forked from demisto/content
-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sort imports and add submit_threat command #1
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
figarrido
reviewed
Jun 2, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
To not cause confusion, in the YML file in the configuration, we should change the defaultvalue
and the display
values for the url
param
6121653
to
06a0633
Compare
06a0633
to
6315aa3
Compare
figarrido
pushed a commit
that referenced
this pull request
Aug 11, 2023
* Updated READMEs * Added descriptions * --amend * restored deleted file * Added RNs * CR updates * Added THF to known words * Split ThreatQ_v1 * ThreatQ RNs * Updated ThreatQ pack-ignore * Added BA124 to ThreatQ.yml * Bump pack from version OpenPhish to 2.0.15. --------- Co-authored-by: Content Bot <bot@demisto.com>
figarrido
pushed a commit
that referenced
this pull request
Sep 21, 2023
…misto#29639) * Fix falls of the autopep8 hook
figarrido
pushed a commit
that referenced
this pull request
Oct 24, 2023
* [pre-commit MyPy] Align the entire repo with MyPy #1 * Xsup 27738 DBotFindSimilarIncidents NoneType Error (demisto#29701) * failed ut * fix * rn * pre-commit * pre commit * just the fix * fix description in yml * fix * docker * Update Packs/Base/ReleaseNotes/1_32_34.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * test * test * removed import --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Wiz v1 2 11 (demisto#29719) * Wiz v1 2 11 (demisto#29688) * remove redundant parenthesis * ../Packs/Wiz/Integrations/Wiz/Wiz.py * add Wiz user agent * rephrase release notes * update pack metadata json * rephrase release notes v2 * fix minor typos and update docker image * Bump Docker version --------- Co-authored-by: Ariel Tobiana <107474518+ariel-wiz@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [ASM] - Expander - Update ASM fields (4821) (demisto#29702) * [ASM] - Expander - Update ASM fields (4821) (demisto#29506) * Add missing comments to grid fields - Update descriptions of fields as needed. * Add release notes * Add descriptions to two fields - asmdevcheckdetails - asmenrichmentstatus * Update release notes. * Grammar updates. * Update release notes * Add mandatory or optional in comments * Update comments with mandatory * Update pack version and release notes * Add correct 1_6_33 release notes * fix rn * fix rn --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> * Wildfire-upload-url add poling timeout argument (demisto#29790) * save adding timeout param * new docker image * added rn * fix ruff * ruff made me to do this fixes :( not related to my changes * Update Packs/Palo_Alto_Networks_WildFire/ReleaseNotes/2_1_35.md * poetry files (demisto#29793) Co-authored-by: Content Bot <bot@demisto.com> * Dra-cvss-color-fix (demisto#29757) * Fixed a small issue when indicator had no custom fields * RN * docker bump * RN * Update CVECVSSColor.py * docker bump * RN * fixing typos in build scripts. (demisto#29788) unremovable -> non-removable productname -> product_name testplaybook -> test_playbook changed some arg passing to use their full name: -gpidd -gpidp Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> * mapping to standard stix values (demisto#29785) * mapping to standard stix values * updated release notes * update docker * breaking json * add dot * Add the nightly_ruff file for run pre-commit with --all flag (demisto#29684) * Add the nightly_ruff file for run pre-commit with --all flag * Add more rules; Add the error name * Add E501 * Add F601, F842, TID252 * XSUP-27528 (demisto#29705) * add_tests * add_tests * add RN, fix tests, format yml * Update Packs/CommonScripts/ReleaseNotes/1_12_24.md Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> * fix readme * Bump pack from version CommonScripts to 1.12.25. --------- Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * Add RN * Update Packs/Cybersixgill-DVE/pack_metadata.json Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Add RN * Fix UT * Update the docker images --------- Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: Ariel Tobiana <107474518+ariel-wiz@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: Darya Koval <72339940+daryakoval@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Dror Avrahami <davrahami@paloaltonetworks.com> Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>
figarrido
added a commit
that referenced
this pull request
Oct 24, 2023
* Update Group-IB TI APP PR from master branch (#29350) * test commit * remove bt link * Remove A in TI for yaml and md for indicator * back yaml to default * refactor yaml with cortex utils * refactor md and yaml for feed * remove bp/domain * replace git_leak with git_repository * Add new collection Fix issue with date for TI * remove changes outside the Packs * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIB_TIA_Feed/test_data/example.json Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIB_TIA_Feed/test_data/example.json Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * update release notes * update logo * update logo * Revert "update release notes" This reverts commit fc93e44461b3085c156c42a96e3f5aaf8efbe0af. * revert microsocks * fix compromised account issue * adding RL * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/GroupIBTIA.py Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> * create release notes v1_3_12 * add test for compromised/account_group * refactor changes in playbook * fixed validation errors * adding pragma no cover * refactor RN * add urllib exception * fixing validation errors * adding pragma no cover * format * fix lint test errors * revert sentinel * revert changes to azure sentinel * fixing cloud machine ids processing (#29777) * fixing cloud machine ids processing * not exiting the installation script if we fail to install a pack. report an error but continue with the test playbook upload (#29759) Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> * Microsoft DNS Parsing Rule Drop (#29765) * Updated ParsingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ReleaseNotes * Updated pack_metadata * Updated pack_metadata * Updated pack_metadata * Updated README * Updated README * Updated README * [JoeSecurity] Pre-Commit (#29717) * [pre-commit ruff] Align the entire repo with ruff #2 (#29754) * [pre-commit ruff] Align the entire repo with ruff #2 * Add RN * Update the docker image * Don't checkout build files in pre-commit (#27900) * is file up to date pre-commit * Revert changes made by mistake --------- Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <mmhw770@gmail.com> * Fixes for 'NGFW Scan' and 'WildFire Malware' XSIAM playbooks (#29774) * Fixes for 'NGFW Scan' and 'WildFire Malware' XSIAM playbooks * RN * fixed RN and 'NGFW Scan playbook' * CiscoSMA- Added timeout parameter (#29372) * fix * add_tests * fix_test_description * fix_yml_add_readme * fixes - add timeout to the client * add timeout to yml * revert changes * Update CiscoSMA.py * Update CiscoSMA.py * CR review * add RN * fix CR review * update docker image * XSUP-27956/ Added EWS PS V3 Description (#29784) * updated the description * update rn * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Xsup 27738 DBotFindSimilarIncidents NoneType Error (#29701) * failed ut * fix * rn * pre-commit * pre commit * just the fix * fix description in yml * fix * docker * Update Packs/Base/ReleaseNotes/1_32_34.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * test * test * removed import --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Wiz v1 2 11 (#29719) * Wiz v1 2 11 (#29688) * remove redundant parenthesis * ../Packs/Wiz/Integrations/Wiz/Wiz.py * add Wiz user agent * rephrase release notes * update pack metadata json * rephrase release notes v2 * fix minor typos and update docker image * Bump Docker version --------- Co-authored-by: Ariel Tobiana <107474518+ariel-wiz@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [ASM] - Expander - Update ASM fields (4821) (#29702) * [ASM] - Expander - Update ASM fields (4821) (#29506) * Add missing comments to grid fields - Update descriptions of fields as needed. * Add release notes * Add descriptions to two fields - asmdevcheckdetails - asmenrichmentstatus * Update release notes. * Grammar updates. * Update release notes * Add mandatory or optional in comments * Update comments with mandatory * Update pack version and release notes * Add correct 1_6_33 release notes * fix rn * fix rn --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> * Wildfire-upload-url add poling timeout argument (#29790) * save adding timeout param * new docker image * added rn * fix ruff * ruff made me to do this fixes :( not related to my changes * Update Packs/Palo_Alto_Networks_WildFire/ReleaseNotes/2_1_35.md * poetry files (#29793) Co-authored-by: Content Bot <bot@demisto.com> * Dra-cvss-color-fix (#29757) * Fixed a small issue when indicator had no custom fields * RN * docker bump * RN * Update CVECVSSColor.py * docker bump * RN * fixing typos in build scripts. (#29788) unremovable -> non-removable productname -> product_name testplaybook -> test_playbook changed some arg passing to use their full name: -gpidd -gpidp Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> * mapping to standard stix values (#29785) * mapping to standard stix values * updated release notes * update docker * breaking json * add dot * Add the nightly_ruff file for run pre-commit with --all flag (#29684) * Add the nightly_ruff file for run pre-commit with --all flag * Add more rules; Add the error name * Add E501 * Add F601, F842, TID252 * XSUP-27528 (#29705) * add_tests * add_tests * add RN, fix tests, format yml * Update Packs/CommonScripts/ReleaseNotes/1_12_24.md Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> * fix readme * Bump pack from version CommonScripts to 1.12.25. --------- Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * [Axonius Content Pack 1.2.0] Bumping Dockerfile (#29802) * [Axonius Content Pack 1.2.0] Bumping Dockerfile (#29625) * bumped docker version for axonius api client * docker image * remove the - --------- Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> * format --------- Co-authored-by: Bryce Pedroza <97995056+bryce-ax@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> * Updated native:8.4 image; Add auth-utils support (#29792) Co-authored-by: GuyAfik <guyafik11@gmail.com> * Fixed sc_task closing state (#29636) * Fixed sc_task closing state * Added release notes * Updated docker image * small fix * bumped dokcer * fixed rn --------- Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> Co-authored-by: sbenyakir <shahaf.benyakir@demisto.com> * Private Compliance Packs (#29664) * XSUP-27936 problem with regex (#29613) * failed test * fix * rn * rn * unit test * ut * validations * fixed test and docker * fix * validation * Prisma Cloud V2 Add "usernames" Argument (#29710) * add username arg * support list * update UT * update README * docker update * update TPB * Fortinet fortigate enhancement (#29655) * Updated the readme for proofpoint fortigate. * Modified the modeling rule. * Modified the modeling rule and the schema file. * Updated the release note. * Update Packs/FortiGate/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Updated the modeling rule. * Added tags to the readme. * removed ftntfgtmastersrcmac and ftntfgtmasterdstmac from the mapping. * updated the modeling rule and the schema file. * updated the modeling rule * updated the modeling rule --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Add syslog example for War Room Actions (#29800) * Graph Security Update (#29797) * Updated MicrosoftGraphSecurity_schema * Updated ReleaseNotes * Updated ReleaseNotes * [Dataminr Pulse] Release 106 (#29805) * [Dataminr Pulse] Release 106 (#29693) * Changes related to release v1.0.6 * Changes related to release v1.0.6 * Fixing Release Note related issue --------- Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * Bump Docker version --------- Co-authored-by: Crest Data Systems <60967033+crestdatasystems@users.noreply.github.com> Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [RecordedFuture] threat actor playbook update V2.5.1 (#29690) (#29807) * Update Threat actor search playbook. * Add release notes * Fix formatting * Change ExtractedIndicators to ExtractedIndicators\.File * Fix release notes --------- Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [JoeSecurity] show partial result in polling commands (#29715) * updating build docker image to latest devdemisto/gitlab-content-ci:1.0.0.64455 (#29761) * updating build docker image to latest devdemisto/gitlab-content-ci:1.0.0.64455 * Private Upload Mode - ThreatExchange v2 (#28249) * ThreatExchange integration * ThreatExchange updates * Added param to instance configuration * pre-commit * updated RN * RN test * CR updates * Removed Threat_Crowd * Update Packs/ThreatExchange/ReleaseNotes/2_0_12.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * docker * format * skip tests since theres no instance * no testing instance --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> * added plus 1 for each iteration in find destination (#29811) * added plus 1 for each iteration in find destination (#29760) * added plus 1 for each iteration in find destination * added release notes * Update Packs/Cisco-umbrella-cloud-security/ReleaseNotes/2_0_2.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * updated docker image tag to latest * updated unit test for pagination functions * removed comments --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update 2_0_2.md --------- Co-authored-by: LiorQM <106475467+LiorQM@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> * Mde list indicator filter (#29640) * Mde list indicator filter (#29338) * init indicator filter * release notes * latest docker image * updated docker image * minor fixes * reslove conflicts * resolve version conflicts * silence linter * format * docker * Apply suggestions from Shirley Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * add period * change phrase * adding "is_mockable": false * docker * try change test playbook * empty line * docker * return the mock * Revert "return the mock" This reverts commit da9baeff5cadddf2cd125fb073c266c867f465a5. --------- Co-authored-by: ckaadic <48683125+ckaadic@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Audit Logs Endpoints Scripts Aligments for Xsoar-8 (#29781) * test * fix core api * ExportAuditLogsToFile - add support for xsoar-8 * add ExportAuditLogsToFile UTs * add forward audit logs uts * update ut * validation fixes * mypy * bump rns * update docker * update docker image * fix ut * format * Bump pack from version CommonScripts to 1.12.25. * Bump pack from version CommonScripts to 1.12.26. * cr * cr fixes * update * fix uts --------- Co-authored-by: Content Bot <bot@demisto.com> * Add command prisma-cloud-compute-get-file-integrity-events (#29608) * Add command prisma-cloud-compute-get-file-integrity-events (#29187) * Add command prisma-cloud-compute-get-file-integrity-events * Incorporate changes from review comments. Add documentation and unit test. * Add missing lines to YML file (add description of new command) * Update docker image * Incorporate changes from demo * Update docker image * fix validation * fix validation --------- Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> * Bump pack from version PrismaCloudCompute to 1.4.10. * [pre-commit ruff] Align the entire repo with ruff (#29603) * Fix falls of the ruff hook * pre-commit * Fix B003 ruff error * Fix ruff errors on Utils/update_playbook.py * remove code to trigger upload on dev branches (#29621) * [pre-commit pycln] Align the entire repo with pycln (#29611) * Fix falls of the pycln hook * pre-commit * Fix unit test * Add RN * Fix validate in GetDomainDNSDetails * fuff on GetDomainDNSDetails * ignore mypy error in test_content.py:350 * Fix falls of the autopep8 hook (#29638) * add marketplaces to metadata (#29629) * Fixing AWS Project Number in ASM Cloud (#29593) (#29642) Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [MS Teams] support reset_graph_auth (#29644) * fixed * pre-commit * update * Recordedfuture threathunting v2.5.0 (#29641) * Recordedfuture threathunting v2.5.0 (#29025) * Add commands related to Automated Threat hunting recordedfuture-threat-map recordedfuture-threat-links recordedfuture-detection-rules * Add recordedfuture-collective-insight command. Change app version. * Update README.md. Add release notes * Add playbook. Add unittests * Add unittests * Fix test_collective_insight_command * Remove incorrect release note * Add documentation for threat actor search playbook * update Recorded Future Threat actor search playbook. add release note about new playbook. * Update release notes, fix formatting * Format yml files * Update Recorded future threat actor search playbook * Update docker image * Fix linter --------- Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * Minor README fixes --------- Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [ASM] Expander 5777 (#29647) * [ASM] Expander 5777 (#29619) * first * RN * Bump pack from version CortexAttackSurfaceManagement to 1.6.36. --------- Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * XDR Malware Enrichment - hotfix for usernames (split) (#29585) * Updated playbook with hotfix where we split usernames from domains and append them to the username list of usernames for account enrichment * Added RN * remove irrelevant test * Updated RN * Bump pack from version CortexXDR to 5.1.6. * Update Packs/CortexXDR/ReleaseNotes/5_1_6.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Docker Image To demisto/pyjwt3 (#29656) * Updated Metadata Of Pack Silverfort * Added release notes to pack Silverfort * Packs/Silverfort/Integrations/Silverfort/Silverfort.yml Docker image update * Update Docker Image To demisto/trustar (#29660) * Updated Metadata Of Pack TruSTAR * Added release notes to pack TruSTAR * Update Docker Image To demisto/keeper-ksm (#29661) * Updated Metadata Of Pack KeeperSecretsManager * Added release notes to pack KeeperSecretsManager * Packs/KeeperSecretsManager/Integrations/KeeperSecretsManager/KeeperSecretsManager.yml Docker image update * Update Docker Image To demisto/py3-tools (#29654) * Updated Metadata Of Pack Intezer * Added release notes to pack Intezer * Packs/Intezer/Integrations/IntezerV2/IntezerV2.yml Docker image update * Updated Metadata Of Pack FeedMalwareBazaar * Added release notes to pack FeedMalwareBazaar * Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update * Updated Metadata Of Pack FeedGCPWhitelist * Added release notes to pack FeedGCPWhitelist * Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update * Updated Metadata Of Pack AccentureCTI_Feed * Added release notes to pack AccentureCTI_Feed * Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Update Docker Image To demisto/taxii-server (#29659) * Updated Metadata Of Pack CybleThreatIntel * Added release notes to pack CybleThreatIntel * Packs/CybleThreatIntel/Integrations/CybleThreatIntel/CybleThreatIntel.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Update Docker Image To demisto/datadog-api-client (#29662) * Updated Metadata Of Pack DatadogCloudSIEM * Added release notes to pack DatadogCloudSIEM * Packs/DatadogCloudSIEM/Integrations/DatadogCloudSIEM/DatadogCloudSIEM.