Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Microsoft365Defender gcc endpoints addition #37723

Open
wants to merge 139 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
139 commits
Select commit Hold shift + click to select a range
810ed11
added the endpoints for microsoft api module
noydavidi Dec 17, 2024
67b26f6
refactored and added fields in yml
noydavidi Dec 17, 2024
c5f2746
changes
noydavidi Dec 17, 2024
c070f45
Added more dicts and fixed client class
noydavidi Dec 18, 2024
571aee5
splitted long lines
noydavidi Dec 18, 2024
02ca13d
Added unittests
noydavidi Dec 22, 2024
47707c7
regenrated readme
noydavidi Dec 22, 2024
9bf19b2
fixed readme
noydavidi Dec 22, 2024
bc131fc
added info t description
noydavidi Dec 22, 2024
6ac6000
added rn and fixed description
noydavidi Dec 22, 2024
8e9db6e
added default value to endpoint_type in microsoft_defender_get_base_url
noydavidi Dec 22, 2024
2922859
fixed pre commit and tests
noydavidi Dec 22, 2024
b983f42
added rn to all integrations using MicrosoftApiModule
noydavidi Dec 22, 2024
25c1c2c
Merged master into current branch.
Dec 22, 2024
99ba229
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Dec 22, 2024
0a15d9b
Bump pack from version MicrosoftTeams to 1.5.11.
Dec 22, 2024
42f20f1
fixed titles in rn
noydavidi Dec 22, 2024
11c4a4c
before merging master
noydavidi Dec 22, 2024
588b6d7
merged master
noydavidi Dec 22, 2024
7a82862
fixed conflicts
noydavidi Dec 22, 2024
0b08a41
fixed conflicts
noydavidi Dec 22, 2024
56160d1
fixed conflicts
noydavidi Dec 22, 2024
f6a6563
fixed conflicts
noydavidi Dec 22, 2024
698d1e1
Merge branch 'master' into microsoft-defender-gcc-endpoints
noydavidi Dec 22, 2024
8e55b2a
Update 1_5_11.md
noydavidi Dec 22, 2024
1696014
Update 1_4_0.md
noydavidi Dec 22, 2024
68801d0
Update 1_3_28.md
noydavidi Dec 22, 2024
6762c84
Update 1_2_33.md
noydavidi Dec 22, 2024
895517c
Update 1_3_7.md
noydavidi Dec 22, 2024
6b5dd5c
Update 1_4_6.md
noydavidi Dec 22, 2024
65c0fe4
Update 1_2_0.md
noydavidi Dec 22, 2024
aec783d
Update 1_1_50.md
noydavidi Dec 22, 2024
529fce5
Update 1_2_5.md
noydavidi Dec 22, 2024
78ab92e
Update 1_2_0.md
noydavidi Dec 22, 2024
1a8442c
Update 1_2_37.md
noydavidi Dec 22, 2024
b2b3fdc
Update 1_0_6.md
noydavidi Dec 22, 2024
b2cfc24
Update 1_2_0.md
noydavidi Dec 22, 2024
22d9315
Update 1_2_5.md
noydavidi Dec 22, 2024
74d7ca2
Update 2_1_0.md
noydavidi Dec 22, 2024
73a9553
Update 1_6_0.md
noydavidi Dec 22, 2024
43fa4fc
Update 1_5_42.md
noydavidi Dec 22, 2024
4e74c3b
Update 1_1_10.md
noydavidi Dec 22, 2024
aea97cb
Update 2_2_22.md
noydavidi Dec 22, 2024
41b3adc
Update 1_0_17.md
noydavidi Dec 22, 2024
62c4ece
Update 1_6_23.md
noydavidi Dec 22, 2024
82c8e5f
Update 1_2_57.md
noydavidi Dec 22, 2024
21541f0
Update 1_1_53.md
noydavidi Dec 22, 2024
1d592f8
Update 1_1_32.md
noydavidi Dec 22, 2024
df923a6
Update 1_1_34.md
noydavidi Dec 22, 2024
4ef8201
Update 1_1_29.md
noydavidi Dec 22, 2024
027fbb6
Update 1_3_0.md
noydavidi Dec 22, 2024
03dd5bc
Update 1_1_53.md
noydavidi Dec 22, 2024
20fbc71
Update 1_5_23.md
noydavidi Dec 22, 2024
2d363c5
Update 1_18_1.md
noydavidi Dec 22, 2024
6c43e43
Update 1_2_32.md
noydavidi Dec 22, 2024
27d1054
Update 1_2_5.md
noydavidi Dec 22, 2024
65013af
Apply suggestions from code review
noydavidi Dec 22, 2024
414596e
Update 1_5_42.md
noydavidi Dec 22, 2024
6fd1859
Update 1_1_10.md
noydavidi Dec 22, 2024
f5e8240
Update 2_2_22.md
noydavidi Dec 22, 2024
a2f80e2
Update 1_0_17.md
noydavidi Dec 22, 2024
0d31b0d
Update 1_6_23.md
noydavidi Dec 22, 2024
86cc257
Update 1_2_57.md
noydavidi Dec 22, 2024
9b4956f
Update 1_1_53.md
noydavidi Dec 22, 2024
78879a4
Update 1_1_34.md
noydavidi Dec 22, 2024
265568b
added default in microsoft_defender_get_base_url
noydavidi Dec 22, 2024
7c1e2d6
pulled
noydavidi Dec 22, 2024
c671159
fixed teams rn
noydavidi Dec 23, 2024
755fe4c
fixed endpoint in main
noydavidi Dec 23, 2024
b48300a
remove spaces from yaml
noydavidi Dec 23, 2024
1964628
Added table for endpoints in readme
noydavidi Dec 23, 2024
da5e67a
fixed rn
noydavidi Dec 23, 2024
7522d35
removed debugging
noydavidi Dec 23, 2024
76ea9f8
Merged master into current branch.
Dec 24, 2024
f1bcac8
Bump pack from version MicrosoftExchangeOnline to 1.5.24.
Dec 24, 2024
e9f556f
Merged master into current branch.
Dec 24, 2024
ac4732a
Bump pack from version Microsoft365Defender to 4.5.40.
Dec 24, 2024
2a672be
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Dec 24, 2024
a9a7504
Merged master into current branch.
Jan 5, 2025
e245478
Bump pack from version MicrosoftGraphTeams to 1.1.11.
Jan 5, 2025
8ac37b2
Merged master into current branch.
Jan 7, 2025
2187ba8
Bump pack from version AzureSentinel to 1.6.0.
Jan 7, 2025
5a254ec
Bump pack from version AzureDevOps to 1.4.7.
Jan 7, 2025
15be793
Bump pack from version MicrosoftCloudAppSecurity to 2.2.11.
Jan 7, 2025
15e1a49
sent endpoint to microsoft client
noydavidi Jan 12, 2025
3a00913
pulled
noydavidi Jan 12, 2025
c0d2d07
Merged master into current branch.
Jan 13, 2025
0742080
Bump pack from version AzureLogAnalytics to 1.2.0.
Jan 13, 2025
42653f1
Bump pack from version AzureRiskyUsers to 1.2.0.
Jan 13, 2025
c121b5a
Merged master into current branch.
Jan 13, 2025
a90e985
Bump pack from version MicrosoftExchangeOnline to 1.5.25.
Jan 13, 2025
0fa77a8
Merged master into current branch.
Jan 14, 2025
01babcb
Bump pack from version MicrosoftExchangeOnline to 1.5.26.
Jan 14, 2025
c47956a
Merged master into current branch.
Jan 15, 2025
e6be2b4
Bump pack from version Microsoft365Defender to 4.5.41.
Jan 15, 2025
06f83eb
Merged master into current branch.
Jan 16, 2025
ebb44ab
Bump pack from version MicrosoftExchangeOnline to 1.5.27.
