Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Pack Manifests with Data Models and Globals #1342

Merged
merged 3 commits into from
Sep 4, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions packs/asana.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,4 +20,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.Asana.Audit
DisplayName: "Panther Asana Pack"
3 changes: 3 additions & 0 deletions packs/atlassian.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.Atlassian.Audit
DisplayName: "Panther Atlassian Pack"
2 changes: 2 additions & 0 deletions packs/aws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -177,7 +177,9 @@ PackDefinition:
# AWS DataModels
- Standard.AWS.ALB
- Standard.AWS.CloudTrail
- Standard.Amazon.EKS.Audit
- Standard.AWS.S3ServerAccess
- Standard.AWS.VPCDns
- Standard.AWS.VPCFlow
- Standard.OCSF.NetworkActivity
- Standard.OCSF.DnsActivity
Expand Down
3 changes: 3 additions & 0 deletions packs/azure_signin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Models
- Standard.Azure.Audit.SignIn
DisplayName: "Panther Azure.Audit SignIn Pack"
3 changes: 3 additions & 0 deletions packs/box.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Models
- Standard.Box.Event
DisplayName: "Panther Box Pack"
3 changes: 2 additions & 1 deletion packs/cisco_umbrella_dns.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,5 +4,6 @@ Description: Group of all Cisco Umbrella detections
PackDefinition:
IDs:
- CiscoUmbrella.DNS.Blocked
# Globals used in these detections
# Data Model
- Standard.CiscoUmbrella.DNS
DisplayName: "Panther Cisco Umbrella Pack"
3 changes: 3 additions & 0 deletions packs/cloudflare.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,6 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
# Data Models
- Standard.Cloudflare.Firewall
- Standard.Cloudflare.HttpReq
6 changes: 6 additions & 0 deletions packs/credential_security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,16 @@ DisplayName: "Panther Credential Security Pack"
PackDefinition:
IDs:
# Data Models
- Standard.Asana.Audit
- Standard.Atlassian.Audit
- Standard.AWS.CloudTrail
- Standard.Crowdstrike.FDR
- Standard.Github.Audit
- Standard.Okta.SystemLog
- Standard.OneLogin.Events
- Standard.Slack.AuditLogs
- Standard.Zendesk.AuditLog
- Standard.Zoom.Operation
# Global Helpers
- global_filter_auth0
- global_filter_github
Expand Down
2 changes: 2 additions & 0 deletions packs/crowdstrike.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,5 +24,7 @@ PackDefinition:
- panther_config_defaults
- panther_config_overrides
# Data models
- Standard.AWS.VPCDns
- Standard.CiscoUmbrella.DNS
- Standard.Crowdstrike.FDR
DisplayName: "Panther Crowdstrike Pack"
3 changes: 3 additions & 0 deletions packs/crowdstrike_event_streams.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,9 @@ PackDefinition:
IDs:
- crowdstrike_event_streams_helpers
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides

- Crowdstrike.AdminRoleAssigned
- Crowdstrike.AllowlistRemoved
Expand Down
2 changes: 2 additions & 0 deletions packs/gsuite_reports.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,4 +39,6 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_lookuptable_helpers
DisplayName: "Panther GSuite Pack"
14 changes: 13 additions & 1 deletion packs/multisource_correlations.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,16 @@ PackDefinition:
- Okta.Login.Success
- Push.Security.Authorized.IdP.Login
- Okta.Login.Without.Push.Marker
- Push.Security.Phishing.Attack
- Push.Security.Phishing.Attack

# Data Models
- Standard.Okta.SystemLog
- Standard.Github.Audit
- Standard.AWS.CloudTrail

# Global Helpers
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
9 changes: 6 additions & 3 deletions packs/notion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,13 +18,16 @@ PackDefinition:
- Notion.SharingSettingsUpdated
- Notion.TeamspaceOwnerAdded
# Globals used in these detections
- panther_base_helpers
- panther_oss_helpers
- panther_notion_helpers
- global_filter_notion
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_ipinfo_helpers
- panther_lookuptable_helpers
- panther_notion_helpers
- panther_oss_helpers
# Data Model
- Standard.Notion.AuditLogs
DisplayName: "Panther Notion Pack"
3 changes: 3 additions & 0 deletions packs/onelogin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,4 +20,7 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
# Data Model
- Standard.OneLogin.Events
DisplayName: "Panther OneLogin Pack"
2 changes: 2 additions & 0 deletions packs/slack.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,3 +32,5 @@ PackDefinition:
- panther_config
- panther_config_defaults
- panther_config_overrides
# Data Model
- Standard.Slack.AuditLogs
8 changes: 7 additions & 1 deletion packs/standard_ruleset.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,12 @@ PackDefinition:
- Standard.NewAWSAccountCreated
- Standard.NewUserAccountCreated
# Global Helpers
- panther_base_helpers
- panther_default
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_ipinfo_helpers
- panther_lookuptable_helpers
- panther_oss_helpers
- panther_default
4 changes: 4 additions & 0 deletions packs/wiz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,7 @@ DisplayName: "Panther Wiz Pack"
PackDefinition:
IDs:
- Wiz.Alert.Passthrough
- panther_base_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
5 changes: 3 additions & 2 deletions packs/zoom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,9 @@ PackDefinition:
- Standard.Zoom.Operation
# Globals used in these detections
- panther_base_helpers
- panther_oss_helpers
- panther_zoom_helpers
- panther_config
- panther_config_defaults
- panther_config_overrides
- panther_event_type_helpers
- panther_oss_helpers
- panther_zoom_helpers
Loading