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Add reliability parameter to cves and pipl integration (#28703) * commiting PrismaCloudCompute * release notes added * changed couldcompute, CVESearchV2, pipl * added pack metadata * fixed pipl readme * reverting changes in CVESearch since it was deprecated * removed redundant * committing pre commit changes * added known words * added known words * fixed lint error * changed according to review * updated docker version in PrismaCloudCompute * changed according to doc review * Added condition for not receiving new incidents in the test playbook * updating release notes * reverting fetch changes * fixed playbook * formatted playbook * new validation, new run * new validation, new run * Bump pack from version PrismaCloudCompute to 1.4.10. * update the docker image --------- Co-authored-by: Content Bot <bot@demisto.com> * Proofpoint email security pack: update description (#29651) * update description * Updated the schema file. * Updated the schema file. --------- Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> * Jira v2 deprecated (#29649) * Deprecate to jira v2 * update RN * update conf.json file * add task to the Create Jira Issue playbook that check if jira v3 is enable * add image.png of the playbook * update the playbook (yml, readme, image) and RN * Update Docker Image To demisto/python3 (#29652) * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack VMwareWorkspaceONEUEM * Added release notes to pack VMwareWorkspaceONEUEM * Packs/VMwareWorkspaceONEUEM/Integrations/VMwareWorkspaceONEUEM/VMwareWorkspaceONEUEM.yml Docker image update * Updated Metadata Of Pack CiscoSMA * Added release notes to pack CiscoSMA * Packs/CiscoSMA/Integrations/CiscoSMA/CiscoSMA.yml Docker image update * Updated Metadata Of Pack FeedThreatConnect * Added release notes to pack FeedThreatConnect * Packs/FeedThreatConnect/Integrations/FeedThreatConnect/FeedThreatConnect.yml Docker image update * Updated Metadata Of Pack BitSight * Added release notes to pack BitSight * Packs/BitSight/Integrations/BitSightForSecurityPerformanceManagement/BitSightForSecurityPerformanceManagement.yml Docker image update * Updated Metadata Of Pack AWS-ILM * Added release notes to pack AWS-ILM * Packs/AWS-ILM/Integrations/AWSILM/AWSILM.yml Docker image update * Updated Metadata Of Pack CiscoWSA * Added release notes to pack CiscoWSA * Packs/CiscoWSA/Integrations/CiscoWSAV2/CiscoWSAV2.yml Docker image update * Updated Metadata Of Pack SysAid * Added release notes to pack SysAid * Packs/SysAid/Integrations/SysAid/SysAid.yml Docker image update * Updated Metadata Of Pack ManageEngine_PAM360 * Added release notes to pack ManageEngine_PAM360 * Packs/ManageEngine_PAM360/Integrations/ManageEnginePAM360/ManageEnginePAM360.yml Docker image update * Updated Metadata Of Pack CiscoUmbrellaReporting * Added release notes to pack CiscoUmbrellaReporting * Packs/CiscoUmbrellaReporting/Integrations/CiscoUmbrellaReporting/CiscoUmbrellaReporting.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * XSUP-27717/FortiSIEM (#29458) * add tests * add RN,fix,logs * Update 2_0_21.md * add period * add a name to incident * fixes CR * update docker image * delete logs * CR fixes * Update 2_0_21.md * Update FortiSIEMV2.py * reverting the Docker image (#29607) * reverting the Docker image * Update Packs/cyberark_AIM/ReleaseNotes/1_0_14.md --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29663) * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29314) * "pack contribution initial commit" * Update RoksitDNSSecurityIntegrationSarp.py * Update RoksitDNSSecurityIntegrationSarp.py * Yehuda's version * test module * readme * new logo * Update RoksitDNSSecurityIntegrationSarp.yml * Apply suggestions from code review * Update RoksitDNSSecurityIntegrationSarp_description.md * Update pack_metadata.json * Update README.md * Update pack_metadata.json * Update pack_metadata.json * Update Packs/RoksitDNSSecurityIntegration-Sarp/pack_metadata.json * fixes * change name * folder name * file names * version * rename sub folder * remove (DNSSense) from the integration name * rename folder * docker * replace image * fix image name --------- Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> * rename image --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> * add unstuck fetch stream command (#29646) * add unstuck fetch stream command * added RN * fixes * add note * cr fixes * fix conflicts * reverts * [pre-commit pycln] Align the entire repo with pycln #4 (#29665) * Fix pycln errors * Update the docker images * Run demisto-sdk pre-commit * Remove unnecessary recommendations from extensions.json (#29605) * update extensions.json * Update devcontainer.json * Update recommendations list * Zscaler-FW-Logs (#29094) * Zscaler FW Logs Modeling Rules * Zscaler FW logs Modeling Rules * Updated README * Updated ZscalerModelingRule_1_3 * Changed cs5 field name to cat * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Updated README * Updated ModelingRules and Schema * Updated ModelingRules and schema * Updated ModelingRules * Updated ModelingRules --------- Co-authored-by: Eido Epstain <eepstain@paloaltonetworks.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * PANOS - EXPANDR-5744 (#29223) (#29686) * playbook updates * RN, Readme, screenshot * Apply suggestions from code review * update RN * bump ver * more descriptive task * bump ver --------- Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Audit alert fields fix (#29685) * Add associated types to systemAssociatedTypes * Add associated types to systemAssociatedTypes * fix incident field structure * RN * Workday documentation fix (#29681) * readme * readme * rn * rn * [Marketplace Contribution] Active Directory Query - Content Pack Update (#28633) * [Marketplace Contribution] Active Directory Query - Content Pack Update (#27822) * "contribution update to pack "Active Directory Query"" * revert changes * rl * remove files * removed from rl * Update pack_metadata.json * Create 1_6_19.md * Update 1_6_18.md * Update 1_6_19.md * Delete 1_6_19.md * Update 1_6_18.md * Update pack_metadata.json * Update Active_Directory_Query.yml removed duplicate section and type * pass SERVER_IP as argument to test_credentials function * Create 1_7_0.md * Update pack_metadata.json * Update README.md with ad-test-credentials info * Update Active_Directory_Query.yml * removed duplicate `type: 8` from ntlm * removed duplicate types from integration settings * removed duplicate description from ad-enable-account * Update Active_Directory_Query.yml * Update Active_Directory_Query.yml * Update Active_Directory_Query.yml * removing not relevant release note * adding function * update fucntion * cr note * adding NTLM_AUTH option * Update Active_Directory_Query.py * Update Packs/Active_Directory_Query/Integrations/Active_Directory_Query/Active_Directory_Query.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * cr notes * update after merging from master * reverting a change in olr rl * added test_test_credentials unit test function * fix unit test * fixing unit tests * fix unit test * fixed lint errors * Update Active_Directory_Query_test.py * empty commit * fix yml and docker file * revert changes in send email manager * fix yml * fix * fix validation error * fixing in129 --------- Co-authored-by: maimorag <mmorag@paloaltonetworks.com> Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * cr notes * Bump pack from version Active_Directory_Query to 1.6.21. * fix yml changes * cr notes * lint fixes * fix test * docker update * Update Packs/Active_Directory_Query/Integrations/Active_Directory_Query/README.md Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * fix delete required * Apply suggestions from code review * fix test * docker update * rl * empty commit * docker update * empty commit * empty commit * merge from master * empty commit check * revert changes * Delete Packs/cyberark_AIM/Integrations/CyberArkAIM_v2/integration-CyberArkAIM_v2.yml * docker downgrade * rl * trying new docker image * validate errors fix * revert docker version * [DS108] - Description must end with a period (".") - fix * empty commit check * empty commit check --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: maimorag <mmorag@paloaltonetworks.com> Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * Big query bug xsup 28132 (#29680) * bug fix * rn * rn * Apply suggestions from code review Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * format * pre commit --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * New Prisma Cloud v2 commands (#29323) * resource list command * limit results * user roles list command * pre commit * users list command * edit remediation commands * UTs * update README * update RN * pre commit fixes * edit test playbook * CR changes * Demo changes - remediate 406 raises error new args for resource_list & user_roles * fix test * Apply suggestions from doc review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * fix test playbook * Tomer's changes --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Prisma Cloud Update (#29666) * Updated ModelingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ModelingRules * Updated ModelingRules * Updated ModelingRules * Bump pack from version PrismaCloud to 4.2.4. --------- Co-authored-by: Content Bot <bot@demisto.com> * Rapid7 appsec (#29134) (#29687) * Revert "Add space to conf" This reverts commit 3a74b931d31ae2b33e0e4570c7df7d06c668e9c8. * Updated the packs category to *Authentication & Identity Management* (part 2) (#24876) * Update Docker Image To demisto/fastapi (#24923) * Updated Metadata Of Pack CyberArkIdentity * Added release notes to pack CyberArkIdentity * Packs/CyberArkIdentity/Integrations/CyberArkIdentityEventCollector/CyberArkIdentityEventCollector.yml Docker image update * Update Docker Image To demisto/lxml (#24924) * Updated Metadata Of Pack TaniumThreatResponse * Added release notes to pack TaniumThreatResponse * Packs/TaniumThreatResponse/Integrations/TaniumThreatResponseV2/TaniumThreatResponseV2.yml Docker image update * Update Docker Image To demisto/crypto (#24922) * Updated Metadata Of Pack X509Certificate * Added release notes to pack X509Certificate * Packs/X509Certificate/Scripts/CertificateExtract/CertificateExtract.yml Docker image update * Update Docker Image To demisto/python3 (#24921) * Updated Metadata Of Pack Cybereason * Added release notes to pack Cybereason * Packs/Cybereason/Integrations/Cybereason/Cybereason.yml Docker image update * Updated Metadata Of Pack DNSDB * Added release notes to pack DNSDB * Packs/DNSDB/Integrations/DNSDB_v2/DNSDB_v2.yml Docker image update * Updated Metadata Of Pack DeepInstinct * Added release notes to pack DeepInstinct * Packs/DeepInstinct/Integrations/DeepInstinct3x/DeepInstinct3x.yml Docker image update * Updated Metadata Of Pack FeedCyrenThreatInDepth * Added release notes to pack FeedCyrenThreatInDepth * Packs/FeedCyrenThreatInDepth/Integrations/CyrenThreatInDepth/CyrenThreatInDepth.yml Docker image update * Updated Metadata Of Pack IronDefense * Added release notes to pack IronDefense * Packs/IronDefense/Integrations/IronDefense/IronDefense.yml Docker image update * Updated Metadata Of Pack Qintel * Added release notes to pack Qintel * Packs/Qintel/Integrations/QintelPMI/QintelPMI.yml Docker image update * Packs/Qintel/Integrations/QintelQSentry/QintelQSentry.yml Docker image update * Packs/Qintel/Integrations/QintelQWatch/QintelQWatch.yml Docker image update * Updated Metadata Of Pack QualysFIM * Added release notes to pack QualysFIM * Packs/QualysFIM/Integrations/QualysFIM/QualysFIM.yml Docker image update * Updated Metadata Of Pack QutteraWebsiteMalwareScanner * Added release notes to pack QutteraWebsiteMalwareScanner * Packs/QutteraWebsiteMalwareScanner/Integrations/QutteraWebsiteMalwareScanner/QutteraWebsiteMalwareScanner.yml Docker image update * Fixed mypy + validation --------- * NGINXApiModule: fix logging typo (#24878) * fix logging typo * bump dependent packs --------- * Downgrade docker to fix banner issue (#24905) * Downgrade docker to fix banner issue * Fix docs * Add UT to prevent Docker bump * Fix yml validation * Adding vulnerability commands * Fixing pagination page index * Updating PR comments and Scan commands * Updating ID in test data. * Updating integration * Updating integration * Updating fromversion * Updating linters * Updating linters * Updating git pre-commit * Updating docstring * Updating the handling of request when limit * Removing get_pagination_params * Updating integration * Updating git-pre commit * Updating integration * Updating integration * Updating unit test * Updating docker image * Updating integration * Updating README version. * Updating secrets * Updating integration * Updating integration * Updating integration * Updating docstrings * Updating doc-review comments. * Updating doc-review comments. * Updating description --------- Co-authored-by: Ron Hadad <112933572+ronh1@users.noreply.github.com> Co-authored-by: TalGumi <talg@qmasters.co> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: sberman <sberman@paloaltonetworks.com> Co-authored-by: Guy Lichtman <1395797+glicht@users.noreply.github.com> Co-authored-by: glicht <glicht@users.noreply.github.com> Co-authored-by: Andrew Shamah <42912128+amshamah419@users.noreply.github.com> * Panos add param (#29672) * added param job_polling_max_num_attempts * Added rn * Added missing param type Fixed unit tests * added to readme * fixed readme * Update Packs/PAN-OS/Integrations/Panorama/Panorama.yml Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com> * fixed text and namings * Bump pack from version PAN-OS to 2.1.8. --------- Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * Fix proxy usage (#85) (#29630) * Fix proxy usage (#85) (#29181) * Fix proxy usage (#85) * Fix proxy usage in ZF client * Fix variable USE_SSL to verify requests * Remove proxy object from client Given that the proxy works by default with env vars, the proxy object is not necessary * Update version and add release notes * Fix call to modified alerts (#86) * Fix call to modified alerts * Update docker image * Fix tests associated with get modified data * change rn * fix validation --------- Co-authored-by: Felipe Garrido <fgarridob.95+github@gmail.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> * Missing dependencies when installing packs (#28989) * search and install packs --------- Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> * Deprecate Picus Community (#29573) * Merge branch 'master' into github_workflow_partner # Conflicts: # Utils/github_workflow_scripts/utils.py * Merge branch 'master' into github_workflow_partner # Conflicts: # Utils/github_workflow_scripts/utils.py * Picus NG display name * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update --------- Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> * [ASM] - Expander - GCP Hierarchy field - 4376 (#29696) (#29704) * Add assethierarchy field to GCP ASM playbook * Add release notes * Update field json Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> * fix merge * update rn * remove access code * fix conflicts * update docker * fix validation --------- Co-authored-by: Ali Sawyer <91506078+ali-sawyer@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> Co-authored-by: Yaakov Praisler <59408745+yaakovpraisler@users.noreply.github.com> Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com> Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: sberman <sberman@paloaltonetworks.com> Co-authored-by: DinaMeylakh <72339665+DinaMeylakh@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> Co-authored-by: nkanon <109467661+nkanon@users.noreply.github.com> Co-authored-by: Eido Epstain <eepstain@paloaltonetworks.com> Co-authored-by: Tomer Haimof <81556849+tomer-pan@users.noreply.github.com> Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> Co-authored-by: maimorag <mmorag@paloaltonetworks.com> Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com> Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com> Co-authored-by: Ron Hadad <112933572+ronh1@users.noreply.github.com> Co-authored-by: TalGumi <talg@qmasters.co> Co-authored-by: Guy Lichtman <1395797+glicht@users.noreply.github.com> Co-authored-by: glicht <glicht@users.noreply.github.com> Co-authored-by: Andrew Shamah <42912128+amshamah419@users.noreply.github.com> Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com> Co-authored-by: Felipe Garrido <fgarridob.95+github@gmail.com> Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> Co-authored-by: Edi Katsenelson <85438368+edik24@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> * [Marketplace Contribution] Okta - Content Pack Update (#29650) * [Marketplace Contribution] Okta - Content Pack Update (#29303) * "contribution update to pack "Okta"" * minor fixes * add outputs and readme * add outputs description * update docker * change outputs --------- Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> * Fixing AWS Project Number in ASM Cloud (#29593) (#29642) Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [MS Teams] support reset_graph_auth (#29644) * fixed * pre-commit * update * Recordedfuture threathunting v2.5.0 (#29641) * Recordedfuture threathunting v2.5.0 (#29025) * Add commands related to Automated Threat hunting recordedfuture-threat-map recordedfuture-threat-links recordedfuture-detection-rules * Add recordedfuture-collective-insight command. Change app version. * Update README.md. Add release notes * Add playbook. Add unittests * Add unittests * Fix test_collective_insight_command * Remove incorrect release note * Add documentation for threat actor search playbook * update Recorded Future Threat actor search playbook. add release note about new playbook. * Update release notes, fix formatting * Format yml files * Update Recorded future threat actor search playbook * Update docker image * Fix linter --------- Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * Minor README fixes --------- Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * [ASM] Expander 5777 (#29647) * [ASM] Expander 5777 (#29619) * first * RN * Bump pack from version CortexAttackSurfaceManagement to 1.6.36. --------- Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * XDR Malware Enrichment - hotfix for usernames (split) (#29585) * Updated playbook with hotfix where we split usernames from domains and append them to the username list of usernames for account enrichment * Added RN * remove irrelevant test * Updated RN * Bump pack from version CortexXDR to 5.1.6. * Update Packs/CortexXDR/ReleaseNotes/5_1_6.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Docker Image To demisto/pyjwt3 (#29656) * Updated Metadata Of Pack Silverfort * Added release notes to pack Silverfort * Packs/Silverfort/Integrations/Silverfort/Silverfort.yml Docker image update * Update Docker Image To demisto/trustar (#29660) * Updated Metadata Of Pack TruSTAR * Added release notes to pack TruSTAR * Update Docker Image To demisto/keeper-ksm (#29661) * Updated Metadata Of Pack KeeperSecretsManager * Added release notes to pack KeeperSecretsManager * Packs/KeeperSecretsManager/Integrations/KeeperSecretsManager/KeeperSecretsManager.yml Docker image update * Update Docker Image To demisto/py3-tools (#29654) * Updated Metadata Of Pack Intezer * Added release notes to pack Intezer * Packs/Intezer/Integrations/IntezerV2/IntezerV2.yml Docker image update * Updated Metadata Of Pack FeedMalwareBazaar * Added release notes to pack FeedMalwareBazaar * Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update * Updated Metadata Of Pack FeedGCPWhitelist * Added release notes to pack FeedGCPWhitelist * Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update * Updated Metadata Of Pack AccentureCTI_Feed * Added release notes to pack AccentureCTI_Feed * Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Update Docker Image To demisto/taxii-server (#29659) * Updated Metadata Of Pack CybleThreatIntel * Added release notes to pack CybleThreatIntel * Packs/CybleThreatIntel/Integrations/CybleThreatIntel/CybleThreatIntel.