Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add for the first time the extension #6

Open
wants to merge 2,461 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
2461 commits
Select commit Hold shift + click to select a range
5c7650a
A successful login from tor (#36687)
ArikDay Oct 15, 2024
80b6016
External Login Password Spray - README update (#36660)
idovandijk Oct 15, 2024
6802e5f
[Marketplace Contribution] Mimecast - Content Pack Update (#36672)
content-bot Oct 15, 2024
1f1b0c3
New command in the Azure Storage Contaitner pack for blocking public …
content-bot Oct 15, 2024
8d7919e
Update python version in setup-python (#36738)
adi88d Oct 15, 2024
cea0659
edit description in pack_metadata.json file (#36739)
rshunim Oct 15, 2024
003f76e
MISP Feed - Added the ability to fetch Host as indicator (#36727)
adi88d Oct 15, 2024
7211d85
Modified parsing rule to support future dates scenarios - Symantec EP…
yasta5 Oct 15, 2024
3cf061d
Suspicious LDAP Search Query (#36707)
ssokolovich Oct 15, 2024
d18e650
Added check-added-large-files hook (#36057)
MosheEichler Oct 15, 2024
d9af679
change on_call (#36742)
sapirshuker Oct 20, 2024
247f0d5
Run Legacy Validate on Contributions workflow - update python version…
adi88d Oct 20, 2024
ffa930c
Update docker image to demisto/flask-nginx:1.0.0.113398 in EDL (#36723)
mayyagoldman Oct 20, 2024
76adb56
Modified parsing rule - Workday (#36766)
yasta5 Oct 21, 2024
1ac9b69
Add some changes to integrations script and release notes
TOUFIKIzakarya Oct 21, 2024
b81a114
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Oct 21, 2024
72984c2
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Oct 21, 2024
781c844
Zafran v1 (#36771)
content-bot Oct 21, 2024
bc1c045
commit (#36747)
omerKarkKatz Oct 21, 2024
6505bed
HTTPFeedApiModule - fix etag header issue (#36773)
adi88d Oct 21, 2024
410dc5a
[Microsoft Graph Mail] Enhance msgraph-mail-get-attachment command (#…
samuelFain Oct 21, 2024
f01d0b8
Ciac 10972 zoom add user sso token revoke (#36725)
ilaredo Oct 21, 2024
78ddf06
Box collector fix Url serialize error (#36774)
itssapir Oct 21, 2024
de1b9ab
Ciac 11383 (#35865)
mayyagoldman Oct 21, 2024
c774b22
Crowdstrike Falcon reset the offset when reaching the limit (#36740)
MosheEichler Oct 21, 2024
bb62acb
Updated docker image staging 18 (#36780)
mayyagoldman Oct 22, 2024
3b26e1a
Change prefix to ext (#36761)
ShirleyDenkberg Oct 22, 2024
4dd8d85
Ciac 11979 - Fixing the 'AutoBlockIndicators' playbook input (#36796)
melamedbn Oct 22, 2024
6de4946
CIAC-11795/XSIAM_PB_Netcat_Makes_or_Get_Connections (#36721)
efelmandar Oct 22, 2024
78881b4
Added to_string for requestTime - Workday (#36802)
yasta5 Oct 22, 2024
17ea97d
fixed autofocus non ascii parsing for url command (#36803)
omerKarkKatz Oct 23, 2024
16543ac
Revert "change on_call (#36742)" (#36811)
sapirshuker Oct 27, 2024
b996b84
update codeowner (#36670)
ilaredo Oct 27, 2024
2b5e86a
Added large files hook enforce all to include committed files (#36750)
MosheEichler Oct 27, 2024
4a3aaa6
Remove holiday message (#36813)
edik24 Oct 27, 2024
f129638
Added check-case-conflict pre commit hook (#36751)
MosheEichler Oct 27, 2024
79f3f2b
try (#36819)
RosenbergYehuda Oct 27, 2024
91bd457
Aud demisto/auto update docker staging branch 20 (#36797)
mayyagoldman Oct 27, 2024
a261fb3
[Azure Log Analytics] fix azure-log-analytics-generate-login-url (#36…
michal-dagan Oct 27, 2024
11151ed
CVE-2024-47575 Rapid Pack (#36847)
melamedbn Oct 27, 2024
4ab6ba0
Security And Compliance - Content Search V2 - update permissions (#36…
michal-dagan Oct 28, 2024
84ebe35
Update playbook-Malware_Investigation_and_Response_Incident_Handler.y…
content-bot Oct 28, 2024
73bfd3f
urlscan country option (#36699) (#36851)
content-bot Oct 28, 2024
788d60b
[Tanium v2] Fixed an issue in tn-get-question-metadata command (#36846)
mmhw Oct 28, 2024
9f87695
skip on nightly check large files (#36850)
MosheEichler Oct 28, 2024
63258a1
[AWS - Lambda] Fixed an issue in aws-lambda-invoke command (#36857)
mmhw Oct 28, 2024
b24e5da
Change marketplace field in CISOMetrics dashbord (#36861)
israelpoli Oct 28, 2024
ad1871e
[PrismaCloudV2] Update The `HeuristicSearch` Parameter (#36854)
shmuel44 Oct 28, 2024
55b8e86
Sophos change readme (#36863)
edik24 Oct 28, 2024
500d69b
Elasticsearch Feed - Generic Feed Type - Fixes (#36745)
ShacharKidor Oct 28, 2024
b71d71d
RemoteAccess v2: fix issue in case of missing permission. (#36855)
ilappe Oct 28, 2024
27e93f4
Bump image tags to latest in requested packs XSUP-42363 (#36826)
mayyagoldman Oct 29, 2024
e736a12
Endpoint investigation plan fix (#36879)
OmriItzhak Oct 29, 2024
aa8993c
BMC-itsm Fixed task update for assigned support company (#36869)
MosheEichler Oct 29, 2024
539cd3e
fix in Core.RiskyUser (#36881)
karinafishman Oct 29, 2024
c22d233
wallixbastion 3.0.0: add new commands, return id from created objects…
content-bot Oct 29, 2024
0041340
Some changes to test mirroring & aplly pre-commit
TOUFIKIzakarya Oct 29, 2024
27a40b0
Zero Networks Segment - casting int fields to string (#36852)
yasta5 Oct 29, 2024
226982b
