-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add CrowdStrike Falcon to XSIAM Marketplace #37854
base: master
Are you sure you want to change the base?
Conversation
@JasBeilin Doc review completed. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice! please check my comments.
Packs/CrowdStrikeFalcon/Scripts/ConvertEnrichmentsToTable/ConvertEnrichmentsToTable.yml
Outdated
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py
Outdated
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml
Outdated
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml
Outdated
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon_description.md
Show resolved
Hide resolved
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon_description.md
Outdated
Show resolved
Hide resolved
|
||
#### Incident Types | ||
|
||
##### CrowdStrike Falcon Detection | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon Incident | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon On-Demand Scans Detection | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon Mobile Detection | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon IOM Event | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon OFP Detection | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon IDP Detection | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon IOA Event | ||
|
||
Ensured incident type only appears in Cortex XSOAR. | ||
|
||
|
||
#### Mappers | ||
|
||
##### Legacy CrowdStrike Falcon-Mapper | ||
|
||
Ensured mapper only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon Mapper | ||
|
||
Ensured mapper only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Outgoing Mapper | ||
|
||
Ensured mapper only appears in Cortex XSOAR. | ||
|
||
|
||
#### Playbooks | ||
|
||
##### CrowdStrike Falcon - Search Endpoints By Hash | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - T1059 - Command and Scripting Interpreter | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Get Detections by Incident | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### Crowdstrike Falcon - Unisolate Endpoint | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Get Endpoint Forensics Data | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Search Endpoints By Indicators | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### Crowdstrike Falcon - Isolate Endpoint | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Retrieve File | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon - Block File | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
##### CrowdStrike Falcon Malware - Verify Containment Actions | ||
|
||
Ensured playbook only appears in Cortex XSOAR. | ||
|
||
|
||
#### Scripts | ||
|
||
##### ConvertEnrichmentsToTable | ||
|
||
Ensured script only appears in Cortex XSOAR. | ||
--> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No need for all of it to be a comment. It is irrelevant to customers.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is in a comment for the following reasons:
- To document this in the code without being visible in the official release notes (also documented internally)
- To pass the SDK release notes validation (if certain titles do not appear, the release notes are considered invalid)
Refer to the official documentation on excluding items from release notes.
Co-authored-by: Jasmine Beilin <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good but I see automations are still being removed from xsiam, is that intended?
See my comments.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Have we checked it looks correct when the tags are inside the link itself?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please Revert
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Seems like we are still removing this script.
Related Issues
fixes: link to the issue
Description
Update CrowdStrike Falcon pack: