Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecated content quick wins #26406

Merged
merged 123 commits into from
May 30, 2023
Merged
Show file tree
Hide file tree
Changes from 74 commits
Commits
Show all changes
123 commits
Select commit Hold shift + click to select a range
dca01b2
deprecated the playbook Archer initiate incident
OmriItzhak May 9, 2023
daec538
RN for deprecated the playbook Archer initiate incident
OmriItzhak May 9, 2023
8904574
Update deprecated content on Block Account - Generic v2 playbook
OmriItzhak May 9, 2023
96b08ec
RN for Update deprecated content on Block Account - Generic v2 playbook
OmriItzhak May 9, 2023
90178e3
Update Deprecated content on cortex xdr playbooks
OmriItzhak May 9, 2023
9fb5ad4
RN for Update Deprecated content on cortex xdr playbooks
OmriItzhak May 9, 2023
6265d5c
Update deprecated content on Saas_Security_-_Incident_Processor playbook
OmriItzhak May 9, 2023
f0752c3
RN for Update deprecated content on Saas_Security_-_Incident_Processo…
OmriItzhak May 9, 2023
27ce93f
deprecated the playbook Vulnerability Management - Qualys (Job)
OmriItzhak May 9, 2023
9dbc237
RN for deprecated the playbook Vulnerability Management - Qualys (Job)
OmriItzhak May 9, 2023
b748eff
update command on the playbook Tanium Demo
OmriItzhak May 9, 2023
c566ca7
RN for update command on the playbook Tanium Demo
OmriItzhak May 9, 2023
7ec6454
Update deprecated commands on the playbooks TIE IOC Hunt and `Search_…
OmriItzhak May 9, 2023
8ba2ffe
RN for Update deprecated commands on the playbooks TIE IOC Hunt and `…
OmriItzhak May 9, 2023
b814c12
Merged master into current branch.
May 9, 2023
4763893
Bump pack from version CortexXDR to 4.10.41.
May 9, 2023
58e9f66
Merged master into current branch.
May 9, 2023
5d53881
Bump pack from version ArcherRSA to 1.2.11.
May 9, 2023
d921993
fix validation errors
OmriItzhak May 10, 2023
e7cfe43
Merge remote-tracking branch 'origin/Deprecated_content_Quick_wins' i…
OmriItzhak May 10, 2023
dffe084
update test playbook McAfee TIE to use the integration McAfee Threat …
OmriItzhak May 11, 2023
8f8a718
update test playbook McAfee TIE to use the integration McAfee Threat …
OmriItzhak May 11, 2023
689e983
Merge branch 'master' into Deprecated_content_Quick_wins
ssokolovich May 11, 2023
f88bf41
Merged master into current branch.
May 14, 2023
49fb1fd
Bump pack from version CommonPlaybooks to 2.3.65.
May 14, 2023
77ecdd4
Merged master into current branch.
May 14, 2023
d81eab2
Bump pack from version CommonPlaybooks to 2.3.66.
May 14, 2023
5c2d0f3
Merged master into current branch.
May 15, 2023
4bfdf86
Bump pack from version CortexXDR to 4.10.42.
May 15, 2023
27e7344
Merged master into current branch.
May 16, 2023
a13a0bd
Bump pack from version McAfee-TIE to 2.0.7.
May 16, 2023
9723f7c
Merge branch 'master' into Deprecated_content_Quick_wins
OmriItzhak May 16, 2023
8bbd830
Merged master into current branch.
May 17, 2023
956636d
Bump pack from version CommonPlaybooks to 2.3.67.
May 17, 2023
029e1e4
Merged master into current branch.
May 17, 2023
de743d4
Bump pack from version CortexXDR to 4.10.43.
May 17, 2023
b27d57c
Merged master into current branch.
May 17, 2023
46f62ef
Bump pack from version Tanium to 1.0.25.
May 17, 2023
76f2922
Merged master into current branch.
May 18, 2023
9c074ab
Bump pack from version qualys to 1.2.8.
May 18, 2023
043abba
Merged master into current branch.
May 21, 2023
ca12113
Bump pack from version CortexXDR to 4.10.44.
May 21, 2023
3984e76
Merged master into current branch.
May 21, 2023
1f1a762
Bump pack from version CommonPlaybooks to 2.3.68.
May 21, 2023
3e63da5
Bump pack from version ArcherRSA to 1.2.12.
May 21, 2023
602aa74
Bump pack from version qualys to 1.2.9.
May 21, 2023
919e691
Merged master into current branch.
May 22, 2023
53701be
Bump pack from version CortexXDR to 4.10.45.
May 22, 2023
f99a55c
Merged master into current branch.
May 22, 2023
8d117e1
Bump pack from version CommonPlaybooks to 2.3.69.
May 22, 2023
cd6623b
Merge branch 'master' into Deprecated_content_Quick_wins
OmriItzhak May 22, 2023
2081c52
removed deprecated commands `EPOFindSystem` (EOL) from playbook-Searc…
OmriItzhak May 23, 2023
adbb047
Deprecated cortex xdr playbooks. replaced with relevance commands
OmriItzhak May 23, 2023
2c576aa
RN for Deprecated cortex xdr playbooks. replaced with relevance commands
OmriItzhak May 23, 2023
c2ffebb
Merged master into current branch.
May 23, 2023
89075c8
Bump pack from version CortexXDR to 4.10.46.
May 23, 2023
b9ee831
replaced sub-playbook-Cortex_XDR_-_delete_file with relevance command…
OmriItzhak May 24, 2023
8c196e2
RN after replaced sub-playbook-Cortex_XDR_-_delete_file with relevanc…
OmriItzhak May 24, 2023
17e73be
Merge remote-tracking branch 'origin/Deprecated_content_Quick_wins' i…
OmriItzhak May 24, 2023
b324107
Merge branch 'master' of github.com:demisto/content into Deprecated_c…
OmriItzhak May 24, 2023
7daad4d
RN after replaced sub-playbook-Cortex_XDR_-_delete_file with relevanc…
OmriItzhak May 24, 2023
711596e
fix validation error - update png name on RM files
OmriItzhak May 24, 2023
0ab529b
Merge branch 'master' into Deprecated_content_Quick_wins
OmriItzhak May 24, 2023
122f849
Merged master into current branch.
May 24, 2023
1bb8b2b
Bump pack from version CortexXDR to 4.11.1.
May 24, 2023
36a3ad2
Merged master into current branch.
May 25, 2023
bdd1b1c
Bump pack from version CommonPlaybooks to 2.3.70.
May 25, 2023
f8f3baa
Merge branch 'master' into Deprecated_content_Quick_wins
OmriItzhak May 28, 2023
8439088
Merge branch 'master' of github.com:demisto/content into Deprecated_c…
OmriItzhak May 28, 2023
291292a
Merge remote-tracking branch 'origin/Deprecated_content_Quick_wins' i…
OmriItzhak May 28, 2023
b72ba29
fix for build error
OmriItzhak May 28, 2023
a6dfe63
Merge branch 'master' into Deprecated_content_Quick_wins
OmriItzhak May 28, 2023
bea8e2c
fix for build error
OmriItzhak May 28, 2023
d229164
Merge remote-tracking branch 'origin/Deprecated_content_Quick_wins' i…
OmriItzhak May 28, 2023
97dd44f
Merged master into current branch.
May 29, 2023
da0c66f
Bump pack from version CommonPlaybooks to 2.3.71.
May 29, 2023
3961cf3
Update Packs/ArcherRSA/ReleaseNotes/1_2_12.md
OmriItzhak May 30, 2023
2eeeef4
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Execute_snippe…
OmriItzhak May 30, 2023
decb739
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
b9fc016
Update Packs/qualys/Playbooks/playbook-Vulnerability_Management__-_Qu…
OmriItzhak May 30, 2023
6e754aa
Update Packs/qualys/Playbooks/playbook-Vulnerability_Management__-_Qu…
OmriItzhak May 30, 2023
e1db034
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Execute_snippe…
OmriItzhak May 30, 2023
1e5d6ff
Update Packs/Tanium/ReleaseNotes/1_0_25.md
OmriItzhak May 30, 2023
08a9cf8
Update Packs/qualys/Playbooks/playbook-Vulnerability_Management__-_Qu…
OmriItzhak May 30, 2023
6bf9853
Update Packs/qualys/ReleaseNotes/1_2_9.md
OmriItzhak May 30, 2023
be48b0b
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
8648c45
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
f0b1579
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
2b45557
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
43d2d87
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_True_Positive_…
OmriItzhak May 30, 2023
1150760
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_check_file_exi…
OmriItzhak May 30, 2023
a6c90d7
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_check_file_exi…
OmriItzhak May 30, 2023
2a634d3
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_check_file_exi…
OmriItzhak May 30, 2023
5cdecdc
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_check_file_exi…
OmriItzhak May 30, 2023
f863728
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_check_file_exi…
OmriItzhak May 30, 2023
4b86193
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_delete_file.yml
OmriItzhak May 30, 2023
fda1afd
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_delete_file.yml
OmriItzhak May 30, 2023
aef3bd1
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_kill_process_R…
OmriItzhak May 30, 2023
38c56a8
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_delete_file.yml
OmriItzhak May 30, 2023
6b134cb
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_delete_file_RE…
OmriItzhak May 30, 2023
8171452
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_execute_comman…
OmriItzhak May 30, 2023
6643f80
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_execute_comman…
OmriItzhak May 30, 2023
b8a23f5
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_execute_comman…
OmriItzhak May 30, 2023
64a3545
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_kill_process.yml
OmriItzhak May 30, 2023
bfcf591
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_kill_process.yml
OmriItzhak May 30, 2023
0b8ebdf
Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_kill_process.yml
OmriItzhak May 30, 2023
813d2a5
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
2b4d052
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
1a72134
Update Packs/Tanium/ReleaseNotes/1_0_25.md
OmriItzhak May 30, 2023
0896b51
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
b3ed014
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
fdbcf88
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
09f6f34
Update Packs/CortexXDR/ReleaseNotes/4_11_1.md
OmriItzhak May 30, 2023
1292b38
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
e2e20d3
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
bd48d3b
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
a42b002
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
f79d3f0
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
acc808d
Update Packs/McAfee-TIE/ReleaseNotes/2_0_7.md
OmriItzhak May 30, 2023
534c042
Update Packs/PrismaSaasSecurity/ReleaseNotes/2_0_21.md
OmriItzhak May 30, 2023
bb315dc
update after review - rollback and commit only changes on xdr playbooks
OmriItzhak May 30, 2023
9a446b5
update after review - rollback and commit only changes on xdr playboo…
OmriItzhak May 30, 2023
1d5879e
fix for validation error change png name
OmriItzhak May 30, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,10 @@ id: Archer initiate incident
version: -1
name: Archer initiate incident
fromversion: "5.0.0"
deprecated: true
starttaskid: "0"
description: "initiate Archer incident"
description: "Deprecated. Use the `archer-get-file` command directly instead.
OmriItzhak marked this conversation as resolved.
Show resolved Hide resolved
initiate Archer incident"
tasks:
"0":
id: "0"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,28 +1,38 @@
Initiates an Archer incident.
Deprecated. Use the `archer-get-file` command directly instead.
initiate Archer incident