Cortex XDRIR - add fetch logs (#36790)
rshunim Oct 29, 2024
7029879
RestartFailedTasks: correct the arg name (#36883)
ilappe Oct 29, 2024
a3e5368
Updated docker image staging 21 (#36856)
mayyagoldman Oct 29, 2024
9ab3277
Linux Parsing Rule add support for ISO 8601 compatible like timestamp…
cweltPA Oct 29, 2024
70ba76f
Workday product modification parsing xsup 42845 (#36887)
yasta5 Oct 29, 2024
5cda430
[Zscaler Internet Access] Fixed an issue where the zscaler-logout and…
mmhw Oct 30, 2024
d61f283
Proofpoint collector audit events (#36765)
itssapir Oct 30, 2024
a736792
QRadar - Generic - fixed issue with username enrichment (#36884)
idovandijk Oct 30, 2024
930e80d
Rasterize - fix mailto timeout issue (#36815)
adi88d Oct 30, 2024
531aa52
Wrong result type removed from ds-search command (#36885)
content-bot Oct 30, 2024
9a947c2
Added assets fix and snapshot fix (#36816)
ShahafBenYakir Oct 30, 2024
db6cd09
change businessflow to appviz (#36878)
edik24 Oct 30, 2024
1309959
[EWS V2] Fix unexpected limit argument behavior of ews-search-mailbox…
samuelFain Oct 30, 2024
586cb40
remove-styling (#36886)
tkatzir Oct 30, 2024
9d1db82
format (#36864)
RosenbergYehuda Oct 30, 2024
d13cf5b
Improve XDR Disconnected Endpoints job playbook - take 2 (#36829)
content-bot Oct 30, 2024
d06cf0e
Containment Plan - Block Indicators - fix (#36959)
OmriItzhak Oct 30, 2024
d2bf47a
Add support for Key ID parameter in OktaV2 (#36760)
amshamah419 Oct 30, 2024
73734e2
poetry files (#36960)
content-bot Oct 31, 2024
d67b9a9
Fix the detection query to sort in ascending order (#37001)
RosenbergYehuda Oct 31, 2024
58357b9
Update content_roles.json (#37002)
jbabazadeh Oct 31, 2024
0fa5a2f
T1552 unsecured credentials unprivileged process opened a registr…
TalNos Oct 31, 2024
b3c6c7a
[FailedInstances] Fixed an issue related to instances in an error sta…
mmhw Oct 31, 2024
393188c
added new task to remove hash from block list (#37003)
OmriItzhak Oct 31, 2024
3cca8eb
fix (#37007)
RosenbergYehuda Oct 31, 2024
7c49790
Azure Sentinel severity key error bug (#36775)
rshunim Oct 31, 2024
030d1ab
JAMF Protect: Log errorneous responses (#37013)
dorschw Oct 31, 2024
ea7b011
Revert removal of polling true (#37000)
thefrieddan1 Oct 31, 2024
dbf306e
CIAC-8968 - Enhancement Hashicorp Vault integration (#34795)
inbalapt1 Nov 3, 2024
2e35d96
update varonis logo (#36893) (#37017)
content-bot Nov 3, 2024
0018a11
Migrate slack-send-file command in SlackV3 Integration to new APIs (#…
kamalq97 Nov 3, 2024
d4a4ef9
[Marketplace Contribution] ServiceNow - Content Pack Update (#36873)
content-bot Nov 3, 2024
4385af9
Xsup 42432 snow auth issue (#37025)
yucohen Nov 3, 2024
5b408d8
Identical YML configs update (#36686)
eepstain Nov 4, 2024
901feff
urlscan - file metadata issue fix (#37018)
content-bot Nov 4, 2024
2e63ca0
CiscoUmbrellaReporting: Added optional "categories" argument to suppo…
content-bot Nov 4, 2024
3ce4508
XSUP-42968 Linux Parsing Rule Extension for Additional Timestamp Form…
cweltPA Nov 4, 2024
8e4c347
Oktav2 revoke sessions (#37028)
content-bot Nov 4, 2024
476cfa5
Feature/search warninglists (#36668) (#37055)
content-bot Nov 4, 2024
84e81e1
Wrap all security tool exceptions operations (#37054)
content-bot Nov 4, 2024
651e554
Axonius Pack - Add proxy support (#37016) (#37053)
content-bot Nov 4, 2024
3fb177f
Update README.md (#37035)
ShirleyDenkberg Nov 4, 2024
a6a72b8
Ciac 12033 - Hide includeinformational argument in SearchAlertsV2 scr…
mayyagoldman Nov 5, 2024
521f06e
try (#37045)
RosenbergYehuda Nov 5, 2024
7a42670
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 5, 2024
334e3b8
Integration: Fix mirroring problem
TOUFIKIzakarya Nov 5, 2024
46ac31f
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 5, 2024
04a9c06
Scripts: Fix mirroring problem
TOUFIKIzakarya Nov 5, 2024
5a50017
Mappers : Add mirrour out field
TOUFIKIzakarya Nov 5, 2024
c1775db
Fields: add mirror out field
TOUFIKIzakarya Nov 5, 2024
331d20e
Update DomainTools_Iris.py (#36794) (#37056)
content-bot Nov 5, 2024
61ae48f
Fixed alerts message reading error (#37036)
content-bot Nov 5, 2024
d81c9b0
V 1.1.0 (#37026)
content-bot Nov 5, 2024
e8720df
Updated docker image to demisto/yolo-coco:1.0.0.115114. PR batch #1/1…
inbalapt1 Nov 5, 2024
c010561
Updated docker image to demisto/ansible-runner:1.0.0.115040. PR batch…
inbalapt1 Nov 5, 2024
d8a9e97
XDR iocs integration- 'XSOAR Comment Field Exporting To XDR' paramete…
rshunim Nov 5, 2024
5914792
Prisma Cloud Compute custom feeds ip remove (CIAC-11607) (#37032)
itssapir Nov 5, 2024
3ccdfb2
Apply format to all the folder
TOUFIKIzakarya Nov 5, 2024
5fc79ee
Scripts: Fix some tests
TOUFIKIzakarya Nov 5, 2024
1b5446b
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 5, 2024
5e262b2
Merge branch 'Add/SekoiaXDR' of github.com:SEKOIA-IO/Cortex-XSOAR-int…
TOUFIKIzakarya Nov 5, 2024
23cd730
Adding support for for HC pack for x8 (#37063)
content-bot Nov 5, 2024
2d81b7e
Scripts: Fix tests
TOUFIKIzakarya Nov 5, 2024
85e15ea
Delete some extra fields
TOUFIKIzakarya Nov 5, 2024
086cdf9
Add field missing
TOUFIKIzakarya Nov 5, 2024
8cd5aa8