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Update Docker Image To demisto/datadog-api-client (#29662) * Updated Metadata Of Pack DatadogCloudSIEM * Added release notes to pack DatadogCloudSIEM * Packs/DatadogCloudSIEM/Integrations/DatadogCloudSIEM/DatadogCloudSIEM.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * Add reliability parameter to cves and pipl integration (#28703) * commiting PrismaCloudCompute * release notes added * changed couldcompute, CVESearchV2, pipl * added pack metadata * fixed pipl readme * reverting changes in CVESearch since it was deprecated * removed redundant * committing pre commit changes * added known words * added known words * fixed lint error * changed according to review * updated docker version in PrismaCloudCompute * changed according to doc review * Added condition for not receiving new incidents in the test playbook * updating release notes * reverting fetch changes * fixed playbook * formatted playbook * new validation, new run * new validation, new run * Bump pack from version PrismaCloudCompute to 1.4.10. * update the docker image --------- Co-authored-by: Content Bot <bot@demisto.com> * Proofpoint email security pack: update description (#29651) * update description * Updated the schema file. * Updated the schema file. --------- Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> * Jira v2 deprecated (#29649) * Deprecate to jira v2 * update RN * update conf.json file * add task to the Create Jira Issue playbook that check if jira v3 is enable * add image.png of the playbook * update the playbook (yml, readme, image) and RN * Update Docker Image To demisto/python3 (#29652) * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack VMwareWorkspaceONEUEM * Added release notes to pack VMwareWorkspaceONEUEM * Packs/VMwareWorkspaceONEUEM/Integrations/VMwareWorkspaceONEUEM/VMwareWorkspaceONEUEM.yml Docker image update * Updated Metadata Of Pack CiscoSMA * Added release notes to pack CiscoSMA * Packs/CiscoSMA/Integrations/CiscoSMA/CiscoSMA.yml Docker image update * Updated Metadata Of Pack FeedThreatConnect * Added release notes to pack FeedThreatConnect * Packs/FeedThreatConnect/Integrations/FeedThreatConnect/FeedThreatConnect.yml Docker image update * Updated Metadata Of Pack BitSight * Added release notes to pack BitSight * Packs/BitSight/Integrations/BitSightForSecurityPerformanceManagement/BitSightForSecurityPerformanceManagement.yml Docker image update * Updated Metadata Of Pack AWS-ILM * Added release notes to pack AWS-ILM * Packs/AWS-ILM/Integrations/AWSILM/AWSILM.yml Docker image update * Updated Metadata Of Pack CiscoWSA * Added release notes to pack CiscoWSA * Packs/CiscoWSA/Integrations/CiscoWSAV2/CiscoWSAV2.yml Docker image update * Updated Metadata Of Pack SysAid * Added release notes to pack SysAid * Packs/SysAid/Integrations/SysAid/SysAid.yml Docker image update * Updated Metadata Of Pack ManageEngine_PAM360 * Added release notes to pack ManageEngine_PAM360 * Packs/ManageEngine_PAM360/Integrations/ManageEnginePAM360/ManageEnginePAM360.yml Docker image update * Updated Metadata Of Pack CiscoUmbrellaReporting * Added release notes to pack CiscoUmbrellaReporting * Packs/CiscoUmbrellaReporting/Integrations/CiscoUmbrellaReporting/CiscoUmbrellaReporting.yml Docker image update * Fix DS108 --------- Co-authored-by: sberman <sberman@paloaltonetworks.com> * XSUP-27717/FortiSIEM (#29458) * add tests * add RN,fix,logs * Update 2_0_21.md * add period * add a name to incident * fixes CR * update docker image * delete logs * CR fixes * Update 2_0_21.md * Update FortiSIEMV2.py * reverting the Docker image (#29607) * reverting the Docker image * Update Packs/cyberark_AIM/ReleaseNotes/1_0_14.md --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29663) * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29314) * "pack contribution initial commit" * Update RoksitDNSSecurityIntegrationSarp.py * Update RoksitDNSSecurityIntegrationSarp.py * Yehuda's version * test module * readme * new logo * Update RoksitDNSSecurityIntegrationSarp.yml * Apply suggestions from code review * Update RoksitDNSSecurityIntegrationSarp_description.md * Update pack_metadata.json * Update README.md * Update pack_metadata.json * Update pack_metadata.json * Update Packs/RoksitDNSSecurityIntegration-Sarp/pack_metadata.json * fixes * change name * folder name * file names * version * rename sub folder * remove (DNSSense) from the integration name * rename folder * docker * replace image * fix image name --------- Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> * rename image --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> * add unstuck fetch stream command (#29646) * add unstuck fetch stream command * added RN * fixes * add note * cr fixes * fix conflicts * reverts * [pre-commit pycln] Align the entire repo with pycln #4 (#29665) * Fix pycln errors * Update the docker images * Run demisto-sdk pre-commit * update docker --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com> Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: sberman <sberman@paloaltonetworks.com> Co-authored-by: DinaMeylakh <72339665+DinaMeylakh@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> * If-Elif Transformer (#27763) * IfElif init * minor changes * parse single strings not json * fixed regex * fixed json bug * removed context * created eval blacklist * added json KW to eval * Update bucket-upload.yml * added ast for parsing * use hash for context grab * added value arg * quick * added unit-tests * added README.md * added RN * added flags arg; use dt for context grabbing * fixed context grabbing * added regex support * finished readme * finished readme 2 * added variables arg * changed vars to upper * changed to class * prefixed variable bug * some tests * finished unit-tests * completed tests * finished docs * finished docs in yml * new design for 'value' * unit-tests complete * docs part 1 * docs complete * added if-elif TPB * fixed TPB * fixed mypy error * fixed mypy error * fixed injection issue; added + op * name changes * added injection test in TPB * CR changes * error for unknown variables * reformat 'from_context' func * resolve conflicts * demo changes * demo changes part 2 * bug fix * updated docker * added list_compare flag * added error catcher for comp funcs * readme update; textArea for conditions * resolve conflicts * resolve conflicts * updated docker * name changes * fixed unit-tests * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * added missing flag to readme * CR changes * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * name changes * added suppres_error behaviuor to docs * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * updated docker --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * revert removal of release notes generator (#29828) * revert * validations * rn * search_and_install_packs.py - less strict when installing packs during nightly. should be reverted in (#29806) Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> * exit on error alignment.fixing echo message when exiting the uninstallation script. (#29821) * exit on error alignment. fixing echo message when exiting the uninstallation script. * installing specific poetry version (#29812) * installing specific poetry version - moving the logic to bootstrap * Cs falcon detections revert (#29833) * Revert "Cs falcon fetch limit issue (#29411)" This reverts commit f7b7d5c6 * Revert "Cs limit in idp detections (#29550)" This reverts commit 47738d56 * Added rn * Added rn * SQL Alchemy 2.x.x (#29436) * MySQL and Postgress works * MSSQL, My SQL and postgres works with bind_variables from the second form * resolve conflicts * fix CR's comments * pre commit * parsing the results * Add UT * same name and right docker * RN * sourcery * another docker image * revert docker image * Update Packs/GenericSQL/ReleaseNotes/1_0_25.md Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * fix variable name * constants * mapping instead of conditions * unskip Oracle TPB * resolve conflicts * resolve conflicts * Constants * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * CR fixes * Update Packs/GenericSQL/ReleaseNotes/1_1_0.md Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * add commit after executing a query * fix UT * remove autocommit true from MSSQL * fix UT * autocommit for MSSQL, commit for the others * commit for the others DBs, since in MSSQL is automatically * docker image --------- Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Generic playbooks fixes (#29711) * fixes for generic playbooks * fixes for generic playbooks * fixes for generic playbooks * Use Case Builder Development stage Field update (#29771) (#29825) * pushing changes to the use case stage * adding release notes * Update pack_metadata.json * Rename 1_1_0.md to 1_0_4.md * Update 1_0_4.md * Update 1_0_4.md --------- Co-authored-by: Joe Cosgrove <joecosgrove5@gmail.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> * Add mapper and disable auto extraction for ThinkstCanary (#29756) * Add Classification and Mapping to ThinkstCanary Integration * Duo Mapping Enrichment (#29139) * Updated DuoModelingRule_1_3 * Updated ModelingRules and ReleaseNotes * Updated ModelingRules and ReleaseNotes * Updated DuoModelingRule_1_3_schema and README * Rev DuoModelingRule_1_3 | add DuoModelingRule_2_0 * Updated .yml and ReleaseNotes * Updated DuoModelingRule_2_0 * Updated ReleaseNotes * Updated .yml with toversion: 8.3.0 * Updated DuoModelingRule_2_0_schema * Updated ModelingRules * Updated ReleaseNotes * Bump pack from version DuoAdminApi to 4.0.8. * Updated DuoModelingRule_1_3 * azure * Updated DuoModelingRule_2_0 * Updated DuoModelingRule_2_0 * Updated ParsingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ReleaseNotes * Updated pack_metadata * Updated pack_metadata * Updated pack_metadata * Updated README * Updated README * Updated README * Updated ReleaseNotes * Updated ReleaseNotes * Updated DuoModelingRule_2_0 * Reverted MS packs * Reverted MS packs * Updated DuoModelingRule_1_3_schema * Updated ReleaseNotes * Update Packs/DuoAdminApi/ReleaseNotes/4_0_10.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * [AWS System Manager] New Pack (#28992) * init - new pack * 2 commands * aws-ssm-inventory-entry-list * list_associations_command * remove boto stubs * remove boto stubs * improve * poetry * revert poetry * aws-ssm-association-list * aws-ssm-association-get * aws-ssm-association-get * aws-ssm-association-version-list * format * aws-ssm-document-list * ruff * ruff * ssmclient test * test * doc get * docs * Update pyproject.toml * Update poetry.lock * Update .pre-commit-config_template.yaml * regex * aws-ssm-tag-remove * improve * aws-ssm-automation-execution-list * pack * aws-ssm-command-list * aws-ssm-command-run aws-ssm-command-cancel * ruff * Apply suggestions from code review Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> * UT * UT * cr and docs * black * black and ruff * format * description * format description * pack metadata * fix ut * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * cr * cr * fix yml * add outputs * Update Packs/AWS_SystemManager/Integrations/AWSSystemManager/AWSSystemManager.py Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * fix cr * run command and fix UT * automation run * fix output add playbook * docs * docs * docs * docs * ruff and black * fix demo * fix demo * update docker and fix line to long * Apply suggestions from code review (docs) Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * cr fix * update docker * fix line * Fix an issue * Fix an issue * Update playbook description * Update docker --------- Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> * Fix splunk search in incident context (#29763) * fixes * fixes * fixes * update docker * added rn * add bc rn * Empty-Commit * Test For 'WildFire Malware' Playbook (#29404) * Test For 'WildFire Malware' Playbook * PR * RN * added the "is_mockable" config to the conf file * removed the "is_mockable" config to the conf file * Bump pack from version Core to 2.0.14. * Bump pack from version Core to 2.0.15. * Increased timeout configs * Added VirusTotal to the conf file * added virustotal instance name * changed the 'AutoContainment' playbook input config to 'true' * changed 'timeout' * changed 'timeout' * changed 'timeout' to 1600 * changed the 'ShouldCloseAutomatically' playbook input to 'false' * added the test playbook name to the playbook YML file * RN * removed the close note alert field verification * added the 'marketplacev2' to the test playbook YML file * added the '000001e7a228b2a7abdf7f7e404bc8522df32b725e86907dde32176bccbbbb27' malicious file hash to secrets ignore file. the file hash is used within the test playbook for enrichment and test purposes. --------- Co-authored-by: Content Bot <bot@demisto.com> * update docker image (#29845) * added functionallity to download index by marketplace (#29834) * added functionallity to download index by marketplace * added some logs for validation * commit * removed logs * [pre-commit MyPy] Align the entire repo with MyPy #2 (#29799) * [pre-commit MyPy] Align the entire repo with MyPy #2 * Add RN * Revert changes in 1.12.26 RN * Update the docker images * [pre-commit MyPy] Align the entire repo with MyPy #1 (#29798) * [pre-commit MyPy] Align the entire repo with MyPy #1 * Xsup 27738 DBotFindSimilarIncidents NoneType Error (#29701) * failed ut * fix * rn * pre-commit * pre commit * just the fix * fix description in yml * fix * docker * Update Packs/Base/ReleaseNotes/1_32_34.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * test * test * removed import --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Wiz v1 2 11 (#29719) * Wiz v1 2 11 (#29688) * remove redundant parenthesis * ../Packs/Wiz/Integrations/Wiz/Wiz.py * add Wiz user agent * rephrase re…
DNRRomero
pushed a commit
that referenced
this pull request
Dec 12, 2023
…#30900) * Group-IB hot fix integration (#30470) (#30878) * test commit * remove bt link * Remove A in TI for yaml and md for indicator * back yaml to default * refactor yaml with cortex utils * refactor md and yaml for feed * remove bp/domain * replace git_leak with git_repository * Add new collection Fix issue with date for TI * remove changes outside the Packs * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIB_TIA_Feed/test_data/example.json * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIB_TIA_Feed/test_data/example.json * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/test_data/example.json * update release notes * update logo * update logo * Revert "update release notes" This reverts commit fc93e44461b3085c156c42a96e3f5aaf8efbe0af. * revert microsocks * fix compromised account issue * adding RL * Update Packs/GroupIB_ThreatIntelligenceAttribution/Integrations/GroupIBTIA/GroupIBTIA.py * create release notes v1_3_12 * add test for compromised/account_group * refactor changes in playbook * fixed validation errors * adding pragma no cover * refactor RN * add urllib exception * fixing validation errors * adding pragma no cover * format * fix lint test errors * revert sentinel * revert changes to azure sentinel * fixing cloud machine ids processing (#29777) * fixing cloud machine ids processing * not exiting the installation script if we fail to install a pack. report an error but continue with the test playbook upload (#29759) * Microsoft DNS Parsing Rule Drop (#29765) * Updated ParsingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ReleaseNotes * Updated pack_metadata * Updated pack_metadata * Updated pack_metadata * Updated README * Updated README * Updated README * [JoeSecurity] Pre-Commit (#29717) * [pre-commit ruff] Align the entire repo with ruff #2 (#29754) * [pre-commit ruff] Align the entire repo with ruff #2 * Add RN * Update the docker image * Don't checkout build files in pre-commit (#27900) * is file up to date pre-commit * Revert changes made by mistake --------- * Fixes for 'NGFW Scan' and 'WildFire Malware' XSIAM playbooks (#29774) * Fixes for 'NGFW Scan' and 'WildFire Malware' XSIAM playbooks * RN * fixed RN and 'NGFW Scan playbook' * CiscoSMA- Added timeout parameter (#29372) * fix * add_tests * fix_test_description * fix_yml_add_readme * fixes - add timeout to the client * add timeout to yml * revert changes * Update CiscoSMA.py * Update CiscoSMA.py * CR review * add RN * fix CR review * update docker image * XSUP-27956/ Added EWS PS V3 Description (#29784) * updated the description * update rn * Apply suggestions from code review --------- * Xsup 27738 DBotFindSimilarIncidents NoneType Error (#29701) * failed ut * fix * rn * pre-commit * pre commit * just the fix * fix description in yml * fix * docker * Update Packs/Base/ReleaseNotes/1_32_34.md * test * test * removed import --------- * Wiz v1 2 11 (#29719) * Wiz v1 2 11 (#29688) * remove redundant parenthesis * ../Packs/Wiz/Integrations/Wiz/Wiz.py * add Wiz user agent * rephrase release notes * update pack metadata json * rephrase release notes v2 * fix minor typos and update docker image * Bump Docker version --------- * [ASM] - Expander - Update ASM fields (4821) (#29702) * [ASM] - Expander - Update ASM fields (4821) (#29506) * Add missing comments to grid fields - Update descriptions of fields as needed. * Add release notes * Add descriptions to two fields - asmdevcheckdetails - asmenrichmentstatus * Update release notes. * Grammar updates. * Update release notes * Add mandatory or optional in comments * Update comments with mandatory * Update pack version and release notes * Add correct 1_6_33 release notes * fix rn * fix rn --------- * Wildfire-upload-url add poling timeout argument (#29790) * save adding timeout param * new docker image * added rn * fix ruff * ruff made me to do this fixes :( not related to my changes * Update Packs/Palo_Alto_Networks_WildFire/ReleaseNotes/2_1_35.md * poetry files (#29793) * Dra-cvss-color-fix (#29757) * Fixed a small issue when indicator had no custom fields * RN * docker bump * RN * Update CVECVSSColor.py * docker bump * RN * fixing typos in build scripts. (#29788) unremovable -> non-removable productname -> product_name testplaybook -> test_playbook changed some arg passing to use their full name: -gpidd -gpidp * mapping to standard stix values (#29785) * mapping to standard stix values * updated release notes * update docker * breaking json * add dot * Add the nightly_ruff file for run pre-commit with --all flag (#29684) * Add the nightly_ruff file for run pre-commit with --all flag * Add more rules; Add the error name * Add E501 * Add F601, F842, TID252 * XSUP-27528 (#29705) * add_tests * add_tests * add RN, fix tests, format yml * Update Packs/CommonScripts/ReleaseNotes/1_12_24.md * fix readme * Bump pack from version CommonScripts to 1.12.25. --------- * [Axonius Content Pack 1.2.0] Bumping Dockerfile (#29802) * [Axonius Content Pack 1.2.0] Bumping Dockerfile (#29625) * bumped docker version for axonius api client * docker image * remove the - --------- * format --------- * Updated native:8.4 image; Add auth-utils support (#29792) * Fixed sc_task closing state (#29636) * Fixed sc_task closing state * Added release notes * Updated docker image * small fix * bumped dokcer * fixed rn --------- * Private Compliance Packs (#29664) * XSUP-27936 problem with regex (#29613) * failed test * fix * rn * rn * unit test * ut * validations * fixed test and docker * fix * validation * Prisma Cloud V2 Add "usernames" Argument (#29710) * add username arg * support list * update UT * update README * docker update * update TPB * Fortinet fortigate enhancement (#29655) * Updated the readme for proofpoint fortigate. * Modified the modeling rule. * Modified the modeling rule and the schema file. * Updated the release note. * Update Packs/FortiGate/README.md * Updated the modeling rule. * Added tags to the readme. * removed ftntfgtmastersrcmac and ftntfgtmasterdstmac from the mapping. * updated the modeling rule and the schema file. * updated the modeling rule * updated the modeling rule --------- * Add syslog example for War Room Actions (#29800) * Graph Security Update (#29797) * Updated MicrosoftGraphSecurity_schema * Updated ReleaseNotes * Updated ReleaseNotes * [Dataminr Pulse] Release 106 (#29805) * [Dataminr Pulse] Release 106 (#29693) * Changes related to release v1.0.6 * Changes related to release v1.0.6 * Fixing Release Note related issue --------- * Bump Docker version --------- * [RecordedFuture] threat actor playbook update V2.5.1 (#29690) (#29807) * Update Threat actor search playbook. * Add release notes * Fix formatting * Change ExtractedIndicators to ExtractedIndicators\.File * Fix release notes --------- * [JoeSecurity] show partial result in polling commands (#29715) * updating build docker image to latest devdemisto/gitlab-content-ci:1.0.0.64455 (#29761) * updating build docker image to latest devdemisto/gitlab-content-ci:1.0.0.64455 * Private Upload Mode - ThreatExchange v2 (#28249) * ThreatExchange integration * ThreatExchange updates * Added param to instance configuration * pre-commit * updated RN * RN test * CR updates * Removed Threat_Crowd * Update Packs/ThreatExchange/ReleaseNotes/2_0_12.md * docker * format * skip tests since theres no instance * no testing instance --------- * added plus 1 for each iteration in find destination (#29811) * added plus 1 for each iteration in find destination (#29760) * added plus 1 for each iteration in find destination * added release notes * Update Packs/Cisco-umbrella-cloud-security/ReleaseNotes/2_0_2.md * updated docker image tag to latest * updated unit test for pagination functions * removed comments --------- * Update 2_0_2.md --------- * Mde list indicator filter (#29640) * Mde list indicator filter (#29338) * init indicator filter * release notes * latest docker image * updated docker image * minor fixes * reslove conflicts * resolve version conflicts * silence linter * format * docker * Apply suggestions from Shirley * add period * change phrase * adding "is_mockable": false * docker * try change test playbook * empty line * docker * return the mock * Revert "return the mock" This reverts commit da9baeff5cadddf2cd125fb073c266c867f465a5. --------- * Audit Logs Endpoints Scripts Aligments for Xsoar-8 (#29781) * test * fix core api * ExportAuditLogsToFile - add support for xsoar-8 * add ExportAuditLogsToFile UTs * add forward audit logs uts * update ut * validation fixes * mypy * bump rns * update docker * update docker image * fix ut * format * Bump pack from version CommonScripts to 1.12.25. * Bump pack from version CommonScripts to 1.12.26. * cr * cr fixes * update * fix uts --------- * Add command prisma-cloud-compute-get-file-integrity-events (#29608) * Add command prisma-cloud-compute-get-file-integrity-events (#29187) * Add command prisma-cloud-compute-get-file-integrity-events * Incorporate changes from review comments. Add documentation and unit test. * Add missing lines to YML file (add description of new command) * Update docker image * Incorporate changes from demo * Update docker image * fix validation * fix validation --------- * Bump pack from version PrismaCloudCompute to 1.4.10. * [pre-commit ruff] Align the entire repo with ruff (#29603) * Fix falls of the ruff hook * pre-commit * Fix B003 ruff error * Fix ruff errors on Utils/update_playbook.py * remove code to trigger upload on dev branches (#29621) * [pre-commit pycln] Align the entire repo with pycln (#29611) * Fix falls of the pycln hook * pre-commit * Fix unit test * Add RN * Fix validate in GetDomainDNSDetails * fuff on GetDomainDNSDetails * ignore mypy error in test_content.py:350 * Fix falls of the autopep8 hook (#29638) * add marketplaces to metadata (#29629) * Fixing AWS Project Number in ASM Cloud (#29593) (#29642) * [MS Teams] support reset_graph_auth (#29644) * fixed * pre-commit * update * Recordedfuture threathunting v2.5.0 (#29641) * Recordedfuture threathunting v2.5.0 (#29025) * Add commands related to Automated Threat hunting recordedfuture-threat-map recordedfuture-threat-links recordedfuture-detection-rules * Add recordedfuture-collective-insight command. Change app version. * Update README.md. Add release notes * Add playbook. Add unittests * Add unittests * Fix test_collective_insight_command * Remove incorrect release note * Add documentation for threat actor search playbook * update Recorded Future Threat actor search playbook. add release note about new playbook. * Update release notes, fix formatting * Format yml files * Update Recorded future threat actor search playbook * Update docker image * Fix linter --------- * Minor README fixes --------- * [ASM] Expander 5777 (#29647) * [ASM] Expander 5777 (#29619) * first * RN * Bump pack from version CortexAttackSurfaceManagement to 1.6.36. --------- * XDR Malware Enrichment - hotfix for usernames (split) (#29585) * Updated playbook with hotfix where we split usernames from domains and append them to the username list of usernames for account enrichment * Added RN * remove irrelevant test * Updated RN * Bump pack from version CortexXDR to 5.1.6. * Update Packs/CortexXDR/ReleaseNotes/5_1_6.md --------- * Update Docker Image To demisto/pyjwt3 (#29656) * Updated Metadata Of Pack Silverfort * Added release notes to pack Silverfort * Packs/Silverfort/Integrations/Silverfort/Silverfort.yml Docker image update * Update Docker Image To demisto/trustar (#29660) * Updated Metadata Of Pack TruSTAR * Added release notes to pack TruSTAR * Update Docker Image To demisto/keeper-ksm (#29661) * Updated Metadata Of Pack KeeperSecretsManager * Added release notes to pack KeeperSecretsManager * Packs/KeeperSecretsManager/Integrations/KeeperSecretsManager/KeeperSecretsManager.yml Docker image update * Update Docker Image To demisto/py3-tools (#29654) * Updated Metadata Of Pack Intezer * Added release notes to pack Intezer * Packs/Intezer/Integrations/IntezerV2/IntezerV2.yml Docker image update * Updated Metadata Of Pack FeedMalwareBazaar * Added release notes to pack FeedMalwareBazaar * Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update * Updated Metadata Of Pack FeedGCPWhitelist * Added release notes to pack FeedGCPWhitelist * Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update * Updated Metadata Of Pack AccentureCTI_Feed * Added release notes to pack AccentureCTI_Feed * Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update * Fix DS108 --------- * Update Docker Image To demisto/taxii-server (#29659) * Updated Metadata Of Pack CybleThreatIntel * Added release notes to pack CybleThreatIntel * Packs/CybleThreatIntel/Integrations/CybleThreatIntel/CybleThreatIntel.yml Docker image update * Fix DS108 --------- * Update Docker Image To demisto/datadog-api-client (#29662) * Updated Metadata Of Pack DatadogCloudSIEM * Added release notes to pack DatadogCloudSIEM * Packs/DatadogCloudSIEM/Integrations/DatadogCloudSIEM/DatadogCloudSIEM.yml Docker image update * Fix DS108 --------- * Add reliability parameter to cves and pipl integration (#28703) * commiting PrismaCloudCompute * release notes added * changed couldcompute, CVESearchV2, pipl * added pack metadata * fixed pipl readme * reverting changes in CVESearch since it was deprecated * removed redundant * committing pre commit changes * added known words * added known words * fixed lint error * changed according to review * updated docker version in PrismaCloudCompute * changed according to doc review * Added condition for not receiving new incidents in the test playbook * updating release notes * reverting fetch changes * fixed playbook * formatted playbook * new validation, new run * new validation, new run * Bump pack from version PrismaCloudCompute to 1.4.10. * update the docker image --------- * Proofpoint email security pack: update description (#29651) * update description * Updated the schema file. * Updated the schema file. --------- * Jira v2 deprecated (#29649) * Deprecate to jira v2 * update RN * update conf.json file * add task to the Create Jira Issue playbook that check if jira v3 is enable * add image.png of the playbook * update the playbook (yml, readme, image) and RN * Update Docker Image To demisto/python3 (#29652) * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack VMwareWorkspaceONEUEM * Added release notes to pack VMwareWorkspaceONEUEM * Packs/VMwareWorkspaceONEUEM/Integrations/VMwareWorkspaceONEUEM/VMwareWorkspaceONEUEM.yml Docker image update * Updated Metadata Of Pack CiscoSMA * Added release notes to pack CiscoSMA * Packs/CiscoSMA/Integrations/CiscoSMA/CiscoSMA.yml Docker image update * Updated Metadata Of Pack FeedThreatConnect * Added release notes to pack FeedThreatConnect * Packs/FeedThreatConnect/Integrations/FeedThreatConnect/FeedThreatConnect.yml Docker image update * Updated Metadata Of Pack BitSight * Added release notes to pack BitSight * Packs/BitSight/Integrations/BitSightForSecurityPerformanceManagement/BitSightForSecurityPerformanceManagement.yml Docker image update * Updated Metadata Of Pack AWS-ILM * Added release notes to pack AWS-ILM * Packs/AWS-ILM/Integrations/AWSILM/AWSILM.yml Docker image update * Updated Metadata Of Pack CiscoWSA * Added release notes to pack CiscoWSA * Packs/CiscoWSA/Integrations/CiscoWSAV2/CiscoWSAV2.yml Docker image update * Updated Metadata Of Pack SysAid * Added release notes to pack SysAid * Packs/SysAid/Integrations/SysAid/SysAid.yml Docker image update * Updated Metadata Of Pack ManageEngine_PAM360 * Added release notes to pack ManageEngine_PAM360 * Packs/ManageEngine_PAM360/Integrations/ManageEnginePAM360/ManageEnginePAM360.yml Docker image update * Updated Metadata Of Pack CiscoUmbrellaReporting * Added release notes to pack CiscoUmbrellaReporting * Packs/CiscoUmbrellaReporting/Integrations/CiscoUmbrellaReporting/CiscoUmbrellaReporting.yml Docker image update * Fix DS108 --------- * XSUP-27717/FortiSIEM (#29458) * add tests * add RN,fix,logs * Update 2_0_21.md * add period * add a name to incident * fixes CR * update docker image * delete logs * CR fixes * Update 2_0_21.md * Update FortiSIEMV2.py * reverting the Docker image (#29607) * reverting the Docker image * Update Packs/cyberark_AIM/ReleaseNotes/1_0_14.md --------- * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29663) * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29314) * "pack contribution initial commit" * Update RoksitDNSSecurityIntegrationSarp.py * Update RoksitDNSSecurityIntegrationSarp.py * Yehuda's version * test module * readme * new logo * Update RoksitDNSSecurityIntegrationSarp.yml * Apply suggestions from code review * Update RoksitDNSSecurityIntegrationSarp_description.md * Update pack_metadata.json * Update README.md * Update pack_metadata.json * Update pack_metadata.json * Update Packs/RoksitDNSSecurityIntegration-Sarp/pack_metadata.json * fixes * change name * folder name * file names * version * rename sub folder * remove (DNSSense) from the integration name * rename folder * docker * replace image * fix image name --------- * rename image --------- * add unstuck fetch stream command (#29646) * add unstuck fetch stream command * added RN * fixes * add note * cr fixes * fix conflicts * reverts * [pre-commit pycln] Align the entire repo with pycln #4 (#29665) * Fix pycln errors * Update the docker images * Run demisto-sdk pre-commit * Remove unnecessary recommendations from extensions.json (#29605) * update extensions.json * Update devcontainer.json * Update recommendations list * Zscaler-FW-Logs (#29094) * Zscaler FW Logs Modeling Rules * Zscaler FW logs Modeling Rules * Updated README * Updated ZscalerModelingRule_1_3 * Changed cs5 field name to cat * Apply suggestions from code review * Updated README * Updated ModelingRules and Schema * Updated ModelingRules and schema * Updated ModelingRules * Updated ModelingRules --------- * PANOS - EXPANDR-5744 (#29223) (#29686) * playbook updates * RN, Readme, screenshot * Apply suggestions from code review * update RN * bump ver * more descriptive task * bump ver --------- * Audit alert fields fix (#29685) * Add associated types to systemAssociatedTypes * Add associated types to systemAssociatedTypes * fix incident field structure * RN * Workday documentation fix (#29681) * readme * readme * rn * rn * [Marketplace Contribution] Active Directory Query - Content Pack Update (#28633) * [Marketplace Contribution] Active Directory Query - Content Pack Update (#27822) * "contribution update to pack "Active Directory Query"" * revert changes * rl * remove files * removed from rl * Update pack_metadata.json * Create 1_6_19.md * Update 1_6_18.md * Update 1_6_19.md * Delete 1_6_19.md * Update 1_6_18.md * Update pack_metadata.json * Update Active_Directory_Query.yml removed duplicate section and type * pass SERVER_IP as argument to test_credentials function * Create 1_7_0.md * Update pack_metadata.json * Update README.md with ad-test-credentials info * Update Active_Directory_Query.yml * removed duplicate `type: 8` from ntlm * removed duplicate types from integration settings * removed duplicate description from ad-enable-account * Update Active_Directory_Query.yml * Update Active_Directory_Query.yml * Update Active_Directory_Query.yml * removing not relevant release note * adding function * update fucntion * cr note * adding NTLM_AUTH option * Update Active_Directory_Query.py * Update Packs/Active_Directory_Query/Integrations/Active_Directory_Query/Active_Directory_Query.py * cr notes * update after merging from master * reverting a change in olr rl * added test_test_credentials unit test function * fix unit test * fixing unit tests * fix unit test * fixed lint errors * Update Active_Directory_Query_test.py * empty commit * fix yml and docker file * revert changes in send email manager * fix yml * fix * fix validation error * fixing in129 --------- * cr notes * Bump pack from version Active_Directory_Query to 1.6.21. * fix yml changes * cr notes * lint fixes * fix test * docker update * Update Packs/Active_Directory_Query/Integrations/Active_Directory_Query/README.md * fix delete required * Apply suggestions from code review * fix test * docker update * rl * empty commit * docker update * empty commit * empty commit * merge from master * empty commit check * revert changes * Delete Packs/cyberark_AIM/Integrations/CyberArkAIM_v2/integration-CyberArkAIM_v2.yml * docker downgrade * rl * trying new docker image * validate errors fix * revert docker version * [DS108] - Description must end with a period (".") - fix * empty commit check * empty commit check --------- * Big query bug xsup 28132 (#29680) * bug fix * rn * rn * Apply suggestions from code review * format * pre commit --------- * New Prisma Cloud v2 commands (#29323) * resource list command * limit results * user roles list command * pre commit * users list command * edit remediation commands * UTs * update README * update RN * pre commit fixes * edit test playbook * CR changes * Demo changes - remediate 406 raises error new args for resource_list & user_roles * fix test * Apply suggestions from doc review * fix test playbook * Tomer's changes --------- * Prisma Cloud Update (#29666) * Updated ModelingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ModelingRules * Updated ModelingRules * Updated ModelingRules * Bump pack from version PrismaCloud to 4.2.4. --------- * Rapid7 appsec (#29134) (#29687) * Revert "Add space to conf" This reverts commit 3a74b931d31ae2b33e0e4570c7df7d06c668e9c8. * Updated the packs category to *Authentication & Identity Management* (part 2) (#24876) * Update Docker Image To demisto/fastapi (#24923) * Updated Metadata Of Pack CyberArkIdentity * Added release notes to pack CyberArkIdentity * Packs/CyberArkIdentity/Integrations/CyberArkIdentityEventCollector/CyberArkIdentityEventCollector.yml Docker image update * Update Docker Image To demisto/lxml (#24924) * Updated Metadata Of Pack TaniumThreatResponse * Added release notes to pack TaniumThreatResponse * Packs/TaniumThreatResponse/Integrations/TaniumThreatResponseV2/TaniumThreatResponseV2.yml Docker image update * Update Docker Image To demisto/crypto (#24922) * Updated Metadata Of Pack X509Certificate * Added release notes to pack X509Certificate * Packs/X509Certificate/Scripts/CertificateExtract/CertificateExtract.yml Docker image update * Update Docker Image To demisto/python3 (#24921) * Updated Metadata Of Pack Cybereason * Added release notes to pack Cybereason * Packs/Cybereason/Integrations/Cybereason/Cybereason.yml Docker image update * Updated Metadata Of Pack DNSDB * Added release notes to pack DNSDB * Packs/DNSDB/Integrations/DNSDB_v2/DNSDB_v2.yml Docker image update * Updated Metadata Of Pack DeepInstinct * Added release notes to pack DeepInstinct * Packs/DeepInstinct/Integrations/DeepInstinct3x/DeepInstinct3x.yml Docker image update * Updated Metadata Of Pack FeedCyrenThreatInDepth * Added release notes to pack FeedCyrenThreatInDepth * Packs/FeedCyrenThreatInDepth/Integrations/CyrenThreatInDepth/CyrenThreatInDepth.yml Docker image update * Updated Metadata Of Pack IronDefense * Added release notes to pack IronDefense * Packs/IronDefense/Integrations/IronDefense/IronDefense.yml Docker image update * Updated Metadata Of Pack Qintel * Added release notes to pack Qintel * Packs/Qintel/Integrations/QintelPMI/QintelPMI.yml Docker image update * Packs/Qintel/Integrations/QintelQSentry/QintelQSentry.yml Docker image update * Packs/Qintel/Integrations/QintelQWatch/QintelQWatch.yml Docker image update * Updated Metadata Of Pack QualysFIM * Added release notes to pack QualysFIM * Packs/QualysFIM/Integrations/QualysFIM/QualysFIM.yml Docker image update * Updated Metadata Of Pack QutteraWebsiteMalwareScanner * Added release notes to pack QutteraWebsiteMalwareScanner * Packs/QutteraWebsiteMalwareScanner/Integrations/QutteraWebsiteMalwareScanner/QutteraWebsiteMalwareScanner.yml Docker image update * Fixed mypy + validation --------- * NGINXApiModule: fix logging typo (#24878) * fix logging typo * bump dependent packs --------- * Downgrade docker to fix banner issue (#24905) * Downgrade docker to fix banner issue * Fix docs * Add UT to prevent Docker bump * Fix yml validation * Adding vulnerability commands * Fixing pagination page index * Updating PR comments and Scan commands * Updating ID in test data. * Updating integration * Updating integration * Updating fromversion * Updating linters * Updating linters * Updating git pre-commit * Updating docstring * Updating the handling of request when limit * Removing get_pagination_params * Updating integration * Updating git-pre commit * Updating integration * Updating integration * Updating unit test * Updating docker image * Updating integration * Updating README version. * Updating secrets * Updating integration * Updating integration * Updating integration * Updating docstrings * Updating doc-review comments. * Updating doc-review comments. * Updating description --------- * Panos add param (#29672) * added param job_polling_max_num_attempts * Added rn * Added missing param type Fixed unit tests * added to readme * fixed readme * Update Packs/PAN-OS/Integrations/Panorama/Panorama.yml * fixed text and namings * Bump pack from version PAN-OS to 2.1.8. --------- * Fix proxy usage (#85) (#29630) * Fix proxy usage (#85) (#29181) * Fix proxy usage (#85) * Fix proxy usage in ZF client * Fix variable USE_SSL to verify requests * Remove proxy object from client Given that the proxy works by default with env vars, the proxy object is not necessary * Update version and add release notes * Fix call to modified alerts (#86) * Fix call to modified alerts * Update docker image * Fix tests associated with get modified data * change rn * fix validation --------- * Missing dependencies when installing packs (#28989) * search and install packs --------- * Deprecate Picus Community (#29573) * Merge branch 'master' into github_workflow_partner # Conflicts: # Utils/github_workflow_scripts/utils.py * Merge branch 'master' into github_workflow_partner # Conflicts: # Utils/github_workflow_scripts/utils.py * Picus NG display name * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update * Picus update --------- * [ASM] - Expander - GCP Hierarchy field - 4376 (#29696) (#29704) * Add assethierarchy field to GCP ASM playbook * Add release notes * Update field json * fix merge * update rn * remove access code * fix conflicts * update docker * fix validation --------- * [Marketplace Contribution] Okta - Content Pack Update (#29650) * [Marketplace Contribution] Okta - Content Pack Update (#29303) * "contribution update to pack "Okta"" * minor fixes * add outputs and readme * add outputs description * update docker * change outputs --------- * Fixing AWS Project Number in ASM Cloud (#29593) (#29642) * [MS Teams] support reset_graph_auth (#29644) * fixed * pre-commit * update * Recordedfuture threathunting v2.5.0 (#29641) * Recordedfuture threathunting v2.5.0 (#29025) * Add commands related to Automated Threat hunting recordedfuture-threat-map recordedfuture-threat-links recordedfuture-detection-rules * Add recordedfuture-collective-insight command. Change app version. * Update README.md. Add release notes * Add playbook. Add unittests * Add unittests * Fix test_collective_insight_command * Remove incorrect release note * Add documentation for threat actor search playbook * update Recorded Future Threat actor search playbook. add release note about new playbook. * Update release notes, fix formatting * Format yml files * Update Recorded future threat actor search playbook * Update docker image * Fix linter --------- * Minor README fixes --------- * [ASM] Expander 5777 (#29647) * [ASM] Expander 5777 (#29619) * first * RN * Bump pack from version CortexAttackSurfaceManagement to 1.6.36. --------- * XDR Malware Enrichment - hotfix for usernames (split) (#29585) * Updated playbook with hotfix where we split usernames from domains and append them to the username list of usernames for account enrichment * Added RN * remove irrelevant test * Updated RN * Bump pack from version CortexXDR to 5.1.6. * Update Packs/CortexXDR/ReleaseNotes/5_1_6.md --------- * Update Docker Image To demisto/pyjwt3 (#29656) * Updated Metadata Of Pack Silverfort * Added release notes to pack Silverfort * Packs/Silverfort/Integrations/Silverfort/Silverfort.yml Docker image update * Update Docker Image To demisto/trustar (#29660) * Updated Metadata Of Pack TruSTAR * Added release notes to pack TruSTAR * Update Docker Image To demisto/keeper-ksm (#29661) * Updated Metadata Of Pack KeeperSecretsManager * Added release notes to pack KeeperSecretsManager * Packs/KeeperSecretsManager/Integrations/KeeperSecretsManager/KeeperSecretsManager.yml Docker image update * Update Docker Image To demisto/py3-tools (#29654) * Updated Metadata Of Pack Intezer * Added release notes to pack Intezer * Packs/Intezer/Integrations/IntezerV2/IntezerV2.yml Docker image update * Updated Metadata Of Pack FeedMalwareBazaar * Added release notes to pack FeedMalwareBazaar * Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update * Updated Metadata Of Pack FeedGCPWhitelist * Added release notes to pack FeedGCPWhitelist * Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update * Updated Metadata Of Pack AccentureCTI_Feed * Added release notes to pack AccentureCTI_Feed * Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update * Fix DS108 --------- * Update Docker Image To demisto/taxii-server (#29659) * Updated Metadata Of Pack CybleThreatIntel * Added release notes to pack CybleThreatIntel * Packs/CybleThreatIntel/Integrations/CybleThreatIntel/CybleThreatIntel.yml Docker image update * Fix DS108 --------- * Update Docker Image To demisto/datadog-api-client (#29662) * Updated Metadata Of Pack DatadogCloudSIEM * Added release notes to pack DatadogCloudSIEM * Packs/DatadogCloudSIEM/Integrations/DatadogCloudSIEM/DatadogCloudSIEM.yml Docker image update * Fix DS108 --------- * Add reliability parameter to cves and pipl integration (#28703) * commiting PrismaCloudCompute * release notes added * changed couldcompute, CVESearchV2, pipl * added pack metadata * fixed pipl readme * reverting changes in CVESearch since it was deprecated * removed redundant * committing pre commit changes * added known words * added known words * fixed lint error * changed according to review * updated docker version in PrismaCloudCompute * changed according to doc review * Added condition for not receiving new incidents in the test playbook * updating release notes * reverting fetch changes * fixed playbook * formatted playbook * new validation, new run * new validation, new run * Bump pack from version PrismaCloudCompute to 1.4.10. * update the docker image --------- * Proofpoint email security pack: update description (#29651) * update description * Updated the schema file. * Updated the schema file. --------- * Jira v2 deprecated (#29649) * Deprecate to jira v2 * update RN * update conf.json file * add task to the Create Jira Issue playbook that check if jira v3 is enable * add image.png of the playbook * update the playbook (yml, readme, image) and RN * Update Docker Image To demisto/python3 (#29652) * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack VMwareWorkspaceONEUEM * Added release notes to pack VMwareWorkspaceONEUEM * Packs/VMwareWorkspaceONEUEM/Integrations/VMwareWorkspaceONEUEM/VMwareWorkspaceONEUEM.yml Docker image update * Updated Metadata Of Pack CiscoSMA * Added release notes to pack CiscoSMA * Packs/CiscoSMA/Integrations/CiscoSMA/CiscoSMA.yml Docker image update * Updated Metadata Of Pack FeedThreatConnect * Added release notes to pack FeedThreatConnect * Packs/FeedThreatConnect/Integrations/FeedThreatConnect/FeedThreatConnect.yml Docker image update * Updated Metadata Of Pack BitSight * Added release notes to pack BitSight * Packs/BitSight/Integrations/BitSightForSecurityPerformanceManagement/BitSightForSecurityPerformanceManagement.yml Docker image update * Updated Metadata Of Pack AWS-ILM * Added release notes to pack AWS-ILM * Packs/AWS-ILM/Integrations/AWSILM/AWSILM.yml Docker image update * Updated Metadata Of Pack CiscoWSA * Added release notes to pack CiscoWSA * Packs/CiscoWSA/Integrations/CiscoWSAV2/CiscoWSAV2.yml Docker image update * Updated Metadata Of Pack SysAid * Added release notes to pack SysAid * Packs/SysAid/Integrations/SysAid/SysAid.yml Docker image update * Updated Metadata Of Pack ManageEngine_PAM360 * Added release notes to pack ManageEngine_PAM360 * Packs/ManageEngine_PAM360/Integrations/ManageEnginePAM360/ManageEnginePAM360.yml Docker image update * Updated Metadata Of Pack CiscoUmbrellaReporting * Added release notes to pack CiscoUmbrellaReporting * Packs/CiscoUmbrellaReporting/Integrations/CiscoUmbrellaReporting/CiscoUmbrellaReporting.yml Docker image update * Fix DS108 --------- * XSUP-27717/FortiSIEM (#29458) * add tests * add RN,fix,logs * Update 2_0_21.md * add period * add a name to incident * fixes CR * update docker image * delete logs * CR fixes * Update 2_0_21.md * Update FortiSIEMV2.py * reverting the Docker image (#29607) * reverting the Docker image * Update Packs/cyberark_AIM/ReleaseNotes/1_0_14.md --------- * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29663) * [Marketplace Contribution] Roksit DNS Security Integration - Sarp (#29314) * "pack contribution initial commit" * Update RoksitDNSSecurityIntegrationSarp.py * Update RoksitDNSSecurityIntegrationSarp.py * Yehuda's version * test module * readme * new logo * Update RoksitDNSSecurityIntegrationSarp.yml * Apply suggestions from code review * Update RoksitDNSSecurityIntegrationSarp_description.md * Update pack_metadata.json * Update README.md * Update pack_metadata.json * Update pack_metadata.json * Update Packs/RoksitDNSSecurityIntegration-Sarp/pack_metadata.json * fixes * change name * folder name * file names * version * rename sub folder * remove (DNSSense) from the integration name * rename folder * docker * replace image * fix image name --------- * rename image --------- * add unstuck fetch stream command (#29646) * add unstuck fetch stream command * added RN * fixes * add note * cr fixes * fix conflicts * reverts * [pre-commit pycln] Align the entire repo with pycln #4 (#29665) * Fix pycln errors * Update the docker images * Run demisto-sdk pre-commit * update docker --------- * If-Elif Transformer (#27763) * IfElif init * minor changes * parse single strings not json * fixed regex * fixed json bug * removed context * created eval blacklist * added json KW to eval * Update bucket-upload.yml * added ast for parsing * use hash for context grab * added value arg * quick * added unit-tests * added README.md * added RN * added flags arg; use dt for context grabbing * fixed context grabbing * added regex support * finished readme * finished readme 2 * added variables arg * changed vars to upper * changed to class * prefixed variable bug * some tests * finished unit-tests * completed tests * finished docs * finished docs in yml * new design for 'value' * unit-tests complete * docs part 1 * docs complete * added if-elif TPB * fixed TPB * fixed mypy error * fixed mypy error * fixed injection issue; added + op * name changes * added injection test in TPB * CR changes * error for unknown variables * reformat 'from_context' func * resolve conflicts * demo changes * demo changes part 2 * bug fix * updated docker * added list_compare flag * added error catcher for comp funcs * readme update; textArea for conditions * resolve conflicts * resolve conflicts * updated docker * name changes * fixed unit-tests * Apply suggestions from code review * added missing flag to readme * CR changes * Apply suggestions from code review * name changes * added suppres_error behaviuor to docs * Apply suggestions from code review * updated docker --------- * revert removal of release notes generator (#29828) * revert * validations * rn * search_and_install_packs.py - less strict when installing packs during nightly. should be reverted in (#29806) * exit on error alignment.fixing echo message when exiting the uninstallation script. (#29821) * exit on error alignment. fixing echo message when exiting the uninstallation script. * installing specific poetry version (#29812) * installing specific poetry version - moving the logic to bootstrap * Cs falcon detections revert (#29833) * Revert "Cs falcon fetch limit issue (#29411)" This reverts commit f7b7d5c6 * Revert "Cs limit in idp detections (#29550)" This reverts commit 47738d56 * Added rn * Added rn * SQL Alchemy 2.x.x (#29436) * MySQL and Postgress works * MSSQL, My SQL and postgres works with bind_variables from the second form * resolve conflicts * fix CR's comments * pre commit * parsing the results * Add UT * same name and right docker * RN * sourcery * another docker image * revert docker image * Update Packs/GenericSQL/ReleaseNotes/1_0_25.md * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py * fix variable name * constants * mapping instead of conditions * unskip Oracle TPB * resolve conflicts * resolve conflicts * Constants * Update Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.py * CR fixes * Update Packs/GenericSQL/ReleaseNotes/1_1_0.md * add commit after executing a query * fix UT * remove autocommit true from MSSQL * fix UT * autocommit for MSSQL, commit for the others * commit for the others DBs, since in MSSQL is automatically * docker image --------- * Generic playbooks fixes (#29711) * fixes for generic playbooks * fixes for generic playbooks * fixes for generic playbooks * Use Case Builder Development stage Field update (#29771) (#29825) * pushing changes to the use case stage * adding release notes * Update pack_metadata.json * Rename 1_1_0.md to 1_0_4.md * Update 1_0_4.md * Update 1_0_4.md --------- * Add mapper and disable auto extraction for ThinkstCanary (#29756) * Add Classification and Mapping to ThinkstCanary Integration * Duo Mapping Enrichment (#29139) * Updated DuoModelingRule_1_3 * Updated ModelingRules and ReleaseNotes * Updated ModelingRules and ReleaseNotes * Updated DuoModelingRule_1_3_schema and README * Rev DuoModelingRule_1_3 | add DuoModelingRule_2_0 * Updated .yml and ReleaseNotes * Updated DuoModelingRule_2_0 * Updated ReleaseNotes * Updated .yml with toversion: 8.3.0 * Updated DuoModelingRule_2_0_schema * Updated ModelingRules * Updated ReleaseNotes * Bump pack from version DuoAdminApi to 4.0.8. * Updated DuoModelingRule_1_3 * azure * Updated DuoModelingRule_2_0 * Updated DuoModelingRule_2_0 * Updated ParsingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ReleaseNotes * Updated pack_metadata * Updated pack_metadata * Updated pack_metadata * Updated README * Updated README * Updated README * Updated ReleaseNotes * Updated ReleaseNotes * Updated DuoModelingRule_2_0 * Reverted MS packs * Reverted MS packs * Updated DuoModelingRule_1_3_schema * Updated ReleaseNotes * Update Packs/DuoAdminApi/ReleaseNotes/4_0_10.md --------- * [AWS System Manager] New Pack (#28992) * init - new pack * 2 commands * aws-ssm-inventory-entry-list * list_associations_command * remove boto stubs * remove boto stubs * improve * poetry * revert poetry * aws-ssm-association-list * aws-ssm-association-get * aws-ssm-association-get * aws-ssm-association-version-list * format * aws-ssm-document-list * ruff * ruff * ssmclient test * test * doc get * docs * Update pyproject.toml * Update poetry.lock * Update .pre-commit-config_template.yaml * regex * aws-ssm-tag-remove * improve * aws-ssm-automation-execution-list * pack * aws-ssm-command-list * aws-ssm-command-run aws-ssm-command-cancel * ruff * Apply suggestions from code review * Apply suggestions from code review * UT * UT * cr and docs * black * black and ruff * format * description * format description * pack metadata * fix ut * Apply suggestions from code review * Apply suggestions from code review * cr * cr * fix yml * add outputs * Update Packs/AWS_SystemManager/Integrations/AWSSystemManager/AWSSystemManager.py * fix cr * run command and fix UT * automation run * fix output add playbook * docs * docs * docs * docs * ruff and black * fix demo * fix demo * update docker and fix line to long * Apply suggestions from code review (docs) * cr fix * update docker * fix line * Fix an issue * Fix an issue * Update playbook description * Update docker --------- * Fix splunk search in incident context (#29763) * fixes * fixes * fixes * update docker * added rn * add bc rn * Empty-Commit * Test For 'WildFire Malware' Playbook (#29404) * Test For 'WildFire Malware' Playbook * PR * RN * added the "is_mockable" config to the conf file * removed the "is_mockable" config to the conf file * Bump pack from version Core to 2.0.14. * Bump pack from version Core to 2.0.15. * Increased timeout configs * Added VirusTotal to the conf file * added virustotal instance name * changed the 'AutoContainment' playbook input config to 'true' * changed 'timeout' * changed 'timeout' * changed 'timeout' to 1600 * changed the 'ShouldCloseAutomatically' playbook input to 'false' * added the test playbook name to the playbook YML file * RN * removed the close note alert field verification * added the 'marketplacev2' to the test playbook YML file * added the '000001e7a228b2a7abdf7f7e404bc8522df32b725e86907dde32176bccbbbb27' malicious file hash to secrets ignore file. the file hash is used within the test playbook for enrichment and test purposes. --------- * update docker image (#29845) * added functionallity to download index by marketplace (#29834) * added functionallity to download index by marketplace * added some logs for validation * commit * removed logs * [pre-commit MyPy] Align the entire repo with MyPy #2 (#29799) * [pre-commit MyPy] Align the entire repo with MyPy #2 * Add RN * Revert changes in 1.12.26 RN * Update the docker images * [pre-commit MyPy] Align the entire repo with MyPy #1 (#29798) * [pre-commit MyPy] Align the entire repo with MyPy #1 * Xsup 27738 DBotFindSimilarIncidents NoneType Error (#29701) * failed ut * fix * rn * pre-commit * pre commit * just the fix * fix description in yml * fix * docker * Update Packs/Base/ReleaseNotes/1_32_34.md * test * test * removed import --------- * Wiz v1 2 11 (#29719) * Wiz v1 2 11 (#29688) * remove redundant parenthesis * ../Packs/Wiz/Integrations/Wiz/Wiz.py * add Wiz user agent * rephrase release notes * update pack metadata json * rephrase release notes v2 … Co-authored-by: Daniil Lanskoy <107933862+LanskoyGIB@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: maimorag <mmorag@paloaltonetworks.com> Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <mmhw770@gmail.com> Co-authored-by: TalNos <112805149+TalNos@users.noreply.github.com> Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: Ariel Tobiana <107474518+ariel-wiz@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: Darya Koval <72339940+daryakoval@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Dror Avrahami <davrahami@paloaltonetworks.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: Bryce Pedroza <97995056+bryce-ax@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> Co-authored-by: GuyAfik <guyafik11@gmail.com> Co-authored-by: Shelly Tzohar <45915502+Shellyber@users.noreply.github.com> Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> Co-authored-by: sbenyakir <shahaf.benyakir@demisto.com> Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com> Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com> Co-authored-by: yasta5 <112320333+yasta5@users.noreply.github.com> Co-authored-by: Crest Data Systems <60967033+crestdatasystems@users.noreply.github.com> Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com> Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: darkushin <61732335+darkushin@users.noreply.github.