Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update for Pack: Gatewatcher AionIQ #38289

Open
wants to merge 160 commits into
base: contrib/clement-lyonnet_gcenter103-1-3-0
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from 154 commits
Commits
Show all changes
160 commits
Select commit Hold shift + click to select a range
26c152c
Initial commit for Gatewatcher v103
clement-lyonnet Nov 25, 2024
35b3b75
Cleaning for v103
clement-lyonnet Nov 25, 2024
bf085a2
IncidentFields creation
clement-lyonnet Nov 25, 2024
105ceda
New IncidentFields for Layouts
clement-lyonnet Nov 26, 2024
6d79bea
New Layout: Gatewatcher alert and IncidentType
clement-lyonnet Nov 26, 2024
f9e817a
Cleaning
clement-lyonnet Nov 26, 2024
a181709
shellcode and powershell fields,layouts,types
clement-lyonnet Nov 26, 2024
c63c0b7
Updated IncidentTypes
clement-lyonnet Nov 26, 2024
6f127ef
Fix for new IncidentTypes
clement-lyonnet Nov 26, 2024
9447da4
Updated Layouts
clement-lyonnet Nov 27, 2024
c7e85e9
New IncidentType for GCap interface
clement-lyonnet Nov 27, 2024
8fb7553
Updated layouts
clement-lyonnet Nov 27, 2024
b9b2767
Merge layouts into one
clement-lyonnet Nov 27, 2024
f8cc891
Merge IncidentTypes
clement-lyonnet Nov 27, 2024
e41ce9b
Updated IncidentTypes
clement-lyonnet Nov 27, 2024
b4b28b9
New sigflow fields, updated layout
clement-lyonnet Nov 27, 2024
2c7c8a5
Updated api endpoint for test configuration
clement-lyonnet Nov 27, 2024
ec62c9e
Update yml config and images
clement-lyonnet Nov 27, 2024
4f25727
Fix for sigflow field
clement-lyonnet Nov 27, 2024
d3a3c9f
Code cleaning, new Classifier
clement-lyonnet Nov 28, 2024
112a763
Engines fields
clement-lyonnet Nov 28, 2024
312516b
Fixing event severity
clement-lyonnet Dec 2, 2024
0d81a7d
More details on fetch limits
clement-lyonnet Dec 2, 2024
aa5f46e
Handling for big fetches
clement-lyonnet Dec 3, 2024
7dc7f54
Updated Fields, Layouts and Classifier for metas
clement-lyonnet Dec 3, 2024
fba3750
cleaning
clement-lyonnet Dec 4, 2024
ac5e148
fix fetch & updated fields
clement-lyonnet Dec 4, 2024
ce9c78f
cleaning
clement-lyonnet Dec 4, 2024
17f7e67
fix Layout for sdk
clement-lyonnet Dec 4, 2024
1600346
New RN
clement-lyonnet Dec 5, 2024
dac2161
fix for incidentfields
clement-lyonnet Dec 5, 2024
3f24346
fix
clement-lyonnet Dec 5, 2024
8406aa3
attempt to fix IncidentType
clement-lyonnet Dec 6, 2024
363684e
fix Layout
clement-lyonnet Dec 6, 2024
661dd5b
fix Classifier
clement-lyonnet Dec 6, 2024
c6a5213
cleaning unecessary files
clement-lyonnet Dec 6, 2024
0fc25bb
cleaning
clement-lyonnet Dec 6, 2024
6b6bbe8
cleaning
clement-lyonnet Dec 6, 2024
3cd69d1
update pack metadata
clement-lyonnet Dec 6, 2024
a413c8c
New README
clement-lyonnet Dec 6, 2024
9ac170e
fix yml file
clement-lyonnet Dec 6, 2024
7974f10
reformatted incidentfields and fix for snmp community
clement-lyonnet Dec 9, 2024
3fa281c
update the fromVersion
clement-lyonnet Dec 9, 2024
41be69c
reformatted Classifier
clement-lyonnet Dec 9, 2024
8685a74
updated fromVersion Layout
clement-lyonnet Dec 9, 2024
5d0c946
updated pack-metadata
clement-lyonnet Dec 9, 2024
9cd55a9
updated fromVersion for yml file
clement-lyonnet Dec 9, 2024
ce81dcf
reformatted GCenter.py
clement-lyonnet Dec 9, 2024
ba9b31c
Content Pack zip upload
clement-lyonnet Dec 9, 2024
3b9cee9
description + zip
clement-lyonnet Dec 10, 2024
079b385
up readme and zip
clement-lyonnet Dec 10, 2024
88c926b
proxy+zip
clement-lyonnet Dec 10, 2024
4c60a8a
new Integration
clement-lyonnet Dec 11, 2024
7f7faef
Separated Alerts and Metadata
clement-lyonnet Dec 11, 2024
fde6597
PASSED: Metadata select, no engines, fetch < 10000
clement-lyonnet Dec 12, 2024
730969b