Update README.md (#37067)
ShirleyDenkberg Nov 5, 2024
9322694
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 5, 2024
a6e9793
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 5, 2024
396eba6
Scripts: Add some tests to sekoia change status
TOUFIKIzakarya Nov 5, 2024
2b77871
Add no cov to script
TOUFIKIzakarya Nov 5, 2024
1e099a9
Scripts: Add some more tests to close script
TOUFIKIzakarya Nov 5, 2024
8baf367
Apply black to close alert folder
TOUFIKIzakarya Nov 5, 2024
a0ce86f
Add no cover to close alert func
TOUFIKIzakarya Nov 5, 2024
f28ffe7
Add some more no cov
TOUFIKIzakarya Nov 5, 2024
bd33b63
Updated docker image to demisto/auth-utils:1.0.0.114762. PR batch #1/…
inbalapt1 Nov 6, 2024
1646ff4
Ews online bug (#37011)
merit-maita Nov 6, 2024
c158257
update armis docker image (#37072)
mayyagoldman Nov 6, 2024
6b76b50
Prisma Cloud DSPM (#37077)
content-bot Nov 6, 2024
b88ddf5
AUD-demisto/auto update docker staging branch 29 (#37075)
inbalapt1 Nov 6, 2024
f7d3289
DBotPredictURLPhishing - remove mailto urls (#37080)
adi88d Nov 6, 2024
822e0f7
Knowbe4 bug (#37049)
merit-maita Nov 6, 2024
26a37ce
Unprivileged process opened a registry hive fix (#37030)
OmriItzhak Nov 6, 2024
78d6de1
AUD-demisto/auto_update_docker_staging_branch_28 (#37073)
inbalapt1 Nov 6, 2024
cf6fdf3
Aud demisto/auto update docker staging branch 23 (#37006)
inbalapt1 Nov 6, 2024
323a7aa
Aud demisto/auto update docker staging branch 30 (#37081)
inbalapt1 Nov 6, 2024
f9cab1b
Updated the SafeBreach deprecated delete plan API (#37062) (#37086)
content-bot Nov 6, 2024
cce807f
CrowdStrikeFalcon: ioc count in case of rate limit (#36602)
ilappe Nov 6, 2024
48e76f0
Delete changed field
TOUFIKIzakarya Nov 6, 2024
403d775
Add default mapper in
TOUFIKIzakarya Nov 6, 2024
dac5ec1
Refactor the condition
TOUFIKIzakarya Nov 6, 2024
3433a1c
Add the fourth point in readme
TOUFIKIzakarya Nov 6, 2024
feb63d5
VaronisSaaS: Updated a Varonis log image for marketplace. (#37101) (#…
content-bot Nov 6, 2024
3525c59
[MimecastV2] mimecast-query - fixes (#37050)
michal-dagan Nov 7, 2024
01a0f5b
Aud demisto/auto update docker staging branch 33 (#37103)
inbalapt1 Nov 7, 2024
4ed79c9
Aud demisto/auto update docker staging branch 31 (#37089)
inbalapt1 Nov 7, 2024
b25955b
Aud demisto/auto update docker staging branch 32 (#37091)
inbalapt1 Nov 7, 2024
28d3ce3
DBotPredictURLPhishing - check mailto_urls value before return the re…
adi88d Nov 7, 2024
3779352
TIM Email type indicator layout fix - adding the verdict section to q…
Ni-Knight Nov 7, 2024
62ecdda
kafka consumer only (#36378)
YaelShamai Nov 7, 2024
af19be7
ElasticsearchV2 - Added Support for v8.x (#34872)
ShacharKidor Nov 7, 2024
325f56a
CIAC-12086 - Command core-get-cloud-original-alerts fails in debugger…
mayyagoldman Nov 7, 2024
f474d69
[DBotFindSimilarIncidentsByIndicators] Fix issue with field that is n…
mmhw Nov 7, 2024
4f3cb62
Akamai 416 and duplications fix (#36405)
YuvHayun Nov 7, 2024
ccea470
XSUP-42968 Linux Parsing Rule Improve ISO 8601 Coverage (#37119)
cweltPA Nov 7, 2024
c1cbe77
Compromise accounts - user rejected numerous sso mfa attempts (#37064)
tomer-pan Nov 7, 2024
a307272
Incident Layouts | Add default Incident Layout For XSIAM (#37027)
shmuel44 Nov 7, 2024
b698478
Microsoft Intune - Update Microsoft Intune endpoint URL (#36812)
michal-dagan Nov 7, 2024
2d08a7e
[EWS0365/EWSv2] Add parsing exceptions handling in fetch-incidents (#…
samuelFain Nov 7, 2024
1fd9b32
Elasticsearch Feed support Elasticsearch client v8 (#36849)
ShacharKidor Nov 7, 2024
79f3563
Aud demisto/auto update docker staging branch 35 (#37122)
inbalapt1 Nov 10, 2024
2dbcb68
Aud demisto/auto update docker staging branch 38 (#37120)
inbalapt1 Nov 10, 2024
0b84d6a
Partner csc adoption complete (#37131) (#37134)
content-bot Nov 10, 2024
599b444
Aud demisto/auto update docker staging branch 36 (#37115)
inbalapt1 Nov 10, 2024
5e38792
UploadFile script fix deprecation message (#37129)
MosheEichler Nov 10, 2024
8192c8d
update parse-email to 0.1.30 (#37135)
moishce Nov 10, 2024
2948943
rasterize - fix timeout issue (#36859)
adi88d Nov 10, 2024
399974c
Incapsula - pass arguments in url params (#37126)
adi88d Nov 10, 2024
5c6f726
Veeam Check for XSIAM v2.5 (#36637)
eepstain Nov 10, 2024
e3b006c
Aud demisto/auto update docker staging branch 39 (#37118)
inbalapt1 Nov 10, 2024
10b0a62
Aud demisto/auto update docker staging branch 26 (#37059)
inbalapt1 Nov 10, 2024
d4baf05
Scheduled task created with http or ftp reference enhancement (#37083)
OmriItzhak Nov 10, 2024
6e259fb
Uncommon remote scheduled task created (#37029)
OmriItzhak Nov 10, 2024
a5d9b94
TIM - Malware indicator type layout mismatch (#36453)
Ni-Knight Nov 10, 2024
e51f8b3
T1564.002 - Hide Artifacts: Hidden Users] - Suspicious hidden user cr…
idovandijk Nov 10, 2024
3aefa62
added new command support in EclecticIQ pack (#37084) (#37157)
content-bot Nov 10, 2024
4eb27fb
Aud demisto/auto update docker staging branch 41 (#37146)
inbalapt1 Nov 11, 2024
5085b5f
Update README.md (#37127)
julieschwartz18 Nov 11, 2024
773b94a
poetry files (#37159)
content-bot Nov 11, 2024
c46ab89
Update README.md (#37121)
julieschwartz18 Nov 11, 2024
110bc89
[Xsup 43700] LinkToPhishingCampaign -Fixed the incident links (#37155)
bziser Nov 11, 2024
7dc9b6a
update docker image (#37153)
inbalapt1 Nov 11, 2024
bcd8087
Aud demisto/auto update docker staging branch 37 (#37124)
inbalapt1 Nov 11, 2024
b45bfff
Revert "Veeam Check for XSIAM v2.5" (#37165)
YuvHayun Nov 11, 2024
8bed9ea
update python3 docker image (#37164)
inbalapt1 Nov 11, 2024
82ff125
potential fix (#37044)
ilappe Nov 11, 2024
2895605
Aud demisto/auto update docker staging branch 42 (#37162)
inbalapt1 Nov 11, 2024
03654fe
[Xsup 43700] TAXII server adding default port (#37144)
bziser Nov 11, 2024
e30e9d0
fix (#37173)
RosenbergYehuda Nov 11, 2024
2a1a219
changed bearer to Bearer (#37158)
yucohen Nov 12, 2024
78d17e5
10611 change path to relative md files scripts (#35282)
maimorag Nov 12, 2024
734baad
A mail forwarding google workspace (#36795)
ArikDay Nov 12, 2024
c6e2a0c
10611 change path to relative md r s t z e (#36470)
maimorag Nov 12, 2024
3a6f3fd
[ASM] EXPANDR-10510 Updated ServiceNow playbook (#36897) (#37184)
content-bot Nov 12, 2024
e3e2c19
mcafee dxl phishlabs (#36471)
maimorag Nov 12, 2024
77f7b43
Displaymappedfield script pipe parse fix (#37176)
altmannyarden Nov 12, 2024
1546222
Update docker_native_image_config.json (#37178)
jlevypaloalto Nov 12, 2024
6407ec4
added rn (#37190)
YuvHayun Nov 12, 2024
06eac13
CRTX-139456 Parsing Rule Fixes for Cisco Catalyst and Azure Security …
cweltPA Nov 12, 2024
a94e828
RSS Feed - add user-agent header (#37160)
adi88d Nov 12, 2024
31b99b0
Google Workspace - Parsing Rule Update (#37171)
eepstain Nov 13, 2024
1200a67
script update in M integrations (#37195)
maimorag Nov 13, 2024
52c8353
SplunkPy: fix the Server URL param (#37065)
ilappe Nov 13, 2024
170e8bc
script update in N O Q integrations (#37197)
maimorag Nov 13, 2024
87eca97
Delete default mapperIn
TOUFIKIzakarya Nov 13, 2024
7424aed
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 13, 2024
c4538ab
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 13, 2024
53b1b14
[FindDuplicateEmailIncidents] fix performance issues (#37180)
jlevypaloalto Nov 13, 2024
e087b8e
Update integration readme
TOUFIKIzakarya Nov 13, 2024
1f37ab6
[TAXII2Server] Fix longRunningPort (#37186)
bziser Nov 13, 2024
bf4a642
XDR IR fix when close_xdr_incident is False (#37172)
noydavidi Nov 13, 2024
3ca893a
Add a 5 sec delta between the min and max time. (#37175)
omerKarkKatz Nov 13, 2024
bd1e1b4
Bug fix/CIAC-12171/update discovery url in TAXII feed (#37200)
MosheEichler Nov 13, 2024
cd5de02
MS Entra Enhancement (#36915)
eepstain Nov 13, 2024
7c9db01
change to image (#37206)
BEAdi Nov 13, 2024
9cf2386
fix image (#37211)
sapirshuker Nov 13, 2024
1290e50
Update TAXII Service integration README.md (#37166)
julieschwartz18 Nov 14, 2024
16cc027
Update the TAXII2 Server Integration README.md (#37169)
julieschwartz18 Nov 14, 2024
dd0a1b8
Update Web File Repository Integration README.md (#37170)
julieschwartz18 Nov 14, 2024
2802f4e
Aud demisto/auto update docker staging branch 40 (#37147)
inbalapt1 Nov 14, 2024
6cc5850
Aud demisto/auto update docker staging branch 43 (#37191)
inbalapt1 Nov 14, 2024
307086a
Fixed an issue with mapping Attack Pattern relationships in the mati-…
content-bot Nov 14, 2024
a5aa072
Add Sub Resolution Option When Closing An Insight (#37133) (#37196)
content-bot Nov 14, 2024
26b4970
Update content_roles.json (#37215)
jbabazadeh Nov 14, 2024
06185a7
Microsoft Windows Events modeling enhancement (#37187)
yasta5 Nov 14, 2024
75b6c8a
Finish CyberArk PAS Pack Adoption (#37204)
kgal-pan Nov 14, 2024
490678a
Update TAXII2 Integration README.md (#37220)
julieschwartz18 Nov 14, 2024
ca114ad
Symantec Endpoint Security (New pack) (#36694)
israelpoli Nov 14, 2024
fdcbe03
Akamai - fix docker timeout due to integration context not json seria…
YuvHayun Nov 14, 2024
ad57c64
[Marketplace Contribution] Akamai WAF - Content Pack Update (#37234)
content-bot Nov 14, 2024
6c407eb
XSIAM Analytics Playbooks Effort - Unsigned and unpopular process per…
melamedbn Nov 15, 2024
5bab287
Add logs XDR-IR (#37233)
dorschw Nov 16, 2024
d692ea3
replace-on-call (#37231)
sapirshuker Nov 17, 2024
04ddf2a
Add support for execution metrics to GenericSQL integration. (#37014)…
content-bot Nov 17, 2024
bf04121
Enrichment for Verdict test (#37224)
RosenbergYehuda Nov 17, 2024
be5d302
CiscoWebex event collector fixed OAuth test command (#37232)
MosheEichler Nov 17, 2024
5602b45
Ibm maas360 security collector (#37031)
itssapir Nov 17, 2024
012c901
Generic SQL yml description (#36814)
rshunim Nov 17, 2024
95f9bfc
Ys_splunk_enhance (#37078)
YaelShamai Nov 17, 2024
6411782
Generic SQL Trino support (#37185)
itssapir Nov 17, 2024
59ec574
Change field name
TOUFIKIzakarya Nov 18, 2024
8c2bdd0
Merge branch 'contrib/SEKOIA-IO_Add/SekoiaXDR' into Add/SekoiaXDR
TOUFIKIzakarya Nov 18, 2024
c90f96b
delete useless (')
TOUFIKIzakarya Nov 18, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
446 changes: 0 additions & 446 deletions .circleci/config.yml