Jan 16, 2025
deffc6d
Merged master into current branch.
Jan 16, 2025
e821598
Bump pack from version AzureLogAnalytics to 1.2.0.
Jan 16, 2025
3a988a7
Bump pack from version MicrosoftGraphMail to 1.6.24.
Jan 16, 2025
5023730
Bump pack from version MicrosoftManagementActivity to 1.4.0.
Jan 16, 2025
7f6ca7d
added azure_cloud
noydavidi Jan 20, 2025
9ee2697
changes
noydavidi Jan 20, 2025
5c77b57
Merged master into current branch.
Jan 21, 2025
93a5f29
Bump pack from version MicrosoftTeams to 1.5.12.
Jan 21, 2025
6447ee5
Bump pack from version Microsoft365Defender to 4.5.42.
Jan 21, 2025
69724f1
Bump pack from version MicrosoftExchangeOnline to 1.5.28.
Jan 21, 2025
beb2c55
pulled
noydavidi Jan 21, 2025
9e2660c
working also in devie code
noydavidi Jan 21, 2025
55353b8
working also in devie code
noydavidi Jan 21, 2025
99b3461
added informative message for when tenant is not supported by GCC-High
noydavidi Jan 21, 2025
d37ce19
fixed
noydavidi Jan 21, 2025
e162142
added more descripotion about gcc
noydavidi Jan 21, 2025
814ebc6
added more descripotion in readme about gcc
noydavidi Jan 21, 2025
22a2238
Merged master into current branch.
Jan 22, 2025
af125da
Bump pack from version MicrosoftGraphIdentityandAccess to 1.2.58.
Jan 22, 2025
442c5ef
Bump pack from version MicrosoftGraphUser to 1.5.43.
Jan 22, 2025
71bfdb0
Merged master into current branch.
Jan 24, 2025
760f0c5
Bump pack from version MicrosoftTeams to 1.5.13.
Jan 24, 2025
221827e
Merged master into current branch.
Jan 26, 2025
2ad1b82
Bump pack from version MicrosoftExchangeOnline to 1.5.29.
Jan 26, 2025
02200f2
Merged master into current branch.
Jan 26, 2025
e54a296
Bump pack from version MicrosoftExchangeOnline to 1.5.30.
Jan 26, 2025
15ee8b2
Merged master into current branch.
Jan 27, 2025
9a4195f
Bump pack from version MicrosoftExchangeOnline to 1.6.1.
Jan 27, 2025
011b1ca
removed /mtp/.default from scope
noydavidi Jan 30, 2025
d6c5890
Merged master into current branch.
Jan 30, 2025
1fe9830
Bump pack from version MicrosoftGraphSecurity to 2.2.23.
Jan 30, 2025
9b952fa
removed /mtp/.default from scope
noydavidi Feb 2, 2025
6c84a65
merged master
noydavidi Feb 2, 2025
319aa7f
fixed api module
noydavidi Feb 2, 2025
3c6f57d
Merged master into current branch.
Feb 2, 2025
a1b3e1b
Bump pack from version MicrosoftExchangeOnline to 1.6.2.
Feb 2, 2025
1da14ed
removed a comma from url
noydavidi Feb 2, 2025
913ceff
pulled
noydavidi Feb 2, 2025
e489e6c
added the mtp to the worldwidr url"
noydavidi Feb 2, 2025
19a2acf
fixed token
noydavidi Feb 2, 2025
7720386
Merged master into current branch.
Feb 5, 2025
edeba49
Bump pack from version MicrosoftTeams to 1.5.14.
Feb 5, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -145,6 +145,62 @@ class Resources:
'gcc-high': 'https://login.microsoftonline.us',
}