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: LiorQM <106475467+LiorQM@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: ckaadic <48683125+ckaadic@users.noreply.github.com> Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com> Co-authored-by: Ali Sawyer <91506078+ali-sawyer@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> Co-authored-by: Yaakov Praisler <59408745+yaakovpraisler@users.noreply.github.com> Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com> Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com> Co-authored-by: sberman <sberman@paloaltonetworks.com> Co-authored-by: DinaMeylakh <72339665+DinaMeylakh@users.noreply.github.com> Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: nkanon <109467661+nkanon@users.noreply.github.com> Co-authored-by: Eido Epstain <eepstain@paloaltonetworks.com> Co-authored-by: Tomer Haimof <81556849+tomer-pan@users.noreply.github.com> Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com> Co-authored-by: Ron Hadad <112933572+ronh1@users.noreply.github.com> Co-authored-by: TalGumi <talg@qmasters.co> Co-authored-by: Guy Lichtman <1395797+glicht@users.noreply.github.com> Co-authored-by: glicht <glicht@users.noreply.github.com> Co-authored-by: Andrew Shamah <42912128+amshamah419@users.noreply.github.com> Co-authored-by: Felipe Garrido <fgarridob.95+github@gmail.com> Co-authored-by: Edi Katsenelson <85438368+edik24@users.noreply.github.com> Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> Co-authored-by: rshunim <102469772+rshunim@users.noreply.github.com> Co-authored-by: OmriItzhak <115150792+OmriItzhak@users.noreply.github.com> Co-authored-by: Joe Cosgrove <joecosgrove5@gmail.com> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com> Co-authored-by: Erez FelmanDar <102903097+efelmandar@users.noreply.github.com> Co-authored-by: israelpolishook <ipolishuk@paloaltonetworks.com> Co-authored-by: ArikDay <115150768+ArikDay@users.noreply.github.com> Co-authored-by: Christopher Hultin <chrishultin@google.com> Co-authored-by: Mike Beauchamp <beauchompers@gmail.com> Co-authored-by: Moshe Galitzky <112559840+moishce@users.noreply.github.com> * revert * revert * fixes * fixes * docker * Mypy * RN * str * Docker --------- Co-authored-by: Daniil Lanskoy <107933862+LanskoyGIB@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: maimorag <mmorag@paloaltonetworks.com> Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: kobymeir <ymeir@paloaltonetworks.com> Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com> Co-authored-by: Menachem Weinfeld <mmhw770@gmail.com> Co-authored-by: TalNos <112805149+TalNos@users.noreply.github.com> Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: Ariel Tobiana <107474518+ariel-wiz@users.noreply.github.com> Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: ostolero <86190583+ostolero@users.noreply.github.com> Co-authored-by: ostolero <ostolero@paloaltonetworks.com> Co-authored-by: Darya Koval <72339940+daryakoval@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Dror Avrahami <davrahami@paloaltonetworks.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: Bryce Pedroza <97995056+bryce-ax@users.noreply.github.com> Co-authored-by: Yehuda <yrosenberg@paloaltonetworks.com> Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> Co-authored-by: GuyAfik <guyafik11@gmail.com> Co-authored-by: Shelly Tzohar <45915502+Shellyber@users.noreply.github.com> Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> Co-authored-by: sbenyakir <shahaf.benyakir@demisto.com> Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com> Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com> Co-authored-by: yasta5 <112320333+yasta5@users.noreply.github.com> Co-authored-by: Crest Data Systems <60967033+crestdatasystems@users.noreply.github.com> Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com> Co-authored-by: Yaroslav Nestor <yaroslav.nestor22@gmail.com> Co-authored-by: darkushin <61732335+darkushin@users.noreply.github.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: LiorQM <106475467+LiorQM@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: ckaadic <48683125+ckaadic@users.noreply.github.com> Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com> Co-authored-by: Ali Sawyer <91506078+ali-sawyer@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> Co-authored-by: Yaakov Praisler <59408745+yaakovpraisler@users.noreply.github.com> Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com> Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com> Co-authored-by: sberman <sberman@paloaltonetworks.com> Co-authored-by: DinaMeylakh <72339665+DinaMeylakh@users.noreply.github.com> Co-authored-by: Yehonatan Asta <yasta@paloaltonetworks.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: asimsarpkurt <79475614+asimsarpkurt@users.noreply.github.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: nkanon <109467661+nkanon@users.noreply.github.com> Co-authored-by: Eido Epstain <eepstain@paloaltonetworks.com> Co-authored-by: Tomer Haimof <81556849+tomer-pan@users.noreply.github.com> Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com> Co-authored-by: Ron Hadad <112933572+ronh1@users.noreply.github.com> Co-authored-by: TalGumi <talg@qmasters.co> Co-authored-by: Guy Lichtman <1395797+glicht@users.noreply.github.com> Co-authored-by: glicht <glicht@users.noreply.github.com> Co-authored-by: Andrew Shamah <42912128+amshamah419@users.noreply.github.com> Co-authored-by: Felipe Garrido <fgarridob.95+github@gmail.com> Co-authored-by: Edi Katsenelson <85438368+edik24@users.noreply.github.com> Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> Co-authored-by: rshunim <102469772+rshunim@users.noreply.github.com> Co-authored-by: OmriItzhak <115150792+OmriItzhak@users.noreply.github.com> Co-authored-by: Joe Cosgrove <joecosgrove5@gmail.com> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com> Co-authored-by: Erez FelmanDar <102903097+efelmandar@users.noreply.github.com> Co-authored-by: israelpolishook <ipolishuk@paloaltonetworks.com> Co-authored-by: ArikDay <115150768+ArikDay@users.noreply.github.com> Co-authored-by: Christopher Hultin <chrishultin@google.com> Co-authored-by: Mike Beauchamp <beauchompers@gmail.com> Co-authored-by: Moshe Galitzky <112559840+moishce@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 12, 2023
* Included new content pack: VectraXDR * Resolved validation error * Resolved linting errors * Suggested changes from the PR comment for the Process Incident and Dispatch Incident playbooks * Updated Docker images tag * Updated README of the playbooks as per latest changes * Added else path to the Add Note playbook for the task #1 * Suggested changes related to validation of page size and other command arguments * Used the get_pack_version function instead hard coding the version to 1.0.0 * Used the credentials parameter type for taking Client ID and Client Secret * Removed duplicate incident field from layout --------- Co-authored-by: Crest Data Systems <60967033+crestdatasystems@users.noreply.github.com> Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com> Co-authored-by: Moshe Eichler <78307768+MosheEichler@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 12, 2023
* fixes * http module * CSV * common server * tests * RN * link * RN * change RN * one more * pre commit * update base version * [known_words] * removing typing * swap the known words * RN * fix RN * Bump pack from version FeedMalwareBazaar to 1.0.30. * Bump pack from version AccentureCTI_Feed to 1.1.27. * Bump pack from version FeedGCPWhitelist to 2.0.30. * Bump pack from version Base to 1.32.52. * make it better * docs * CR * cr * Fixing dirty merge #1 * fixing dirty merge #2 * fix dirty merge #3 * more * fox dirty merge #4 * common * poetry * fix dirty merge #5 * fix test date * base rn * RN * fix common docstring * fix rn * fix errors in build * shirley * Bump pack from version Base to 1.32.54. * RN * mypy * fix common server * ignore type error * skip test * fix test name * add import * remove the import, test is failing * fixed function and test * space * conf * add a test for a uniq time zone * fix test * move the import into the function * move the import from the test as well * replace timezone with pytz, to fit python 2 * Bump pack from version Base to 1.33.1. * fix test comment --------- Co-authored-by: Content Bot <bot@demisto.com>
figarrido
pushed a commit
that referenced
this pull request
Jan 12, 2024
* Replacing the deprecated sub-playbook within the 'NGFW Internal Scan'… (#31197) * Replacing the deprecated sub-playbook within the 'NGFW Internal Scan' XSIAM playbook * RN * [Marketplace Contribution] CISO Metrics (#30641) (#31213) * "pack contribution initial commit" * Update pack_metadata.json * Update and rename dashboard-98f353a2-312b-49f2-8e58-d71f60daf3a7-CISO_Metrics.json to dashboard-98f353a2-312b-49f2-8e58-d71f60daf3a7-CommunityCommonDashboards.json Rename to CommunityCommonDashboards * Update pack_metadata.json Renamed "name": "CommunityCommonDashboards" * Update README.md Added description * Update README.md * Update and rename README.md to README.md * Rename dashboard-98f353a2-312b-49f2-8e58-d71f60daf3a7-CommunityCommonDashboards.json to dashboard-98f353a2-312b-49f2-8e58-d71f60daf3a7-CommunityCommonDashboards.json * Rename .pack-ignore to .pack-ignore * Rename .secrets-ignore to .secrets-ignore * Rename pack_metadata.json to pack_metadata.json * Update .pack-ignore * Update pack_metadata.json * Update .pack-ignore * Update and rename dashboard-98f353a2-312b-49f2-8e58-d71f60daf3a7-CommunityCommonDashboards.json to CISOMetrics.json Renamed to CISOMetrics * Update pack_metadata.json * Update pack_metadata.json * Update README.md --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: David Uhrlaub <90627446+rurhrlaub@users.noreply.github.com> * Cybereason xsoar v 2.1.14 (#30647) (#31225) * added v2.1.14 codebase * fix pr comments * replace dummy md5 placeholder * Update Packs/Cybereason/Integrations/Cybereason/Cybereason.py * updated docker image python version * updated release notes docker version * added pagination params * updated docker image * fix lint errors * fix demisto validate errors * updated release notes * updated release notes * updated release notes * updated command name as per PR comment * removed manual filtering for response * updated function name to match the command name format * updated unit test as per new command name * added machinename filter to api query * moved empty output message to the top * updated docker image tag to latest * undo changes from unisolate endpoint playbook --------- Co-authored-by: suraj-metron <87964764+suraj-metron@users.noreply.github.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> * fixed polling support (#30873) * fixed polling support * fixed rn * added rn * added rn * XSUP-30786/Fix (#31168) * Added failing UT * Fixed the issue * Updated docker image * Updated RN * Update Packs/PAN-OS/ReleaseNotes/2_1_15.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Updated the bug fix and the UT * updated docker image --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * rewrite to js FirstArrayElement and LastArrayElement (#31228) * rewrite to js * added tpb * added empty test case to tpb * precommit fixes * change fromversion so build wont fail * Enable Core REST API with general XSIAM endpoints (#31226) * mostly works * added release notes * fixes from review * F5 APM fixed the marketplace build failure (#31236) * F5 APM Remove XSIAM tags * fix marketplace error * Add incidents field (#30393) (#31233) * add rawJSON field to incidents * release notes * update docker image tag * nit * fetching incident details * mapper + incident fields * remove incorrect incident field files * new incident field files, new mapper * sdk validate command changes * update release noteS * validation errors * fix validation errors * undo release notes changes * undo release notes change * undo release notes * undo release notes * undo release notes * nit * new release notes * remove playbook id * update docker image tag * revert release notes * revert RN * nit- remove filters used for testing * add details field to threats * remove try/except blocks * changing version * Update Abnormal_Security_Custom_Incident_types.json change from version * nit - remove changes used for demo * updating docker image * update docker image tag --------- Co-authored-by: William Olyslager <wolyslager@abnormalsecurity.com> Co-authored-by: sapirshuker <sshuker@paloaltonetworks.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> * Update Docker Image To demisto/python3 (#31242) * Updated Metadata Of Pack CIRCL * Added release notes to pack CIRCL * Packs/CIRCL/Integrations/CirclCVESearch/CirclCVESearch.yml Docker image update * Updated Metadata Of Pack ipinfo * Added release notes to pack ipinfo * Packs/ipinfo/Integrations/ipinfo_v2/ipinfo_v2.yml Docker image update * Updated Metadata Of Pack AutoFocus * Added release notes to pack AutoFocus * Packs/AutoFocus/Integrations/FeedAutofocus/FeedAutofocus.yml Docker image update * Packs/AutoFocus/Integrations/AutofocusV2/AutofocusV2.yml Docker image update * Updated Metadata Of Pack MailSenderNew * Added release notes to pack MailSenderNew * Packs/MailSenderNew/Integrations/MailSenderNew/MailSenderNew.yml Docker image update * avoid to update Docker for AutoFocusv2 --------- Co-authored-by: israelpolishook <ipolishuk@paloaltonetworks.com> * Fixes For 'IP Enrichment - Generic v2' Playbook (#31183) * Fixes For 'IP Enrichment - Generic v2' Playbook * RN * RN * Updated the 'InternalRange' playbook input's default value. * configured the 'extended_data' and 'threat_model_association' sub-playbook inputs * Bump pack from version CommonPlaybooks to 2.4.36. * Bump pack from version CommonPlaybooks to 2.4.37. * changed the default value of the 'ResolveIP' playbook input * re-added RN after merging from master * Fixes RN --------- Co-authored-by: Content Bot <bot@demisto.com> * Check if should run Instance role (#31245) * Added the sync from the saas bucket and modified the verify script to take the revision from the correct bucket. (#31254) * AWS Organizations (#30525) * init * commands template * aws-org-children-list * more commands * even more commands * added account commands * removed enhancement commands * use json_transform * unit-tests init * unit-tests continued * unit-tests continued some more * TPB * one more unit-test * one more unit-test * one more unit-test * name change * TPB * docs complete * pack readme * pack readme part 2 * readme modified * more tests * more tests * use get() * adde description * removed isFetch * added image * name change * CR changes * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update docker * put the commands back in * code complete * yml part 2 * yml part 3 * test template * unit-tests continued some more * unit-tests almost complete * unit-tests complete * fixed a few bugs * fixed unit-tests * added readme * update readme * added missing descriptions to readme * TPB * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * CR changes * demo changes * update docker * build wars: round 1 * build wars: round 2 * build wars: round 3; add unit-tests * build wars: round 4 * build wars: round 5 * build wars: round 6 --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * NextToken in CommandResults (#30501) * init * new design * added error in case of non nested input * RN * a tad more docs * Bump pack from version Base to 1.32.47. * Bump pack from version Base to 1.32.48. * Bump pack from version Base to 1.32.49. * improved doc-string * resolve conflicts * resolve conflicts * Bump pack from version Base to 1.32.52. --------- Co-authored-by: Content Bot <bot@demisto.com> * demisto-sdk-release 1.24.0 (#31268) * poetry files * update validate manager imports (#31179) * update validate manager imports * revert * Update Tests/configure_and_test_integration_instances.py * Edit file types test (#31170) * edited tests * s * s * edit --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com> Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com> * modified modeling rules of clearswift dlp (#31247) * modified modeling rules of clearswift dlp * modified the parsing rule of clearswiftdlp * Added release notes. * added dlp to pack ignore * added Clearswift to pack ignore * QRadar: continue to poll in case of networking issues (#31084) * Generalize the mode option in pre-commit (#30663) * args updated to match the update in the sdk * add merge-coverage-report and coverage-analyze * updaing pyproject.toml * poetry lock * restoring pyproject.toml and poetry.lock * pre-commit.yml * updates * test comment * use sdk ref * if * add github output * revert ilan changes * merge-pytest-reports --------- Co-authored-by: ilan <ierukhimovic@paloaltonetworks.com> * EXPANDR-1576 CortexXpanse Remediation Guidance changes (#31190) * EXPANDR-1576 CortexXpanse Remediation Guidance changes (#30712) * CortexXpanse RG changes * Fix flake8 errors * Fix unit test cases * Update docker version * update command name * Readme updates * docker update * Ignore BC error * fix packignore * Update release notes * update breaking change notes * update breaking change notes * correct RN --------- Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: ilappe <ilappe@paloaltonetworks.com> * Feature/cyberint enhancement (#31252) * Feature/cyberint enhancement (#30493) * Update Docker Image To demisto/py3-tools (#25523) * Updated Metadata Of Pack FeedAWS * Added release notes to pack FeedAWS * Packs/FeedAWS/Integrations/FeedAWS/FeedAWS.yml Docker image update * update Cyberint Pack * update release note and incidentfields * update CommonType release note * update CommonType relesenotes * update CommonType relese notes * update CyberInt Related entity name * update release notes * add new incident field: Alert Data * foramt alert_data * update CyberInt Related Entity name to avoid validation errors * reset the CyberInt Related Entity name * update incident field name * Update 3_3_93.md * pre commit update docker * added known words * fixed the RN * known words --------- Co-authored-by: TalGumi <101499620+TalGumi@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> Co-authored-by: okarkkatz <okarkkatz@paloaltonetworks.com> * [xsoar-8 coverage] - use poll functions from SDK clients (#31144) * update poetry * use poll functions * test against builds * try to fix ssl issue * timeout = 300 + verify ssl * fix ssl issues * fix incident pull * fix * make verify=false by default * fix ports bug * use sdk master * revert poetry * revert infra used for testing * [CrowdStrike Falcon Intel v2] Fixed an issue in 'cs-actors' and 'cs-reports' commands (#31265) * Fix the 'NoneType' object is not iterable issue * ruff * Update the docker image; Add RN * Update Packs/CrowdStrikeIntel/ReleaseNotes/2_0_34.md Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com> --------- Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com> * oncall- installation orders (#31253) * test * test * revert debugs * pre-commit --------- Co-authored-by: Jas Beilin <jgranot@paloaltonetworks.com> * Core rest api docs fix (#31262) * Improved descriptions. * Added docs * Added rn. * Changed i.e to e.g * bugfix/XSUP-30713/port-scan-pb-issue-incident-failure (#31154) * Fix playbook input's default value, change to not required, add check for value not empty * Update playbook image * Update release notes * Bump pack from version CortexXDR to 6.0.5. * Moved InternalIPRanges input check to better location * Fix review comments --------- Co-authored-by: Content Bot <bot@demisto.com> * [PagerDuty v2] Added Support For Pagination (#30959) * commit init - lint and type annotation * typing * pagination function and some typing * fix api limit and pagination * added UT and test_data * added RN and description for args * generate readme * update docker * added UT * fix flake8 * more docstring, one more UT, fix send unnecessary parameters * fix f-string * fix pep8 * revert copy * fix parameters name * docs review * update docker * [ASM] EXPANDR 7225 - Update Ev1 Integration Display Name (#31234) (#31276) * Update Display Name * Update release notes * Update docker image and add period to descriptions Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> * Update Docker Image To demisto/python3 (#31286) * Updated Metadata Of Pack QualysFIM * Added release notes to pack QualysFIM * Packs/QualysFIM/Integrations/QualysFIM/QualysFIM.yml Docker image update * Updated Metadata Of Pack FortiSIEM * Added release notes to pack FortiSIEM * Packs/FortiSIEM/Integrations/FortiSIEMV2/FortiSIEMV2.yml Docker image update * Updated Metadata Of Pack FreshworksFreshservice * Added release notes to pack FreshworksFreshservice * Packs/FreshworksFreshservice/Integrations/FreshworksFreshservice/FreshworksFreshservice.yml Docker image update * Updated Metadata Of Pack KnowBe4_KMSAT * Added release notes to pack KnowBe4_KMSAT * Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSATEventCollector/KnowBe4KMSATEventCollector.yml Docker image update * Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSAT/KnowBe4KMSAT.yml Docker image update * Updated Metadata Of Pack SafeNet_Trusted_Access * Added release notes to pack SafeNet_Trusted_Access * Packs/SafeNet_Trusted_Access/Integrations/SafeNetTrustedAccessEventCollector/SafeNetTrustedAccessEventCollector.yml Docker image update * Updated Metadata Of Pack DelineaSS * Added release notes to pack DelineaSS * Packs/DelineaSS/Integrations/DelineaSS/DelineaSS.yml Docker image update * Updated Metadata Of Pack Cryptocurrency * Added release notes to pack Cryptocurrency * Packs/Cryptocurrency/Integrations/Cryptocurrency/Cryptocurrency.yml Docker image update * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack DeveloperTools * Added release notes to pack DeveloperTools * Packs/DeveloperTools/Integrations/CreateIncidents/CreateIncidents.yml Docker image update * Add XSOAR_SAAS section to EDL description (#31264) * add XSOAR_SAAS section to EDL description * update RN * [XSUP 30575] Added full fields query param (#31272) * get indicators full fields data * pre-commit * release notes * tests and CR fixes * Update Packs/FeedCrowdstrikeFalconIntel/ReleaseNotes/2_1_13.