This file was deleted.

3 changes: 0 additions & 3 deletions .circleci/content_release_vars.sh

This file was deleted.

21 changes: 0 additions & 21 deletions .circleci/gitlab-ci-env-variables.sh

This file was deleted.

13 changes: 8 additions & 5 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,12 +1,14 @@
FROM python:3.10-slim-bullseye
FROM python:3.10-slim-bookworm

ENV USERNAME demisto
ENV HOME /home/$USERNAME
ENV NODE_EXTRA_CA_CERTS /usr/local/share/ca-certificates/certs.crt
ENV PATH $PATH:$HOME/.local/bin:/root/.local/bin:/usr/local/share/nvm/current/bin
ENV FEATURES_COMMIT_HASH fc62e9abf47c5ea52e02de997c91c5d52a5edc3a


ADD createCerts.sh .
RUN apt-get update && apt-get install dos2unix git python2 curl -y \
RUN apt-get update && apt-get install dos2unix git curl -y \
&& dos2unix /createCerts.sh \
&& chmod +x /createCerts.sh \
&& /createCerts.sh $NODE_EXTRA_CA_CERTS \
Expand All @@ -15,13 +17,14 @@ RUN apt-get update && apt-get install dos2unix git python2 curl -y \
&& git clone https://github.com/devcontainers/features.git /features \
&& cd /features \
# locking to the latest master commit in this repo (https://github.com/devcontainers/features.git) to prevent breaking changes
# We should update this commit hash from time to time to
&& git checkout 96bff0097028001e6e4126c5528d37cb8c13e785
# We should update this commit hash from time to time to time
&& git checkout $FEATURES_COMMIT_HASH