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

## Sub-playbooks
### Sub-playbooks

This playbook does not use any sub-playbooks.

## Integrations
### Integrations

* RSA Archer

## Scripts
### Scripts

This playbook does not use any scripts.

## Commands
### Commands

* archer-get-file

## Playbook Inputs

---
There are no inputs for this playbook.

## Playbook Outputs

---
There are no outputs for this playbook.

## Playbook Image

---
![Archer_initiate_incident](https://raw.githubusercontent.com/demisto/content/1bdd5229392bd86f0cc58265a24df23ee3f7e662/docs/images/playbooks/Archer_initiate_incident.png)

![Archer initiate incident](../doc_files/Archer_initiate_incident.png)
6 changes: 6 additions & 0 deletions Packs/ArcherRSA/ReleaseNotes/1_2_12.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@

#### Playbooks

##### Archer initiate incident

- Deprecated. Use the `archer-get-file` command directly instead.
OmriItzhak marked this conversation as resolved.
Show resolved Hide resolved
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2 changes: 1 addition & 1 deletion Packs/ArcherRSA/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "RSA Archer",
"description": "The RSA Archer GRC Platform provides a common foundation for managing policies, controls, risks, assessments and deficiencies across lines of business.",
"support": "xsoar",
"currentVersion": "1.2.11",
"currentVersion": "1.2.12",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -160,8 +160,8 @@ tasks:
id: 6c4b8a60-449b-4710-89e8-a68c32fdda28
version: -1
name: PAN-OS - Register Tag to User
description: Apply a tag to a user.
script: "|||panorama-register-user-tag"
description: Registers users to a tag. This command is only available for PAN-OS version 9.x and above.
script: '|||pan-os-register-user-tag'
type: regular
iscommand: true
brand: ""
Expand All @@ -170,10 +170,14 @@ tasks:
- "2"
scriptarguments:
Users:
simple: ${Blocklist.Final}
complex:
root: Blocklist
accessor: Final
tag:
simple: ${inputs.Tag}
complex:
root: inputs.Tag
separatecontext: false
continueonerrortype: ""
view: |-
{
"position": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,28 +3,41 @@ This playbook blocks malicious usernames using all integrations that you have en
Supported integrations for this playbook:
* Active Directory
* PAN-OS - This requires PAN-OS 9.1 or higher.
* SailPoint
* PingOne
* AWS IAM
* Clarizen IAM
* Envoy IAM
* ExceedLMS IAM
* Okta

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

This playbook does not use any sub-playbooks.

### Integrations

* Active Directory Query v2

### Scripts

* SetAndHandleEmpty
* IsIntegrationAvailable

### Commands
* panorama-register-user-tag
* pingone-deactivate-user

* iam-disable-user
* identityiq-disable-account
* pingone-deactivate-user
* pan-os-register-user-tag
* ad-disable-account
* iam-disable-user

## Playbook Inputs

---

| **Name** | **Description** | **Default Value** | **Required** |
Expand All @@ -35,12 +48,15 @@ This playbook does not use any sub-playbooks.
| UserVerification | Possible values:True/False. Default:True.<br/>Specify if User Verification is Requrired | True | Optional |

## Playbook Outputs

---

| **Path** | **Description** | **Type** |
| --- | --- | --- |
| Blocklist.Final | Blocked accounts | unknown |

## Playbook Image

---
![Block Account - Generic v2](../doc_files/Block_Account_-_Generic_v2.png)

![Block Account - Generic v2](../doc_files/Block_Account_-_Generic_v2.png)
4 changes: 4 additions & 0 deletions Packs/CommonPlaybooks/ReleaseNotes/2_3_70.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
#### Playbooks

##### Block Account - Generic v2
Updated deprecated command from ***panorama-register-user-tag*** to ***pan-os-register-user-tag***.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Updated deprecated command from ***panorama-register-user-tag*** to ***pan-os-register-user-tag***.
Updated the deprecated command from ***panorama-register-user-tag*** to ***pan-os-register-user-tag***.

2 changes: 1 addition & 1 deletion Packs/CommonPlaybooks/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Common Playbooks",
"description": "Frequently used playbooks pack.",
"support": "xsoar",
"currentVersion": "2.3.69",
"currentVersion": "2.3.70",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
Loading