Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix MDE settings description #31398

Merged
merged 8 commits into from
Dec 13, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ configuration:
section: Connect
required: false
- defaultvalue: New
display: 'Status to filter out alerts for fetching as incidents. Comma-separated lists are supported, e.g., New,Resolved.'
display: 'Status for fetching alerts as incidents. Comma-separated lists are supported, e.g., New,Resolved.'
name: fetch_status
options:
- New
Expand Down Expand Up @@ -151,7 +151,7 @@ configuration:
advanced: true
required: false
- defaultvalue: Informational,Low,Medium,High
display: 'Severity to filter out alerts for fetching as incidents. Comma-separated lists are supported, e.g., Medium,High.'
display: 'Severity for fetching alerts as incidents. Comma-separated lists are supported, e.g., Medium,High.'
name: fetch_severity
type: 16
options:
Expand Down Expand Up @@ -5534,7 +5534,7 @@ script:
execution: false
name: microsoft-atp-auth-reset
arguments: []
dockerimage: demisto/crypto:1.0.0.82826
dockerimage: demisto/crypto:1.0.0.83343
isfetch: true
runonce: false
script: '-'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -77,9 +77,9 @@ Please add the following permissions to the app registration. Choose application
| Application redirect URI (for authorization code mode) | | False |
| Authorization code | for user-auth mode - received from the authorization step. see Detailed Instructions section | False |
| Azure Managed Identities Client ID | The Managed Identities client ID for authentication - relevant only if the integration is running on Azure VM. | UUID |
| Status to filter out alerts for fetching as incidents | The property values are, "New", "InProgress" or "Resolved". Comma-separated lists are supported, e.g., New,Resolved. | New,In Progress,Resolved |
| Status for fetching alerts as incidents | The property values are, "New", "InProgress" or "Resolved". Comma-separated lists are supported, e.g., New,Resolved. | New,In Progress,Resolved |
| DetecitonSource to filter out alters for fetching as incidents. | The property values are, "Antivirus", "CustomDetection", "CustomTI", "EDR" and "MDO". Comma-separated lists are supported, e.g., Antivirus,EDR. | CustomDetection,EDR |
| Severity to filter out alerts for fetching as incidents | The property values are, "Informational", "Low", "Medium" and "High". Comma-separated lists are supported, e.g., Medium,High. | Medium,High |
| Severity for fetching alerts as incidents| The property values are, "Informational", "Low", "Medium" and "High". Comma-separated lists are supported, e.g., Medium,High. | Medium,High |
| Maximum number of incidents to fetch | The maximum number of incidents to retrieve per fetch. | 50 |
| Trust any Certificate (Not Secure) | When selected, certificates are not checked. | N/A |
| Fetch alert evidence | When selected, fetches alerts in Microsoft Defender. | N/A |
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@

#### Integrations

##### Microsoft Defender for Endpoint
- Updated the Docker image to: *demisto/crypto:1.0.0.83343*.
- Updated the settings' descriptions.
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "Microsoft Defender for Endpoint",
"description": "Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection (ATP)) is a unified platform for preventative protection, post-breach detection, automated investigation, and response.",
"support": "xsoar",
"currentVersion": "1.16.20",
"currentVersion": "1.16.21",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down