# This is a workaround for VSCode devcontainer features in self signed certificate
RUN UID="1000" GID="1000" bash /features/src/common-utils/install.sh
RUN VERSION="os-provided" bash /features/src/git/install.sh
RUN VERSION="latest" bash /features/src/docker-in-docker/install.sh
# Install a specific version of moby-buildx when using Moby. (2024-02-09: Microsoft's Package Manifest has mismatching filesize and SHA for 0.12.1; 0.12.0 is the last known good version)
RUN VERSION="lts" MOBYBUILDXVERSION="0.12.0" bash /features/src/docker-in-docker/install.sh
RUN VERSION="lts" bash /features/src/node/install.sh
RUN bash /features/src/sshd/install.sh
RUN bash /features/src/github-cli/install.sh
Expand Down
94 changes: 26 additions & 68 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,55 +1,32 @@
# Marketplace Related - Marketplace PMs only
/Tests/Marketplace/approved_tags.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/approved_usecases.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Config/approved_tags.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Config/approved_usecases.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/landingPage_sections.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/approved_categories.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/core_packs_list.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/core_packs_mpv2_list.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Tests/Marketplace/versions-metadata.json @yaakovpraisler
/Tests/Marketplace/corepacks_override.json @yaakovpraisler
/Config/approved_categories.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Config/core_packs_list.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Config/core_packs_mpv2_list.json @yaakovpraisler @bakatzir @GuyLibermanPA @demisto/content-leaders
/Config/corepacks_override.json @yaakovpraisler

# Docker native image
/Tests/docker_native_image_config.json @GuyAfik @JudahSchwartz @samuelFain

# Marketplace & Upload-Flow
/Tests/scripts/create_artifacts_graph/create_artifacts.py @ilaner
/Tests/Marketplace/upload_git_snapshot.py @yaakovpraisler
/Tests/Marketplace/install_packs.sh @yaakovpraisler
/Tests/Marketplace/configure_and_install_packs.py @yaakovpraisler
/Tests/Marketplace/copy_and_upload_packs.py @yaakovpraisler
/Tests/Marketplace/marketplace_services.py @yaakovpraisler @ilaner
/Tests/Marketplace/marketplace_statistics.py @yaakovpraisler
/Tests/Marketplace/marketplace_constants.py @yaakovpraisler
/Tests/Marketplace/zip_packs.py @yaakovpraisler
/Tests/Marketplace/upload_packs.py @yaakovpraisler @ilaner
/Tests/Marketplace/packs_dependencies.py @yaakovpraisler
/Tests/Marketplace/search_and_install_packs.py @yaakovpraisler
/Tests/scripts/prepare_content_packs_for_testing.sh @yaakovpraisler
/Utils/trigger_test_upload_flow.sh @yaakovpraisler
/Utils/trigger_upload_packs_to_production.sh @yaakovpraisler
/Utils/should_trigger_test_upload.sh @yaakovpraisler
/Utils/test_upload_flow/* @yaakovpraisler
/Tests/docker_native_image_config.json @JudahSchwartz @shmuel44

# Test Collection
/Tests/scripts/collect_tests @dorschw
/Tests/scripts/collect_tests/id_set.py @ilaner
/Tests/conf.json @sapirshuker

# PANW Products
/Packs/Palo_Alto_Networks_Enterprise_DLP/ @DeanArbel
/Packs/PAN-OS/Integrations/ @jlevypaloalto
/Packs/PrismaCloudCompute/Integrations/ @GuyAfik
/Packs/PrismaSaasSecurity/Integrations/ @GuyAfik

# Important Integrations
/Packs/QRadar/Integrations/QRadar_v3/* @ilaner
/Packs/QRadar/Integrations/QRadar_v3/* @jbabazadeh
/Packs/Slack/Integrations/* @amshamah419 @rshunim
/Packs/SplunkPy/Integrations/SplunkPy/* @ilappe
/Packs/MicrosoftExchangeOnPremise/Integrations @amshamah419
/Packs/MicrosoftExchangeOnline/Integrations @amshamah419 @thefrieddan1
/Packs/ContentManagement/* @adi88d
/Packs/TAXIIServer/Integrations/TAXII2Server/* @Ni-Knight
/Packs/FeedTAXII/Integrations/FeedTAXII2/* @Ni-Knight
/Packs/rasterize/Integrations/rasterize/* @ilaredo

# Important Scripts
/Packs/CommonScripts/Scripts/SetGridField/* @altmannyarden
Expand All @@ -60,9 +37,9 @@
/Packs/CommonScripts/Scripts/StixCreator/* @Ni-Knight

# Common Packs
/Packs/CommonTypes/ @michalgold @idovandijk
/Packs/CommonPlaybooks/ @michalgold @idovandijk
/Packs/CommonDashboards/ @michalgold @idovandijk
/Packs/CommonTypes/ @altmannyarden @idovandijk
/Packs/CommonPlaybooks/ @altmannyarden @idovandijk
/Packs/CommonDashboards/ @altmannyarden @idovandijk
/Packs/ContentManagement/ @mmhw
/Packs/CommonTypes/IndicatorTypes/* @Ni-Knight
/Packs/CommonTypes/Layouts/* @Ni-Knight
Expand All @@ -76,44 +53,20 @@
/Packs/CommonScripts/Scripts/ExtractEmailV2/* @Ni-Knight
/Packs/CommonScripts/Scripts/UnEscapeIPs/* @Ni-Knight


# Build related
.circleci/config.yml @yucohen
.gitlab/ci/* @yucohen
.gitlab/* @yucohen
.gitlab-ci.yml @yucohen
/Tests/scripts/wait_in_line_for_cloud_env.sh @daryakoval
.gitlab/ci/.gitlab-ci.staging.yml @ilaner
/Tests/scripts/uninstall_packs_and_reset_bucket_cloud.sh @daryakoval
/Tests/Marketplace/search_and_uninstall_pack.py @daryakoval
/Tests/scripts/install_content_and_test_integrations.sh @daryakoval
/Tests/configure_and_test_integration_instances.py @daryakoval
/Tests/scripts/print_cloud_machine_details.sh @daryakoval
/Tests/scripts/run_tests.sh @daryakoval
/Tests/scripts/download_demisto_conf.sh @daryakoval
Tests/scripts/test_modeling_rules.sh @daryakoval
Tests/scripts/lock_cloud_machines.py @daryakoval
Tests/Marketplace/server_content_items.json @dantavori