1.2.0 - WORKING: fetch <10k, multiple engines selected
clement-lyonnet Dec 13, 2024
ebd24d9
Updated IncidentFields
clement-lyonnet Dec 16, 2024
6ffcffe
Updated Classifiers
clement-lyonnet Dec 16, 2024
56aecb4
Updated Layouts
clement-lyonnet Dec 16, 2024
94b188e
Handle active_cti engine
clement-lyonnet Dec 16, 2024
50160c1
Updated IncidentTypes
clement-lyonnet Dec 16, 2024
0955a20
Updated zip
clement-lyonnet Dec 16, 2024
418ab24
New Automation script for Engine alerts
clement-lyonnet Dec 16, 2024
212cace
rawJSON not parsed, using CustomField method
clement-lyonnet Dec 16, 2024
3ef4291
Updated Layouts
clement-lyonnet Dec 16, 2024
1c70529
WORKING: selection of engines, dynamic layout for alerts
clement-lyonnet Dec 16, 2024
9cb8f94
New Field for GCenter WebUI link
clement-lyonnet Dec 16, 2024
3b62c58
Updated Layout
clement-lyonnet Dec 16, 2024
68f8c53
Handle WebUI link
clement-lyonnet Dec 16, 2024
ea76bab
Updated zip, WebUI link to GCenter
clement-lyonnet Dec 16, 2024
e6278dc
Updated Integration
clement-lyonnet Dec 17, 2024
cb1ec4b
Script Automation - directory tree
clement-lyonnet Dec 17, 2024
a9d8325
New RN
clement-lyonnet Dec 17, 2024
47a7c27
Updated zip
clement-lyonnet Dec 17, 2024
a828fcd
fix incidents duplicates
clement-lyonnet Dec 18, 2024
581eff2
Linting and typing
clement-lyonnet Dec 19, 2024
fc0e070
Remove unnecessary zip
clement-lyonnet Dec 19, 2024
66e4d01
Setting IncidentFields unsearchable property to true
clement-lyonnet Dec 26, 2024
a7ad297
Apply fix_broken_list suggested changes
clement-lyonnet Dec 26, 2024
314fde8
Use handle_proxy function from CommonServer
clement-lyonnet Dec 26, 2024
c4eafa4
Malcore IncidentFields renamed
clement-lyonnet Dec 26, 2024
71937c9
Shellcode Detect IncidentFields renamed
clement-lyonnet Dec 26, 2024
0a37e0a
Malicious Powershell Detect IncidentFields renamed
clement-lyonnet Dec 26, 2024
08284c4
Sigflow IncidentFields renamed
clement-lyonnet Dec 26, 2024
fc42a00
DGA Detect IncidentFields renamed
clement-lyonnet Dec 26, 2024
71968f1
Active CTI ioc IncidentFields renamed
clement-lyonnet Dec 26, 2024
eaba865
Ransomware Detect IncidentFields renamed
clement-lyonnet Dec 26, 2024
baefd7a
Beacon Detect IncidentFields renamed
clement-lyonnet Dec 26, 2024
842e0ac
Removed 1 unecessary Mapper Incoming, updated yml config file accordi…
clement-lyonnet Dec 26, 2024
e8e5eea
DCE/RPC IncidentFields renamed
clement-lyonnet Dec 26, 2024
0d33882
DHCP IncidentFields renamed
clement-lyonnet Dec 26, 2024
c34f2da
DNP3 IncidentFields renamed
clement-lyonnet Dec 26, 2024
6390906
DNS IncidentFields renamed
clement-lyonnet Dec 26, 2024
e1f446f
event module IncidentFields renamed
clement-lyonnet Dec 26, 2024
64ffa67
file IncidentFields renamed
clement-lyonnet Dec 26, 2024
d8a4f9e
flow id IncidentField renamed
clement-lyonnet Dec 27, 2024
e8644af
FTP IncidentFields renamed
clement-lyonnet Dec 27, 2024
0f2f481
GCap IncidentFields renamed
clement-lyonnet Dec 27, 2024
9d667b6
GCenter IncidentFields renamed
clement-lyonnet Dec 27, 2024
3463ab9
HTTP2 IncidentFields renamed
clement-lyonnet Dec 27, 2024
20cac26
HTTP IncidentFields renamed
clement-lyonnet Dec 27, 2024
f30220d
IKEV2 IncidentFields renamed
clement-lyonnet Dec 27, 2024
ace4128
KRB IncidentFields renamed
clement-lyonnet Dec 27, 2024
d5041a2
MQTT IncidentFields renamed
clement-lyonnet Dec 27, 2024
bbd5201
NBA IncidentFields renamed
clement-lyonnet Dec 27, 2024
7d4b3e1
Kerberos IncidentFields reworked
clement-lyonnet Dec 27, 2024
02079b5
NFS IncidentFields renamed
clement-lyonnet Dec 27, 2024
98d3475
Raw Event IncidentFields renamed
clement-lyonnet Dec 27, 2024
08449d3
RDP IncidentFields renamed
clement-lyonnet Dec 27, 2024
22e4dc8
