "input", + "static": false, + "type": "indicators", + "w": 2, + "x": 0, + "y": 4 + }, + { + "displayType": "CARD", + "h": 2, + "i": "caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289", + "items": [ + { + "endCol": 1, + "fieldId": "occurred", + "height": 26, + "id": "incident-occurred-field", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 1, + "fieldId": "dbotmodified", + "height": 26, + "id": "incident-modified-field", + "index": 1, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "dbotduedate", + "height": 26, + "id": "incident-dueDate-field", + "index": 2, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "dbotcreated", + "height": 26, + "id": "incident-created-field", + "index": 0, + "sectionItemType": "field", + "startCol": 1 + }, + { + "endCol": 2, + "fieldId": "dbotclosed", + "height": 26, + "id": "incident-closed-field", + "index": 1, + "sectionItemType": "field", + "startCol": 1 + } + ], + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Timeline Information", + "static": false, + "w": 1, + "x": 0, + "y": 2 + }, + { + "displayType": "ROW", + "h": 2, + "i": "caseinfoid-88e6bf70-a0b1-11e9-b27f-13ae1773d289", + "isVisible": true, + "items": [ + { + "endCol": 2, + "fieldId": "dbotclosed", + "height": 26, + "id": "incident-dbotClosed-field", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "closereason", + "height": 26, + "id": "incident-closeReason-field", + "index": 1, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "closenotes", + "height": 26, + "id": "incident-closeNotes-field", + "index": 2, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Closing Information", + "static": false, + "w": 1, + "x": 0, + "y": 6 + }, + { + "displayType": "CARD", + "h": 2, + "i": "caseinfoid-e54b1770-a0b1-11e9-b27f-13ae1773d289", + "isVisible": true, + "items": [ + { + "endCol": 2, + "fieldId": "details", + "height": 26, + "id": "incident-details-field", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Investigation Data", + "static": false, + "w": 1, + "x": 1, + "y": 2 + } + ], + "type": "custom" + }, + { + "id": "warRoom", + "name": "War Room", + "type": "warRoom" + }, + { + "id": "workPlan", + "name": "Work Plan", + "type": "workPlan" + }, + { + "id": "evidenceBoard", + "name": "Evidence Board", + "type": "evidenceBoard" + }, + { + "id": "canvas", + "name": "Canvas", + "type": "canvas" + }, + { + "hidden": false, + "id": "chtyrfjhpp", + "name": "Doppel Alert Data", + "sections": [ + { + "description": "Details about the alert fetched from the Doppel platform", + "displayType": "ROW", + "h": 5, + "hideName": false, + "i": "chtyrfjhpp-6cccc2bd-1312-44b7-8ab4-2e23aae407a7", + "items": [ + { + "endCol": 2, + "fieldId": "doppelalertid", + "height": 26, + "id": "a6ce5d89-5115-4f48-b430-d33799081c52", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelseverity", + "height": 26, + "id": "2feff9ff-9c80-4aed-8866-abf3892a2fa6", + "index": 1, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelbrand", + "height": 26, + "id": "31921aa2-3b76-4b3a-a6d3-5f1e43968dcb", + "index": 2, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "brand", + "height": 26, + "id": "5f7dc687-7405-4465-a603-fbab6c1e4686", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "entitystate", + "height": 26, + "id": "dbd066f4-285b-4a9a-9467-50671f5a2915", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "queuestate", + "height": 26, + "id": "27e8a019-7828-4406-93b9-dbf951f71a7a", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "product", + "height": 26, + "id": "079c3ec9-f0a9-4673-8aa5-4e4c9e9e79cf", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "platform", + "height": 26, + "id": "d2ad1638-1c98-4e96-a52e-561c72297fa6", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppellink", + "height": 26, + "id": "128d659a-5c63-458c-a96b-0240bbeae842", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelnotes", + "height": 26, + "id": "a144e1c1-b303-4dcb-b56d-d89508e3ccd1", + "index": 4, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelplatform", + "height": 26, + "id": "30e0153f-6343-44eb-b9ca-c4dea0e82161", + "index": 5, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelproduct", + "height": 26, + "id": "edcef656-d794-4f5c-9fed-5b583384d3ea", + "index": 6, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelqueuestate", + "height": 26, + "id": "820d34e6-33ef-4990-9345-865772efc7a1", + "index": 7, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelcreatedat", + "height": 26, + "id": "270e7ec6-6db4-43ce-9f88-6d16e08649f9", + "index": 8, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelsource", + "height": 26, + "id": "bd17abba-3f1f-4159-ab0e-9645d32c3c66", + "index": 9, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppeltags", + "height": 26, + "id": "98baebf3-14e6-445c-ae21-91664a795ade", + "index": 10, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppeluploadedby", + "height": 26, + "id": "baaf1629-2c6e-4f54-9970-16aac380b407", + "index": 11, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxH": null, + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Alert Details", + "static": false, + "w": 1, + "x": 0, + "y": 0 + }, + { + "description": "Details about the entity received from Doppel", + "displayType": "ROW", + "h": 2, + "hideName": false, + "i": "chtyrfjhpp-db82b87b-a67c-4e81-8e33-29dae245ea1b", + "items": [ + { + "endCol": 2, + "fieldId": "entitycontentrootdomainregistrar", + "height": 26, + "id": "f9107076-5e95-4c45-83ef-9c014570de24", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelentity", + "height": 26, + "id": "1bfc1bbf-f0cd-4b97-af72-0c2dc7db87e6", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 3, + "fieldId": "doppelentitycontent", + "height": 26, + "id": "4c377f5a-6dcf-4122-8112-4fb557f4642b", + "index": 1, + "sectionItemType": "field", + "startCol": 0 + }, + { + "endCol": 2, + "fieldId": "doppelentitystate", + "height": 26, + "id": "f36bf862-77df-4d6d-be09-9079492ef44c", + "index": 3, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxH": null, + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Entity Content", + "static": false, + "w": 2, + "x": 1, + "y": 0 + }, + { + "description": "Shows the Audit log history for the particular Alert", + "displayType": "ROW", + "h": 3, + "hideName": false, + "i": "chtyrfjhpp-07b54ffa-28e8-4216-b4d2-1d0590a0affe", + "items": [ + { + "endCol": 4, + "fieldId": "doppelauditlogs", + "height": 26, + "id": "e211b223-1b57-4d29-b3cb-1bd7b7fd6475", + "index": 0, + "sectionItemType": "field", + "startCol": 0 + } + ], + "maxH": null, + "maxW": 3, + "minH": 1, + "moved": false, + "name": "Audit Log History", + "static": false, + "w": 2, + "x": 1, + "y": 2 + } + ], + "type": "custom" + } + ] + }, + "edit": null, + "fromServerVersion": "", + "group": "incident", + "id": "acdb3cde-b78d-4fa0-86e3-ef0a01606a26", + "indicatorsDetails": null, + "indicatorsQuickView": null, + "itemVersion": "", + "locked": false, + "mobile": null, + "name": "Doppel Alert Layout", + "packID": "c3beb3d4-5d11-46e9-85ec-87a0586dd624", + "packName": "Fields", + "propagationLabels": [ + "all" + ], + "quickView": null, + "quickViewV2": null, + "system": false, + "toServerVersion": "", + "version": -1 +} \ No newline at end of file