# SDK Related
.gitlab/ci/.gitlab-ci.sdk-nightly.yml @dorschw
Utils/trigger_nightly_sdk_build.sh @dorschw
.pre-commit-config_template.yaml @dorschw @ilaner
.pre-commit-config_template.yaml @SamuelFain @YuvHayun
validation_config.toml @YuvHayun

# XDR Related
/Packs/CortexXDR/Integrations/ @dansterenson
/Packs/Core/Integrations/ @dansterenson
/Packs/ApiModules/Scripts/CoreIRApiModule/* @dansterenson
/Packs/CortexXDR/Integrations/ @maimorag
/Packs/Core/Integrations/ @maimorag
/Packs/ApiModules/Scripts/CoreIRApiModule/* @maimorag

# Dependencies
pyproject.toml @ilaner @dorschw
poetry.lock @ilaner @dorschw

# Devcontainers
.devcontainer/* @ilaner
poetry.lock @dorschw

# Demisto Class
Packs/ApiModules/Scripts/DemistoClassApiModule/DemistoClassApiModule.py @daryakoval
Packs/ApiModules/Scripts/DemistoClassApiModule/DemistoClassApiModule.py @dantavori

# TIM Related
/Packs/TAXIIServer/Integrations/* @MLainer1
Expand All @@ -126,9 +79,14 @@ Packs/ApiModules/Scripts/DemistoClassApiModule/DemistoClassApiModule.py @daryako

# ML scripts
/Packs/ML/ @jlevypaloalto
/Packs/PhishingURL/Scripts/DBotPredictURLPhishing/ @jlevypaloalto
/Packs/PhishingURL/ @jlevypaloalto
/Packs/Phishing/Scripts/PhishingDedupPreprocessingRule @jlevypaloalto
/Packs/Phishing/Scripts/FindDuplicateEmailIncidents @jlevypaloalto
/Packs/Base/Scripts/DrawRelatedIncidentsCanvas@jlevypaloalto
/Packs/Campaign/Scripts/FindEmailCampaign/ @jlevypaloalto
/Packs/CortexXDR/Scripts/DBotGroupXDRIncidents/ @jlevypaloalto
/Packs/CommonScripts/Scripts/DBotUpdateLogoURLPhishing/ @jlevypaloalto
/Packs/Base/Scripts/FindSimilarIncidentsByText/ @jlevypaloalto
/Packs/Base/Scripts/DBotTrainTextClassifierV2/ @jlevypaloalto
/Packs/Base/Scripts/DBotShowClusteringModelInfo/ @jlevypaloalto
/Packs/Base/Scripts/DBotPredictPhishingWords/ @jlevypaloalto
Expand All @@ -139,4 +97,4 @@ Packs/ApiModules/Scripts/DemistoClassApiModule/DemistoClassApiModule.py @daryako
/Packs/Base/Scripts/DBotFindSimilarIncidentsByIndicators/ @jlevypaloalto
/Packs/Base/Scripts/DBotSuggestClassifierMapping/ @jlevypaloalto
/Packs/Base/Scripts/GetMLModelEvaluation/ @jlevypaloalto
/Packs/Base/Scripts/DBotMLFetchData/ @jlevypaloalto
/Packs/Base/Scripts/DBotMLFetchData/ @jlevypaloalto
20 changes: 13 additions & 7 deletions .github/content_roles.json
Original file line number Diff line number Diff line change
@@ -1,14 +1,20 @@
{
"__comment__": {
"CONTRIBUTION_REVIEWERS": "A list of GitHub username for the contribution team reviewers pool",
"ON_CALL_DEVS": "A list of on-call users, Use PANW account username",
"DOC_REVIEWER": "The GitHub username for documentation reviews owner",
"TIM_REVIEWER": "The GitHub username for TIM reviews owner"
},
"CONTRIBUTION_REVIEWERS": [
"YuvHayun",
"yucohen",
"shmuel44"
"MLainer1",
"YairGlik",
"amshamah419"
],
"CONTRIBUTION_TL": "AradCarmi",
"CONTRIBUTION_SECURITY_REVIEWER": "melamedbn",
"CONTRIBUTION_TL": "samuelFain",
"CONTRIBUTION_SECURITY_REVIEWER": ["idovandijk"],
"ON_CALL_DEVS": [
"dfried",
"meichler"
"sshuker",
"sberman"
],
"DOC_REVIEWER": "ShirleyDenkberg",
"TIM_REVIEWER": "MLainer1"
Expand Down
9 changes: 0 additions & 9 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,12 +26,3 @@ updates:
- "python"
- "dependencies"
- "docs-approved"

- package-ecosystem: "pip"
directory: ".circleci"
schedule:
interval: "daily"
labels:
- "python"
- "dependencies"
- "docs-approved"
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
from github.PullRequest import PullRequest
from github.Repository import Repository
import sys
from Utils.github_workflow_scripts.autobump_release_notes.skip_conditions import MetadataCondition, \
from skip_conditions import MetadataCondition, \
LastModifiedCondition, LabelCondition, AddedRNFilesCondition, HasConflictOnAllowedFilesCondition, \
PackSupportCondition, MajorChangeCondition, MaxVersionCondition, OnlyVersionChangedCondition, \
OnlyOneRNPerPackCondition, SameRNMetadataVersionCondition, AllowedBumpCondition, UpdateType
from Utils.github_workflow_scripts.utils import timestamped_print, Checkout
from utils import timestamped_print, Checkout
from git import Repo
from demisto_sdk.commands.update_release_notes.update_rn import UpdateRN
import os
Expand Down Expand Up @@ -192,6 +192,10 @@ def manage(self):
for pr in self.github_repo_obj.get_pulls(
state="open", sort="created", base=BASE
):
if pr.draft:
# The bot does not go through a PR that is in draft
continue

print(
f"{t.yellow}Looking on pr number [{pr.number}]: last updated: "
f"{str(pr.updated_at)}, branch={pr.head.ref}"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
from github.Repository import Repository
from github.PullRequest import PullRequest
from demisto_sdk.commands.common.tools import get_pack_name
from Utils.github_workflow_scripts.utils import timestamped_print, get_support_level
from utils import timestamped_print, get_support_level

urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
print = timestamped_print
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,12 @@
import sys
from pathlib import Path

CONTENT_ROOT = Path(__file__).parents[1]
CONTENT_ROOT = Path(__file__).parents[2]
assert CONTENT_ROOT.name == "content" or (os.getenv("CIRCLECI") and CONTENT_ROOT.name == "project")

PROTECTED_DIRECTORY_PATHS: set[Path] = {
Path(CONTENT_ROOT, dir_name)
for dir_name in (
".circleci",
".devcontainer",
".github",
".gitlab",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,12 +7,11 @@
from github import Github
from handle_external_pr import EXTERNAL_LABEL

from Utils.github_workflow_scripts.utils import (
from utils import (
get_env_var,
timestamped_print,
load_json,
get_doc_reviewer,
CONTENT_ROLES_PATH
get_content_roles
)
from urllib3.exceptions import InsecureRequestWarning

Expand Down Expand Up @@ -81,7 +80,7 @@ def main():
assignees = [assignee.login for assignee in merged_pr.assignees]

# Un-assign the tech writer (cause the docs reviewed has already been done on the external PR)
content_roles = load_json(CONTENT_ROLES_PATH)
content_roles = get_content_roles()
if content_roles:

try:
Expand All @@ -96,7 +95,7 @@ def main():
print(f"{str(ve)}. Skipped tech writer unassignment.")

else:
print(f"Unable to parse JSON from '{CONTENT_ROLES_PATH}'. Skipping tech writer unassignment.")
print("Unable to get content roles. Skipping tech writer unassignment...")

pr.add_to_assignees(*assignees)
print(f'{t.cyan}Assigned users {assignees}{t.normal}')
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,19 +4,18 @@
from packaging.version import Version
from typing import Optional, List
from unittest.mock import MagicMock
import pytest as pytest
from Utils.github_workflow_scripts.autobump_release_notes.autobump_rn import (
import pytest
from github_workflow_scripts.autobump_release_notes.autobump_rn import (
PackAutoBumper,
BranchAutoBumper, AutoBumperManager,
)
from Utils.github_workflow_scripts.autobump_release_notes.skip_conditions import ConditionResult, MetadataCondition, \
from github_workflow_scripts.autobump_release_notes.skip_conditions import ConditionResult, MetadataCondition, \
LastModifiedCondition, LabelCondition, AddedRNFilesCondition, HasConflictOnAllowedFilesCondition, \
PackSupportCondition, MajorChangeCondition, MaxVersionCondition, OnlyVersionChangedCondition, \
OnlyOneRNPerPackCondition, SameRNMetadataVersionCondition, AllowedBumpCondition, UpdateType
from git import GitCommandError
from demisto_sdk.commands.update_release_notes.update_rn import UpdateRN
import Utils.github_workflow_scripts.autobump_release_notes.skip_conditions as skip_conditions

from github_workflow_scripts.autobump_release_notes import skip_conditions
MERGE_STDOUT = "stdout: '\n Auto-merging {}\n failed.\n Auto-merging {}\n failed.\n"


Expand Down Expand Up @@ -164,7 +163,7 @@ def test_get_metadata_files(mocker):
origin_metadata = {"name": "MyPack", "currentVersion": "1.0.5"}
branch_metadata = {"name": "MyPack", "currentVersion": "1.0.4"}
base_metadata = {"name": "MyPack", "currentVersion": "1.0.3"}
mocker.patch("Utils.github_workflow_scripts.autobump_release_notes.skip_conditions.Checkout")
mocker.patch("github_workflow_scripts.autobump_release_notes.skip_conditions.Checkout")
mocker.patch.object(
skip_conditions,
"load_json",
Expand Down Expand Up @@ -615,7 +614,7 @@ def test_branch_auto_bumper(mocker):
pack_auto_bumper = MagicMock()
pack_auto_bumper.autobump.return_value = "1.0.2"
pack_auto_bumper.pack_id = "MyPack"
mocker.patch("Utils.github_workflow_scripts.autobump_release_notes.autobump_rn.Checkout")
mocker.patch("github_workflow_scripts.autobump_release_notes.autobump_rn.Checkout")
branch_auto_bumper = BranchAutoBumper(
pr=PullRequest(),
git_repo=Repo(),
Expand Down Expand Up @@ -648,7 +647,7 @@ def test_autobump_manager(mocker):
git_repo_obj=Repo(files=CHANGED_FILES),
run_id="1",
)
mocker.patch("Utils.github_workflow_scripts.autobump_release_notes.autobump_rn.Checkout")
mocker.patch("github_workflow_scripts.autobump_release_notes.autobump_rn.Checkout")
mocker.patch.object(BranchAutoBumper, "autobump")
mocker.patch.object(
MetadataCondition,
Expand Down
Loading
Loading