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Update Docker Image To demisto/boto3py3 (#31287) * Updated Metadata Of Pack SecurityIntelligenceServicesFeed * Added release notes to pack SecurityIntelligenceServicesFeed * Packs/SecurityIntelligenceServicesFeed/Integrations/SecurityIntelligenceServicesFeed/SecurityIntelligenceServicesFeed.yml Docker image update * Updated Metadata Of Pack AWS-IAM * Added release notes to pack AWS-IAM * Packs/AWS-IAM/Integrations/AWS-IAM/AWS-IAM.yml Docker image update * Updated Metadata Of Pack AWS-Route53 * Added release notes to pack AWS-Route53 * Packs/AWS-Route53/Integrations/AWSRoute53/AWSRoute53.yml Docker image update * Updated Metadata Of Pack AWS-AccessAnalyzer * Added release notes to pack AWS-AccessAnalyzer * Packs/AWS-AccessAnalyzer/Integrations/AWS-AccessAnalyzer/AWS-AccessAnalyzer.yml Docker image update * Updated Metadata Of Pack AWS-GuardDuty * Added release notes to pack AWS-GuardDuty * Packs/AWS-GuardDuty/Integrations/AWSGuardDutyEventCollector/AWSGuardDutyEventCollector.yml Docker image update * Packs/AWS-GuardDuty/Integrations/AWSGuardDuty/AWSGuardDuty.yml Docker image update * Updated Metadata Of Pack AWS-SecurityHub * Added release notes to pack AWS-SecurityHub * Packs/AWS-SecurityHub/Integrations/AWSSecurityHubEventCollector/AWSSecurityHubEventCollector.yml Docker image update * Updated Metadata Of Pack Aws-SecretsManager * Added release notes to pack Aws-SecretsManager * Packs/Aws-SecretsManager/Integrations/AwsSecretsManager/AwsSecretsManager.yml Docker image update * Update Docker Image To demisto/accessdata (#31288) * Updated Metadata Of Pack Exterro * Added release notes to pack Exterro * Packs/Exterro/Integrations/Exterro/Exterro.yml Docker image update * Update Docker Image To demisto/oci (#31290) * Updated Metadata Of Pack OracleCloudInfrastructure * Added release notes to pack OracleCloudInfrastructure * Packs/OracleCloudInfrastructure/Integrations/OracleCloudInfrastructureEventCollector/OracleCloudInfrastructureEventCollector.yml Docker image update * Update Docker Image To demisto/py3-tools (#31289) * Updated Metadata Of Pack Intezer * Added release notes to pack Intezer * Packs/Intezer/Integrations/IntezerV2/IntezerV2.yml Docker image update * Updated Metadata Of Pack Zabbix * Added release notes to pack Zabbix * Packs/Zabbix/Integrations/Zabbix/Zabbix.yml Docker image update * Updated Metadata Of Pack FeedMalwareBazaar * Added release notes to pack FeedMalwareBazaar * Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update * Updated Metadata Of Pack FeedGCPWhitelist * Added release notes to pack FeedGCPWhitelist * Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update * Updated Metadata Of Pack AccentureCTI_Feed * Added release notes to pack AccentureCTI_Feed * Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update * Updated Metadata Of Pack SEKOIAIntelligenceCenter * Added release notes to pack SEKOIAIntelligenceCenter * Packs/SEKOIAIntelligenceCenter/Integrations/SEKOIAIntelligenceCenter/SEKOIAIntelligenceCenter.yml Docker image update * Updated Metadata Of Pack JARM * Added release notes to pack JARM * Packs/JARM/Integrations/JARM/JARM.yml Docker image update * Updated Metadata Of Pack Anomali_ThreatStream * Added release notes to pack Anomali_ThreatStream * Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStreamv3/AnomaliThreatStreamv3.yml Docker image update * Updated Metadata Of Pack CommonWidgets * Added release notes to pack CommonWidgets * Packs/CommonWidgets/Scripts/RSSWidget/RSSWidget.yml Docker image update * Updated Metadata Of Pack FiltersAndTransformers * Added release notes to pack FiltersAndTransformers * Packs/FiltersAndTransformers/Scripts/Jmespath/Jmespath.yml Docker image update * Update Docker Image To demisto/armorblox (#31291) * Updated Metadata Of Pack Armorblox * Added release notes to pack Armorblox * Packs/Armorblox/Integrations/Armorblox/Armorblox.yml Docker image update * Update Docker Image To demisto/crypto (#31292) * Updated Metadata Of Pack AzureKeyVault * Added release notes to pack AzureKeyVault * Packs/AzureKeyVault/Integrations/AzureKeyVault/AzureKeyVault.yml Docker image update * Updated Metadata Of Pack AzureSentinel * Added release notes to pack AzureSentinel * Packs/AzureSentinel/Integrations/AzureSentinel/AzureSentinel.yml Docker image update * Updated Metadata Of Pack AzureDevOps * Added release notes to pack AzureDevOps * Packs/AzureDevOps/Integrations/AzureDevOps/AzureDevOps.yml Docker image update * Updated Metadata Of Pack MicrosoftCloudAppSecurity * Added release notes to pack MicrosoftCloudAppSecurity * Packs/MicrosoftCloudAppSecurity/Integrations/MicrosoftCloudAppSecurity/MicrosoftCloudAppSecurity.yml Docker image update * Updated Metadata Of Pack AzureRiskyUsers * Added release notes to pack AzureRiskyUsers * Packs/AzureRiskyUsers/Integrations/AzureRiskyUsers/AzureRiskyUsers.yml Docker image update * Updated Metadata Of Pack MicrosoftGraphGroups * Added release notes to pack MicrosoftGraphGroups * Packs/MicrosoftGraphGroups/Integrations/MicrosoftGraphGroups/MicrosoftGraphGroups.yml Docker image update * Updated Metadata Of Pack AzureSQLManagement * Added release notes to pack AzureSQLManagement * Packs/AzureSQLManagement/Integrations/AzureSQLManagement/AzureSQLManagement.yml Docker image update * Updated Metadata Of Pack MicrosoftGraphAPI * Added release notes to pack MicrosoftGraphAPI * Packs/MicrosoftGraphAPI/Integrations/MicrosoftGraphAPI/MicrosoftGraphAPI.yml Docker image update * Updated Metadata Of Pack MicrosoftTeams * Added release notes to pack MicrosoftTeams * Packs/MicrosoftTeams/Integrations/MicrosoftTeamsManagement/MicrosoftTeamsManagement.yml Docker image update * Updated Metadata Of Pack MicrosoftGraphApplications * Added release notes to pack MicrosoftGraphApplications * Packs/MicrosoftGraphApplications/Integrations/MicrosoftGraphApplications/MicrosoftGraphApplications.yml Docker image update * Update Docker Image To demisto/sixgill (#31293) * Updated Metadata Of Pack Cybersixgill-ActionableAlerts * Added release notes to pack Cybersixgill-ActionableAlerts * Packs/Cybersixgill-ActionableAlerts/Integrations/CybersixgillActionableAlerts/CybersixgillActionableAlerts.yml Docker image update * Updated Metadata Of Pack Sixgill-Darkfeed * Added release notes to pack Sixgill-Darkfeed * Packs/Sixgill-Darkfeed/Integrations/Sixgill_Darkfeed_Enrichment/Sixgill_Darkfeed_Enrichment.yml Docker image update * Packs/Sixgill-Darkfeed/Integrations/Sixgill_Darkfeed/Sixgill_Darkfeed.yml Docker image update * Update Docker Image To demisto/carbon-black-cloud (#31295) * Updated Metadata Of Pack CarbonBlackDefense * Added release notes to pack CarbonBlackDefense * Packs/CarbonBlackDefense/Integrations/CarbonBlackLiveResponseCloud/CarbonBlackLiveResponseCloud.yml Docker image update * Update Docker Image To demisto/taxii2 (#31294) * Updated Metadata Of Pack FeedDHS * Added release notes to pack FeedDHS * Packs/FeedDHS/Integrations/DHSFeedV2/DHSFeedV2.yml Docker image update * Updated Metadata Of Pack FeedUnit42v2 * Added release notes to pack FeedUnit42v2 * Packs/FeedUnit42v2/Integrations/FeedUnit42v2/FeedUnit42v2.yml Docker image update * MS IIS Update2 (#31256) * Updated MicrosoftIISWebServerModelingRules_1_3 * Updated ModelingRules filters * Updated ModelingRules filters * Updated ReleaseNotes * Upated ReleaseNotes * CrowdStrikeFalconX-genreic-polling (#31189) * old playbooks deprecated and new one added * readme file edited * set the interval from the inputs * fixes for release notes * added extensions to known words * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_URL_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/ReleaseNotes/1_2_37.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/ReleaseNotes/1_2_37.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/ReleaseNotes/1_2_37.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/ReleaseNotes/1_2_37.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_File_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * minor fixes for description * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_URL_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_URL_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CrowdStrikeFalconX/Playbooks/Detonate_URL_-_CrowdStrike_Falcon_Intelligence_Sandbox_v2.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Add Symantec MSS to ignored items (#31296) * [XSUP 30870] Added full fields option for cs-actors and cs-reports commands (#31271) * Added the display_full_fields argument * pre-commit * release notes * tests and CR fixes * resolve conflict * pre-commit * CR fixes * docker * pre-commit * add myself as codeowner (#31314) * ORKL Feed Integration 1.0.0 Initial Release (#31166) * ORKL Feed Integration 1.0.0 Initial Release (#31101) Co-authored-by: Martin Ohl <Martin.Ohl@ohl-net.eu> * [VirusTotal] Add suspicious threshold (#31220) * [VirusTotal] Add suspicious threshold (#31021) * fixing CimTrak_test.py unit tests (#31308) fixing CimTrak_test.py unit tests #31308 * Add new command and bug fix. (#31311) * Anomali ThreatStream v3 - Fix threatstream-get-indicators command (#31269) * fix get_indicators method * update RN * update docker * update test * update test * update get_indicators method * update RN * Update Packs/Anomali_ThreatStream/ReleaseNotes/2_2_9.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * update docker * update docker --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * SentinelOne v2: Add 2 new commands (#31312) * fixing jira file attachments (#31297) fixing jira file attachments, fixing mapping of newly created tickets #31297 * CiscoSMA Update (#31315) * Updated ModelingRules * Updated ReleaseNotes * Updated ReleaseNotes * updated docs (#31192) * updated docs * running pre-commit and docker * docker update * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * remove package-lock file * cr note * Update Packs/MicrosoftGraphDeviceManagement/ReleaseNotes/1_1_20.md Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> * Fix an issue when there is only one incident in fetch_incidents powershell (#31267) * added -AsArray * updated the docker image and added . * RN * unit tests and docker image * rn * docker image and release notes * Update Packs/Base/ReleaseNotes/1_32_53.md Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> * updated the unit tests --------- Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com> * Get Entity Alerts by MITRE Tactics - Performance Improvements (Refactor) (#31232) * Added playbooks * New playbooks images, formatted playbooks, and added RN * Updated pb image to be in light mode * Further improvements to playbooks, updated docs, and updated playbook images * Bump pack from version CortexXDR to 6.0.6. * Changed alert to incident to fix validation * Descriptions --------- Co-authored-by: Content Bot <bot@demisto.com> * fix for sdk nightly e2e tests (#31310) * [qradar-v3] - handle connection errors (#31246) * [qradar-v3] - handle connection errors * add uts * bump rn * remove irrelevant imports * update code * timeout = 300 * bump rn * update implementation * docker image * fixes * remove imports * rn * update debug-message * update log * fix docker-image * fix ut * oncall-sdk-nightly-create-xsoar-instance (#31300) * overwrite the filter env file * remove space * remove print * Update .gitlab/ci/.gitlab-ci.on-push.yml Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> * [ASM] - EXPANDER 7238 - Jira Playbook Support for V2 and V3 Project Key (#31273) (#31322) * Add support V2 and V3, remove default project key - Add data collection task for customer - Leave Jira Project Key input as blank - Add support for project key passed into Jira V2 and V3 integrations * Add release notes * Update Playbook ReadMe * Add task description * Update release notes Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> * Support contributions when the name of the repo isn't content (#31320) * update handle_external_pr.py * set repo_name arg as optional * Oncall sdk nightly create xsoar instance (#31324) Oncall sdk nightly create xsoar instance #31324 * CIAC-4556/xdr-remote-psexec-lolbin-command-execution-playbook (#29092) * Add playbook and readme files * Add updated files * Add playbook image * Update release notes * Fix validation error * Bump pack from version CortexXDR to 5.1.0. * Bump pack from version CortexXDR to 5.2.0. * Bump pack from version CortexXDR to 5.2.0. * Bump pack from version CortexXDR to 5.2.0. * Add CommandLine verdict to layout * Update according to demo review comments * Bump pack from version CortexXDR to 5.2.0. * Bump pack from version CortexXDR to 5.2.0. * Add field for cmd line verdict * Update layout * Fix review comments * Update from master * Update Packs/CortexXDR/ReleaseNotes/5_2_0.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/ReleaseNotes/5_2_0.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Fix review comments and validations * Apply suggestions from code review Fix docs review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexXDR/Playbooks/playbook-Cortex_XDR_-_Remote_PsExec_with_LOLBIN_command_execution_alert.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Fix review comments * Remove duplicate task for alert details, update playbook image * Fix skipifunavailable validations and update release notes * Fix review comments * Update release notes * Update release notes * Bump pack from version CortexXDR to 5.2.0. * Fix review comments * Update release notes * Bump pack from version CortexXDR to 5.2.2. * Bump pack from version CortexXDR to 5.2.3. * Fix review comments * Fix validation error * Fix validation errors * Update release notes * Fix conflicts * removed already added incident field * Update release notes * Fix validation errors * Fix validation errors * revert file changes * Fix validation errors * Fix validation errors * Bump pack from version CortexXDR to 6.0.4. * Fix review comments * Fix review comments * Update to correct playbook image * Bump pack from version CortexXDR to 6.0.5. * Update 6_0_5.md * Update release notes * Update 6_0_5.md * Bump pack from version CortexXDR to 6.0.7. * Fix precommit errors --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update README.md (#31299) * Last Mirrored New Field & Qradar fix (#31251) * add field * Bump pack from version CommonTypes to 3.3.95. * fix * review fix --------- Co-authored-by: Content Bot <bot@demisto.com> * Update native candidate to py3-native:8.4.0.82817 (#31319) * SplunkPy missing incidents (#30783) * Used exclusion of even ids * Reverted changes in unit tests * Fixed unbound issue * Added last fetched notables * Added potential solution * Comments in UTs * Added UTs * Added UTs with explanation * Added RNs * Fixed UTs and updated how we exclude ids * Fixed conflicts * Fixed CR * Fixed conflicts * Updated docker image * Fixed pre-commit in test file * Removed second pytest * Fixed comments in test file * MATI - Supporting multiple inputs for generic enrichment commands (#30940) (#31334) * Supporting multiple inputs for generic enrichment commands * Return list of CommandResults * Re-adding rawJSON * Bumping docker version * Relesase Notes * Tests * Tests * Adding details to contexts * Fixing tests * Bumping docker * Bumping docker * Fixing spacing * Fixing spacing * Fixing fetch --------- Co-authored-by: Christopher Hultin <chrishultin@google.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> * [Cortex Data Lake] Update the Docker Image (#31337) * Support Threat Assessment functionality in MS Graph Security (#30110) * added yml and the first command in code * added commands * added to description in yml * added readme for first command * added readme to second command * added third command to readme * added url command to readme * added list command to readme * added tests files * minor edits * added unittests * added unittest * updated docker image * added rn * edited readme * edit * fixed lint errors * fixed validation errors * fixed rn * edits precommits errors * fixed unittest for test auth code * edited tpb * added unittests * to revert some of these changes * update after doc review * added unittests * removed checking server version in CSP * updated docker image * added rn * Bump pack from version Base to 1.32.41. * reverted changes for csp * reveeted changes * deleted rn * added fromversion field * added unittest * updated for pre commit * updated for pre commit * edits after build failed * removed file * edits * added the tpb * fixed tpb * edited the list command * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/ReleaseNotes/2_2_5.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftGraphSecurity/Integrations/MicrosoftGraphSecurity/MicrosoftGraphSecurity.