MICROSOFT_365_DEFENDER_TYPE = {
"Worldwide": "com",
"US Geo Proximity": "geo-us",
"EU Geo Proximity": "geo-eu",
"UK Geo Proximity": "geo-uk",
"AU Geo Proximity": "geo-au",
"SWA Geo Proximity": "geo-swa",
"INA Geo Proximity": "geo-ina",
"US GCC": "gcc",
"US GCC-High": "gcc-high",
"DoD": "dod",
}

# https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list
# https://learn.microsoft.com/en-us/defender-xdr/usgov?view=o365-worldwide
MICROSOFT_365_DEFENDER_API_ENDPOINTS = {
"com": "https://api.security.microsoft.com",
"geo-us": "https://us.api.security.microsoft.com",
"geo-eu": "https://eu.api.security.microsoft.com",
"geo-uk": "https://uk.api.security.microsoft.com",
"geo-au": "https://au.api.security.microsoft.com",
"geo-swa": "https://swa.api.security.microsoft.com",
"geo-ina": "https://ina.api.security.microsoft.com",
"gcc": "https://api-gcc.security.microsoft.us",
"gcc-high": "https://api-gov.security.microsoft.us",
"dod": "https://api-gov.security.microsoft.us",
}

# https://learn.microsoft.com/en-us/defender-xdr/usgov?view=o365-worldwide
MICROSOFT_365_DEFENDER_TOKEN_RETRIEVAL_ENDPOINTS = {
'com': 'https://login.windows.net',
'geo-us': 'https://login.windows.net',
'geo-eu': 'https://login.windows.net',
'geo-uk': 'https://login.windows.net',
"geo-au": 'https://login.windows.net',
"geo-swa": 'https://login.windows.net',
"geo-ina": 'https://login.windows.net',
"gcc": "https://login.microsoftonline.com",
"gcc-high": "https://login.microsoftonline.us",
"dod": "https://login.microsoftonline.us",
}

MICROSOFT_365_DEFENDER_SCOPES = {
'com': "https://security.microsoft.com/mtp",
'geo-us': 'https://security.microsoft.com',
'geo-eu': 'https://security.microsoft.com',
'geo-uk': 'https://security.microsoft.com',
"geo-au": 'https://security.microsoft.com',
"geo-swa": 'https://security.microsoft.com',
"geo-ina": 'https://security.microsoft.com',
'gcc': 'https://security.microsoft.com',
'gcc-high': 'https://security.microsoft.us',
'dod': 'https://security.apps.mil',
}


# Azure Managed Identities
MANAGED_IDENTITIES_TOKEN_URL = 'http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01'
MANAGED_IDENTITIES_SYSTEM_ASSIGNED = 'SYSTEM_ASSIGNED'
Expand Down Expand Up @@ -636,6 +692,17 @@ def get_azure_cloud(params, integration_name):
return AZURE_CLOUDS.get(AZURE_CLOUD_NAME_MAPPING.get(azure_cloud_arg), AZURE_WORLDWIDE_CLOUD) # type: ignore[arg-type]


def microsoft_defender_get_base_url(base_url: str, endpoint_type: str) -> str:
if endpoint_type == 'Custom':
if not base_url:
raise DemistoException("Endpoint type is set to 'Custom' but no URL was provided.")
url = base_url
else:
endpoint = MICROSOFT_365_DEFENDER_TYPE.get(endpoint_type, 'com')
url = MICROSOFT_365_DEFENDER_API_ENDPOINTS.get(endpoint, 'https://api.security.microsoft.com')
return url


class MicrosoftClient(BaseClient):
def __init__(self, tenant_id: str = '',
auth_id: str = '',
Expand Down Expand Up @@ -1387,15 +1454,22 @@ def _add_info_headers() -> dict[str, str]:
def device_auth_request(self) -> dict:
response_json = {}
try:
if self.tenant_id:
url = f'{self.azure_ad_endpoint}/{self.tenant_id}/oauth2/v2.0/devicecode'
else:
url = f'{self.azure_ad_endpoint}/organizations/oauth2/v2.0/devicecode'
response = requests.post(
url=f'{self.azure_ad_endpoint}/organizations/oauth2/v2.0/devicecode',
url=url,
data={
'client_id': self.client_id,
'scope': self.scope
},
verify=self.verify
)
if not response.ok:
if "National Cloud" in self.error_parser(response):
return_error(f'Error in Microsoft authorization. Status: {response.status_code},'
f' The tenant is not supported by GCC-High. body: {self.error_parser(response)}')
return_error(f'Error in Microsoft authorization. Status: {response.status_code},'
f' body: {self.error_parser(response)}')
response_json = response.json()
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureActiveDirectory/ReleaseNotes/1_3_28.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Active Directory Identity Protection (Deprecated)

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureActiveDirectory/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"description": "Deprecated. Use Microsoft Graph Identity and Access instead.",
"support": "xsoar",
"hidden": true,
"currentVersion": "1.3.27",
"currentVersion": "1.3.28",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureCompute/ReleaseNotes/1_2_33.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Compute v2

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureCompute/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Compute",
"description": "Create and Manage Azure Virtual Machines",
"support": "xsoar",
"currentVersion": "1.2.32",
"currentVersion": "1.2.33",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureDataExplorer/ReleaseNotes/1_3_7.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Data Explorer

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureDataExplorer/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Data Explorer",
"description": "Use Azure Data Explorer integration to collect and analyze data inside clusters of Azure Data Explorer and manage search queries.",
"support": "xsoar",
"currentVersion": "1.3.6",
"currentVersion": "1.3.7",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureDevOps/ReleaseNotes/1_4_7.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### AzureDevOps

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureDevOps/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "AzureDevOps",
"description": "Create and manage Git repositories in Azure DevOps Services.",
"support": "xsoar",
"currentVersion": "1.4.6",
"currentVersion": "1.4.7",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureFirewall/ReleaseNotes/1_2_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Firewall

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureFirewall/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Firewall",
"description": "Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful firewall as a service, with built-in high availability and unrestricted cloud scalability. This pack contains an integration with a main goal to manage Azure Firewall security service, and normalization rules for ingesting and modeling Azure Firewall Resource logs.",
"support": "xsoar",
"currentVersion": "1.1.46",
"currentVersion": "1.2.0",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureKeyVault/ReleaseNotes/1_1_50.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Key Vault

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureKeyVault/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Key Vault",
"description": "Use Key Vault to safeguard and manage cryptographic keys and secrets used by cloud applications and services.",
"support": "xsoar",
"currentVersion": "1.1.49",
"currentVersion": "1.1.50",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureKubernetesServices/ReleaseNotes/1_2_5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Kubernetes Services

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureKubernetesServices/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Kubernetes Services",
"description": "Deploy and manage containerized applications with a fully managed Kubernetes service.",
"support": "xsoar",
"currentVersion": "1.2.4",
"currentVersion": "1.2.5",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureLogAnalytics/ReleaseNotes/1_2_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Log Analytics

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureLogAnalytics/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Log Analytics",
"description": "Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments.",
"support": "xsoar",
"currentVersion": "1.1.43",
"currentVersion": "1.2.0",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureNetworkSecurityGroups/ReleaseNotes/1_2_37.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Network Security Groups

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureNetworkSecurityGroups/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Network Security Groups",
"description": "Azure Network Security Groups are used to filter network traffic to and from Azure resources in an Azure virtual network",
"support": "xsoar",
"currentVersion": "1.2.36",
"currentVersion": "1.2.37",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureResourceGraph/ReleaseNotes/1_0_6.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Resource Graph

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureResourceGraph/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Resource Graph",
"description": "Azure Resource Graph is an Azure service designed to extend Azure Resource Management by providing efficient and performant resource exploration with the ability to query at scale across a given set of resources. This pack is primarily used to allow for executing Azure Resource Graph queries.",
"support": "xsoar",
"currentVersion": "1.0.5",
"currentVersion": "1.0.6",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureRiskyUsers/ReleaseNotes/1_2_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Risky Users

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureRiskyUsers/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Risky Users",
"description": "Azure Risky Users provides access to all at-risk users and risk detections in Azure AD environment.",
"support": "xsoar",
"currentVersion": "1.1.42",
"currentVersion": "1.2.0",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureSQLManagement/ReleaseNotes/1_2_5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure SQL Management

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureSQLManagement/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure SQL Management",
"description": "Microsoft Azure SQL Database is a managed cloud database provided as part of Microsoft Azure",
"support": "xsoar",
"currentVersion": "1.2.4",
"currentVersion": "1.2.5",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
9 changes: 9 additions & 0 deletions Packs/AzureSecurityCenter/ReleaseNotes/2_1_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
#### Integrations

##### Microsoft Defender for Cloud Event Collector

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.

##### Microsoft Defender for Cloud

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureSecurityCenter/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Microsoft Defender for Cloud",
"description": "Unified security management and advanced threat protection across hybrid cloud workloads.",
"support": "xsoar",
"currentVersion": "2.0.35",
"currentVersion": "2.1.0",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureSentinel/ReleaseNotes/1_6_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Microsoft Sentinel

Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureSentinel/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Microsoft Sentinel",
"description": "Microsoft Sentinel is a cloud-native security information and event manager (SIEM) platform that uses built-in AI to help analyze large volumes of data across an enterprise.",
"support": "xsoar",
"currentVersion": "1.5.57",
"currentVersion": "1.6.0",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
5 changes: 5 additions & 0 deletions Packs/AzureStorage/ReleaseNotes/1_2_32.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
#### Integrations

##### Azure Storage Management

- Added support for National Cloud in Microsoft 365 Defender, implemented in the Microsoft API Module.
2 changes: 1 addition & 1 deletion Packs/AzureStorage/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Azure Storage Management",
"description": "Deploy and manage storage accounts and blob service properties.",
"support": "xsoar",
"currentVersion": "1.2.31",
"currentVersion": "1.2.32",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
Loading
Loading