Skip to content

Commit

Permalink
Update Pack Manifests with Data Models and Globals (#1342)
Browse files Browse the repository at this point in the history
* add missing data models to packs

* add missing globals to packs

---------

Co-authored-by: Ariel Ropek <79653153+arielkr256@users.noreply.github.com>
  • Loading branch information
ben-githubs and arielkr256 authored Sep 4, 2024
1 parent f67b924 commit d195f9d
Show file tree
Hide file tree
Showing 18 changed files with 70 additions and 8 deletions.
3 changes: 3 additions & 0 deletions packs/asana.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,4 +20,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.Asana.Audit
DisplayName: "Panther Asana Pack"
3 changes: 3 additions & 0 deletions packs/atlassian.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.Atlassian.Audit
DisplayName: "Panther Atlassian Pack"
2 changes: 2 additions & 0 deletions packs/aws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -177,7 +177,9 @@ PackDefinition:
# AWS DataModels
- Standard.AWS.ALB
- Standard.AWS.CloudTrail
- Standard.Amazon.EKS.Audit
- Standard.AWS.S3ServerAccess
- Standard.AWS.VPCDns
- Standard.AWS.VPCFlow
- Standard.OCSF.NetworkActivity
- Standard.OCSF.DnsActivity
Expand Down
3 changes: 3 additions & 0 deletions packs/azure_signin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Models
- Standard.Azure.Audit.SignIn
DisplayName: "Panther Azure.Audit SignIn Pack"
3 changes: 3 additions & 0 deletions packs/box.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Models
- Standard.Box.Event
DisplayName: "Panther Box Pack"
3 changes: 2 additions & 1 deletion packs/cisco_umbrella_dns.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,5 +4,6 @@ Description: Group of all Cisco Umbrella detections
PackDefinition:
IDs:
- CiscoUmbrella.DNS.Blocked
# Globals used in these detections
# Data Model
- Standard.CiscoUmbrella.DNS
DisplayName: "Panther Cisco Umbrella Pack"
3 changes: 3 additions & 0 deletions packs/cloudflare.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,6 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
# Data Models
- Standard.Cloudflare.Firewall
- Standard.Cloudflare.HttpReq
6 changes: 6 additions & 0 deletions packs/credential_security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,16 @@ DisplayName: "Panther Credential Security Pack"
PackDefinition:
IDs:
# Data Models
- Standard.Asana.Audit
- Standard.Atlassian.Audit
- Standard.AWS.CloudTrail
- Standard.Crowdstrike.FDR
- Standard.Github.Audit
- Standard.Okta.SystemLog
- Standard.OneLogin.Events
- Standard.Slack.AuditLogs
- Standard.Zendesk.AuditLog
- Standard.Zoom.Operation
# Global Helpers
- global_filter_auth0
- global_filter_github
Expand Down
2 changes: 2 additions & 0 deletions packs/crowdstrike.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,5 +24,7 @@ PackDefinition:
- panther_config_defaults
- panther_config_overrides
# Data models
- Standard.AWS.VPCDns
- Standard.CiscoUmbrella.DNS
- Standard.Crowdstrike.FDR
DisplayName: "Panther Crowdstrike Pack"
3 changes: 3 additions & 0 deletions packs/crowdstrike_event_streams.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,9 @@ PackDefinition:
IDs:
- crowdstrike_event_streams_helpers
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides

- Crowdstrike.AdminRoleAssigned
- Crowdstrike.AllowlistRemoved
Expand Down
2 changes: 2 additions & 0 deletions packs/gsuite_reports.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,4 +39,6 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_lookuptable_helpers
DisplayName: "Panther GSuite Pack"
14 changes: 13 additions & 1 deletion packs/multisource_correlations.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,16 @@ PackDefinition:
- Okta.Login.Success
- Push.Security.Authorized.IdP.Login
- Okta.Login.Without.Push.Marker
- Push.Security.Phishing.Attack
- Push.Security.Phishing.Attack

# Data Models
- Standard.Okta.SystemLog
- Standard.Github.Audit
- Standard.AWS.CloudTrail

# Global Helpers
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
9 changes: 6 additions & 3 deletions packs/notion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,13 +18,16 @@ PackDefinition:
- Notion.SharingSettingsUpdated
- Notion.TeamspaceOwnerAdded
# Globals used in these detections
- panther_base_helpers
- panther_oss_helpers
- panther_notion_helpers
- global_filter_notion
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_ipinfo_helpers
- panther_lookuptable_helpers
- panther_notion_helpers
- panther_oss_helpers
# Data Model
- Standard.Notion.AuditLogs
DisplayName: "Panther Notion Pack"
3 changes: 3 additions & 0 deletions packs/onelogin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,4 +20,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.OneLogin.Events
DisplayName: "Panther OneLogin Pack"
2 changes: 2 additions & 0 deletions packs/slack.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,3 +32,5 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
# Data Model
- Standard.Slack.AuditLogs
8 changes: 7 additions & 1 deletion packs/standard_ruleset.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,12 @@ PackDefinition:
- Standard.NewAWSAccountCreated
- Standard.NewUserAccountCreated
# Global Helpers
- panther_base_helpers
- panther_default
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_ipinfo_helpers
- panther_lookuptable_helpers
- panther_oss_helpers
- panther_default
4 changes: 4 additions & 0 deletions packs/wiz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,7 @@ DisplayName: "Panther Wiz Pack"
PackDefinition:
IDs:
- Wiz.Alert.Passthrough
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
5 changes: 3 additions & 2 deletions packs/zoom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,9 @@ PackDefinition:
- Standard.Zoom.Operation
# Globals used in these detections
- panther_base_helpers
- panther_oss_helpers
- panther_zoom_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_oss_helpers
- panther_zoom_helpers

0 comments on commit d195f9d

Please sign in to comment.