RFB IncidentFields renamed
clement-lyonnet Dec 27, 2024
5eb37ed
SIP IncidentFields renamed
clement-lyonnet Dec 27, 2024
ceb43e0
SMB IncidentFields renamed
clement-lyonnet Dec 27, 2024
d18df42
SMTP IncidentFields renamed
clement-lyonnet Dec 27, 2024
a2dfcd6
SNMP IncidentFields renamed
clement-lyonnet Dec 27, 2024
365e6d9
SSH IncidentFields renamed
clement-lyonnet Dec 27, 2024
7d2226f
TFTP IncidentFields renamed
clement-lyonnet Dec 27, 2024
98ec4fc
TLS IncidentFields renamed
clement-lyonnet Dec 27, 2024
1bc4fef
Fix FTP field type data
clement-lyonnet Dec 27, 2024
9c8ebd0
Transport layer IncidentField renamed
clement-lyonnet Dec 27, 2024
d12a8e3
Removed unecessary fields
clement-lyonnet Dec 27, 2024
7065ef6
Updated Classifier for CommonTypes
clement-lyonnet Dec 27, 2024
b06dcff
Updated Layouts for CommonTypes
clement-lyonnet Dec 27, 2024
970f64f
Merge branch 'contrib/clement-lyonnet_gwecs' into gwecs
amshamah419 Jan 2, 2025
8c5cac5
Updated field names and associated file names
clement-lyonnet Jan 6, 2025
3fe4c0c
Merge 1.2.0 fetch and 1.3.0 commands
clement-lyonnet Jan 16, 2025
0542898
Mapping for UUID / event.id
clement-lyonnet Jan 16, 2025
2284b56
fix for commands
clement-lyonnet Jan 16, 2025
793bf24
new Playbook for Malcore Files and VirusTotal reputation
clement-lyonnet Jan 16, 2025
c49d855
VT to APIv2 from v3
clement-lyonnet Jan 17, 2025
f54a2fe
Updated Playbooks
clement-lyonnet Jan 17, 2025
525b1ff
fix for fileName Playbook Malcore
clement-lyonnet Jan 17, 2025
3b285b3
DONE: Malcore VT file reputation check
clement-lyonnet Jan 17, 2025
471bfa3
Updated Layouts
clement-lyonnet Jan 22, 2025
58423ee
Updated RN for pull request
clement-lyonnet Jan 23, 2025
6a1d302
format on Layouts
clement-lyonnet Jan 23, 2025
478b0dc
fix for token and classic credentials auth
clement-lyonnet Jan 24, 2025
d5c549b
test_module command reworked
clement-lyonnet Jan 29, 2025
920b6bd
test_module rework
clement-lyonnet Jan 29, 2025
75a109a
trying resolving conflicts on one file
clement-lyonnet Feb 3, 2025
f444a09
retry resolve on one file
clement-lyonnet Feb 3, 2025
a785c2e
resolve secrets ignore conflict
clement-lyonnet Feb 3, 2025
813aa57
resolve secrets ignore conflict
clement-lyonnet Feb 3, 2025
568b9a4
resolving Author image conflict
clement-lyonnet Feb 3, 2025
c60e253
resolving conflicts
clement-lyonnet Feb 3, 2025
ccd7bef
Ruff whitespace warning
clement-lyonnet Feb 3, 2025
65fe0d8
Ruff linter
clement-lyonnet Feb 3, 2025
e44a5b9
Remove duplicated IncidentField
clement-lyonnet Feb 4, 2025
17f0207
Add suffix _command to all commands
clement-lyonnet Feb 5, 2025
dbff0dc
Removed type ignore tags
clement-lyonnet Feb 5, 2025
68f8d06
Add CONTRIBUTORS file
clement-lyonnet Feb 5, 2025
a35adb9
Use of get method to access dict keys, some variables typing
clement-lyonnet Feb 6, 2025
faec186
command examples file
clement-lyonnet Feb 7, 2025
b552082
readable output reformatted
clement-lyonnet Feb 7, 2025
3b85f00
Test Playbook example
clement-lyonnet Feb 7, 2025
1347bb7
commands parameters: description format and content, updated release …
clement-lyonnet Feb 11, 2025
01a7f23
unit tests proposal, modified playbook depedencies, some mypy and val…
clement-lyonnet Feb 19, 2025
5f407ca
Fixing RM116, RN107 & RN114
clement-lyonnet Feb 19, 2025
5947085
Fixing RM114
clement-lyonnet Feb 19, 2025
1d63152
removed F405 comments, 2 new units tests
clement-lyonnet Feb 25, 2025
7a27d97
fixes for unit tests
clement-lyonnet Feb 25, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions Packs/Gatewatcher-AionIQ/CONTRIBUTORS.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
[
"FabienMht",
"CesarGW",
"ThibaultReboul",
"clement-lyonnet"
]
Loading
Loading