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * updated docker image * edited after build failed * reverted changes * updated do * added arg * added rn * updated docker image * edit * edits after cr * updated do * edited the get user call * checked the 2 other commands * edited yml * updated do * edited test * removed comments * updated do * edit * edit --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * incident field helloworld onprem (#31340) * update ParseEmailFilesV2 to 0.1.19 (#31331) * update Docker image and added bcc * update rn * update tests * Update Packs/CommonScripts/ReleaseNotes/1_12_55.md Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> --------- Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> * update readme (#31343) * [CommonServer.js] Update emailRegex (#31148) change email regex * Ciac 3790/add auto determine LDAP vendor (#31124) * Added auto determine LDAP vendor * Added test and RN * fix lint and rn * added to readme * docker * changed default vendor param to auto * [Versa Director] Update response data formats (#31327) * Remove accept: application/xml from get requests * Remove redundant get() from request responses * Update UTs * Release notes; pre-commit updates * Update UTs; Revert relevant get() functions * Revert relevant get() functions * Fix syntax error * Update Packs/VersaDirector/ReleaseNotes/1_0_7.md Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> * Update 1_0_7.md --------- Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> * Replace LastMirroredInTime incident field with Last Mirrored Time Stamp incident field in QRadar (#31281) * add field * Last Mirrored Time Stamp * fix unrelated release notes * RN * docker image and release notes * rn * rn * docker image and release notes * RN * updates * update * unit tests for the script * update rn and bc * docstring for the ubit tests --------- Co-authored-by: arikday <aday@paloaltonetworks.com> Co-authored-by: ArikDay <115150768+ArikDay@users.noreply.github.com> * Tessian integration setup (#31350) * Tessian integration setup (#31028) * revert package-lock.json --------- Co-authored-by: NicBunn-PlutoFlume <112942358+NicBunn-PlutoFlume@users.noreply.github.com> Co-authored-by: adi88d <adaud@paloaltonetworks.com> Co-authored-by: Adi Daud <46249224+adi88d@users.noreply.github.com> * Kiteworks Modeling CIAC-6377 (#31230) * init-pack * parsing-rules * json-format-modeling * README.md * modeling-rules * refactor-modeling-rules * fix-modeling-rules-issues * single-line-format-modeling * activity-group-type-modeling * refactor-modeling-rules * refactor-modeling-rules * Update Packs/Kiteworks/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * refactor-modeling-rules * refactor-modeling-rules * modeling-rules-json-fix * modeling-rules-json-refactor * modeling-rules-remove-unused-field --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Prisma SASE - Quarantine Host With Active Threat (#31346) * New playbook for Prisma SASE * update RN * update RN * update playbook description * update playbook readme * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * update RN * update playbook readme * update RN --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Symantec web security service pack long running (#30990) * first commit * commit * commit * first commit * update pack_metadata file * extract_logs_from_response changes * get_events_command changes * commit * commit * add logs * commit * commit * commit * commit * commit * commit * commit * commit * commit * commit * commit * commit * commit * Fixed the memory load on Docker * commit * first commit for rewrite * commit * commit * add UT and finish implementation * design * Change pack name * add-modeling-rules * add-parsing-rules * siem-content-minor-fixes * add UT and docstring * add-siem-documentation * update-siem-documentation * update-siem-documentation * commit * Change readme file * fix UT and add description to pack_metadata * commit * fix mypy flake8 * add UT * refactor-siem-content * Apply suggestions from code review Comment corrections Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * comment corrections * comment corrections and add UT for it * comment correction * mypy * update Docker * comment corrections * comment corrections * update docker * fix UT and pre-commit * commit * commit * fix pre commit * commit --------- Co-authored-by: Chanan Welt <cwelt@paloaltonetworks.com> Co-authored-by: cweltPA <129675344+cweltPA@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * FireEye ETP Event Collector fixes (#30819) * Fixed date parsing * format and tests * fixed date parsing from and to the api * fixed tests * fixed invalid date order * fetch in asc order * fetch in asc order * fix unitesing * fix potential formatting issue * change first_run * change first_run * Fix RN * Fix lint * Fix lint * added unitests * added unitests * CR fixes * CR fixes * Update Docker Image To demisto/accessdata (#31373) * Updated Metadata Of Pack Exterro * Added release notes to pack Exterro * Packs/Exterro/Integrations/Exterro/Exterro.yml Docker image update * Update Docker Image To demisto/boto3py3 (#31372) * Updated Metadata Of Pack SecurityIntelligenceServicesFeed * Added release notes to pack SecurityIntelligenceServicesFeed * Packs/SecurityIntelligenceServicesFeed/Integrations/SecurityIntelligenceServicesFeed/SecurityIntelligenceServicesFeed.yml Docker image update * Updated Metadata Of Pack AWS-IAM * Added release notes to pack AWS-IAM * Packs/AWS-IAM/Integrations/AWS-IAM/AWS-IAM.yml Docker image update * Updated Metadata Of Pack AWS-Route53 * Added release notes to pack AWS-Route53 * Packs/AWS-Route53/Integrations/AWSRoute53/AWSRoute53.yml Docker image update * Updated Metadata Of Pack AWS-AccessAnalyzer * Added release notes to pack AWS-AccessAnalyzer * Packs/AWS-AccessAnalyzer/Integrations/AWS-AccessAnalyzer/AWS-AccessAnalyzer.yml Docker image update * Updated Metadata Of Pack AWS-GuardDuty * Added release notes to pack AWS-GuardDuty * Packs/AWS-GuardDuty/Integrations/AWSGuardDutyEventCollector/AWSGuardDutyEventCollector.yml Docker image update * Packs/AWS-GuardDuty/Integrations/AWSGuardDuty/AWSGuardDuty.yml Docker image update * Updated Metadata Of Pack AWS-SecurityHub * Added release notes to pack AWS-SecurityHub * Packs/AWS-SecurityHub/Integrations/AWSSecurityHubEventCollector/AWSSecurityHubEventCollector.yml Docker image update * Updated Metadata Of Pack Aws-SecretsManager * Added release notes to pack Aws-SecretsManager * Packs/Aws-SecretsManager/Integrations/AwsSecretsManager/AwsSecretsManager.yml Docker image update * [ASM] - EXPANDER 3741 - XSIAM Layout and Rule (#31352) * [ASM] - EXPANDER 3741 - XSIAM Layout and Rule (#31212) * Update Rem. Guidance Playbook, add new fields Created fields: - "ASM - Attack Surface Rule Category" - "ASM - Attack Surface Rule Description" - "ASM - Attack Surface Rule Priority" - "ASM - Attack Surface Rule Remediation Guidance" Set fields in Remediation Guidance playbook * Update release notes * Update field descriptions * Format JSON files * update unsearchable and fromVersion * Add ASM layout and rule * Add release notes * Update pack ReadMe * Update server content items * Add marketplace to layout * Update release notes version * Add AlertType to server content items * Add IncidentType to server content items * update ASM.json layout * remove ASM from server_content_items.json --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: Adi Daud <46249224+adi88d@users.noreply.github.com> Co-authored-by: adi88d <adaud@paloaltonetworks.com> * Feed Recorded Future download all compressed data on disk bug (#30981) * Hint for solution * Potential solution * Tried solution, did not work * Added potential solution * Added RNs and updated docker image * Added debug logs * Resolved conflicts * Added handling of cut-off bytes while streaming * Added unit tests and test data * Outsourced decoder * Went over CR comments * Fixed Chunk Size * Added description to fixture * Ran pre-commit * Refactored decoding mechanism * Fix chunk size * Update FeedRecordedFuture.yml * Update 1_0_32.md * CISCO SMA u200b Update (#31349) * Updated ModelingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ModelingRules logic * [e2e xsoar-saas] - fix issue with taxii2-server test (#31362) * Update Docker Image To demisto/crypto (#31368) * Updated Metadata Of Pack MicrosoftDefenderAdvancedThreatProtection * Added release notes to pack MicrosoftDefenderAdvancedThreatProtection * Packs/MicrosoftDefenderAdvancedThreatProtection/Integrations/MicrosoftDefenderAdvancedThreatProtection/MicrosoftDefenderAdvancedThreatProtection.yml Docker image update * Updated Metadata Of Pack AzureSecurityCenter * Added release notes to pack AzureSecurityCenter * Packs/AzureSecurityCenter/Integrations/AzureSecurityCenter_v2/AzureSecurityCenter_v2.yml Docker image update * Update Docker Image To demisto/armorblox (#31376) * Updated Metadata Of Pack Armorblox * Added release notes to pack Armorblox * Packs/Armorblox/Integrations/Armorblox/Armorblox.yml Docker image update * Update Docker Image To demisto/pymisp2 (#31369) * Updated Metadata Of Pack MISP * Added release notes to pack MISP * Packs/MISP/Integrations/MISPV3/MISPV3.yml Docker image update * Update Docker Image To demisto/genericsql (#31370) * Updated Metadata Of Pack GenericSQL * Added release notes to pack GenericSQL * Packs/GenericSQL/Integrations/GenericSQL/GenericSQL.yml Docker image update * MS IIS Update3 (#31385) * Updated ModelingRules * Updated ReleaseNotes * Updated ReleaseNotes * Updated ModelingRules * Updated ModelingRules * Add a manual fatch once in 12 hours (#31123) * fixes * http module * CSV * common server * tests * RN * link * RN * change RN * one more * pre commit * update base version * [known_words] * removing typing * swap the known words * RN * fix RN * Bump pack from version FeedMalwareBazaar to 1.0.30. * Bump pack from version AccentureCTI_Feed to 1.1.27. * Bump pack from version FeedGCPWhitelist to 2.0.30. * Bump pack from version Base to 1.32.52. * make it better * docs * CR * cr * Fixing dirty merge #1 * fixing dirty merge #2 * fix dirty merge #3 * more * fox dirty merge #4 * common * poetry * fix dirty merge #5 * fix test date * base rn * RN * fix common docstring * fix rn * fix errors in build * shirley * Bump pack from version Base to 1.32.54. * RN * mypy * fix common server * ignore type error * skip test * fix test name * add import * remove the import, test is failing * fixed function and test * space * conf * add a test for a uniq time zone * fix test * move the import into the function * move the import from the test as well * replace timezone with pytz, to fit python 2 * Bump pack from version Base to 1.33.1. * fix test comment --------- Co-authored-by: Content Bot <bot@demisto.com> * Fix gmail get mail context output (#31342) * update context path * added RN * updated readme * update docker * added run get attachments argument * pre commit fixes * pre commit fixes * cr fixes * cr fixes * cr fixes * update RN * update docker * Updated README.md (#31347) (#31363) * [Zscaler] Add URLs to Retaining Parent Category (#30637) * add retaining parent url * Update retaining_parent_category_url argument * Add retaining-parent-category-ip to yml * Add retaining-parent-category-ip logic * ip argument no longer marked required * url argument no longer marked required * retaining_parent_category args are None by default * Add retaining-parent-category-url to remove-url * Add retaining-parent-category-ip to remove-ip * UT fix; ruff updates * Remove redundant context output * Update release notes * FIx Failed UTs * Case of only one ip argument in remove commands * pre-commit updates * Update release notes * Change display value to original value * Update release notes * UT Coverage * Add UTs; Remove redundant debug logs * Update release notes * Apply suggestions from code review Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> * Remove "pragma no cover" from unrelated UTs * Revert open function's default 'r' value for readability --------- Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> * Update Docker Image To demisto/python3 (#31371) * Updated Metadata Of Pack QualysFIM * Added release notes to pack QualysFIM * Packs/QualysFIM/Integrations/QualysFIM/QualysFIM.yml Docker image update * Updated Metadata Of Pack FortiSIEM * Added release notes to pack FortiSIEM * Packs/FortiSIEM/Integrations/FortiSIEMV2/FortiSIEMV2.yml Docker image update * Updated Metadata Of Pack FreshworksFreshservice * Added release notes to pack FreshworksFreshservice * Packs/FreshworksFreshservice/Integrations/FreshworksFreshservice/FreshworksFreshservice.yml Docker image update * Updated Metadata Of Pack KnowBe4_KMSAT * Added release notes to pack KnowBe4_KMSAT * Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSATEventCollector/KnowBe4KMSATEventCollector.yml Docker image update * Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSAT/KnowBe4KMSAT.yml Docker image update * Updated Metadata Of Pack SafeNet_Trusted_Access * Added release notes to pack SafeNet_Trusted_Access * Packs/SafeNet_Trusted_Access/Integrations/SafeNetTrustedAccessEventCollector/SafeNetTrustedAccessEventCollector.yml Docker image update * Updated Metadata Of Pack DelineaSS * Added release notes to pack DelineaSS * Packs/DelineaSS/Integrations/DelineaSS/DelineaSS.yml Docker image update * Updated Metadata Of Pack Cryptocurrency * Added release notes to pack Cryptocurrency * Packs/Cryptocurrency/Integrations/Cryptocurrency/Cryptocurrency.yml Docker image update * Updated Metadata Of Pack PANOSPolicyOptimizer * Added release notes to pack PANOSPolicyOptimizer * Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update * Updated Metadata Of Pack DeveloperTools * Added release notes to pack DeveloperTools * Packs/DeveloperTools/Integrations/CreateIncidents/CreateIncidents.yml Docker image update * Updated Metadata Of Pack QualysFIM * Updated Metadata Of Pack QualysFIM * [Marketplace Contribution] MicrosoftGraphTeams - Content Pack Update (#31097) (#31387) * "contribution update to pack "MicrosoftGraphTeams"" * Update MicrosoftGraphTeams.py uncomment 'topic' to allow subject for group type chat. * Update MicrosoftGraphTeams.yml fixed validation error for descriptions. * Update Packs/MicrosoftGraphTeams/Integrations/MicrosoftGraphTeams/MicrosoftGraphTeams.py done * cr * Update 1_1_0.md * Update MicrosoftGraphTeams.yml * Update 1_1_0.md * Update 1_1_0.md * Update MicrosoftGraphTeams.yml --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: Vipul Kaneriya <50216620+vipulkaneriya@users.noreply.github.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> Co-authored-by: MLainer1 <mlainer@paloaltonetworks.com> * Cybersixgill alerts typosquatting (#31386) * Cybersixgill alerts typosquatting (#30787) * Added mapper for 2 custom incident fields * Updated release notes. * Added typosquatting to known words * new Incident fields and incomming mapper formated * Release notes reviewed. * setting unseachable to true. * Suspicious and Triggered domain as tables. * Moved 3 mappings from code to mapper. * Updated test case * Updated test case * Added default mapper and updated docker image version * Added breaking change note * Removed breaking change note * Renamed files as per suggestion * renamed mapper as per suggestion * Added new release note. * Changed id and name for incident fields and updated docker image name * update RN * update RN, update fields names, update mapper * update id, update RN * Update 1_2_10.md * Update incidentfield-Cybersixgill_Triggered_Domain.json * update docker * ID value contained invalid caps character. * changing type in fields to tagselect --------- Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: sapirshuker <sshuker@paloaltonetworks.com> * docker image update --------- Co-authored-by: syed-loginsoft <97145640+syed-loginsoft@users.noreply.github.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: sapirshuker <sshuker@paloaltonetworks.com> * Armis …
DNRRomero
pushed a commit
that referenced
this pull request
Jun 13, 2024
* add comment * fix * fix * tests * mirroring alerts * fixe get alerts * DELETE DEBUG * SPACE * del,ete dev * fix * tests * pre-commit * pre-commit * fix params close * RN * fix readme * add test * fix * Updated docker image to demisto/pcap-miner:1.0.0.91369. PR batch #1/3 (demisto#33830) * Updated docker image to demisto/pcap-miner:1.0.0.91369. PR batch #2/3 (demisto#33831) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * fix rn * fix merge of auto docker * fix merge docker related * add test * pre-commit * cr * FIX CR * fix * revert * fix * fix tests * remove dev * fix raw * fix * fix comment * fix dev * Bump pack from version CortexXDR to 6.1.29. * fix after alerts changed * Apply suggestions from code review doc review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Merge remote-tracking branch 'origin' into xdr_alert_mrroring * Apply suggestions from code review docs and adi Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * cr * fix * fix test * assign params * fix debug * FIX PALYBOOK * fix test * delete informatinal * 6_1_30 * fix playbook * add version * rn31 * Bump pack from version CortexXDR to 6.1.32. * fix rn * fix * fix 33 * fix * Bump pack from version CortexXDR to 6.1.35. * Bump pack from version CortexXDR to 6.1.36. * Bump pack from version CortexXDR to 6.1.37. * docker image --------- Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jun 13, 2024
* demisto/python3:3.10.14.92207 | 0-100 | PR batch #6/6 (demisto#34076) * Updated docker image to demisto/python3:3.10.14.92207. PR batch #6/6 * fix period * fix . --------- Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> * demisto/python3:3.10.14.92207 | 0-100 | PR batch #4/6 (demisto#34074) * Updated docker image to demisto/python3:3.10.14.92207. PR batch #4/6 * fix . --------- Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> * demisto/python3:3.10.14.92207 | 0-100 | PR batch #5/6 (demisto#34075) * Updated docker image to demisto/python3:3.10.14.92207. PR batch #5/6 * fix . --------- Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> * Updated docker image to demisto/python3:3.10.14.92207. PR batch #1/6 (demisto#34071) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.92207. PR batch #2/6 (demisto#34072) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.92207. PR batch #3/6 (demisto#34073) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Add release notes * revert auto changes related to escape characters * pre-commit * Update release notes * Fix Packs/Gurucul/ReleaseNotes/2_0_4.md --------- Co-authored-by: anas-yousef <44998563+anas-yousef@users.noreply.github.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jun 13, 2024
* Updated docker image to demisto/pcap-miner:1.0.0.91369. PR batch #1/3 (demisto#33830) * Updated docker image to demisto/pcap-miner:1.0.0.91369. PR batch #2/3 (demisto#33831) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * demisto/paho-mqtt:1.0.0.56447 | 0-100 | PR batch #1/1 (demisto#33828) * Updated docker image to demisto/paho-mqtt:1.0.0.56447. PR batch #1/1 * Revert ZipFile image (demisto#33825) * revert docker image and added the TPB to the yml * updated release notes * pre-commit fixes * updated release notes * Docker Hardening test - fix flaky test (demisto#33805) * Revert "Merge branch 'auto_update_docker_staging_branch' into AUD-demisto/paho-mqtt-1.0.0.56447-pr-batch-1" This reverts commit c5dffd6, reversing changes made to d9ce372. * add space * delete space * version 29 --------- Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> * Fix conflict * Updated docker image to demisto/py3-tools:1.0.0.91908. PR batch #1/3 (demisto#33871) * Update release notes * Validate * pre-commit * Fix RN for Anomali ThreatStream v3 * Fix PcapAnalysis.yml file * update devdemisto/polyswarm * dockerImage uploaded to docker hub * revert pcap-minor related changes * Resolve Packs/CommonScripts merge conflict * Resolve Packs/CommonScripts merge conflict * Remove pcap-minor RN file * Update release notes * Update release notes * Update UBIRCH to use demisto/py3-tools instead of demisto/paho-mqtt * Resolve Packs/CommonScripts merge conflict * Resolve Packs/Anomali_ThreatStream merge conflict --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com> Co-authored-by: Tal <tcarmeli@paloaltonetworks.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jun 28, 2024
…emisto#34968) * Updated docker image to demisto/pcap-miner:1.0.0.96695. PR batch #1/1 (demisto#34716) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/pycountry:1.0.0.96960. PR batch #1/1 (demisto#34718) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/py3-tools:1.0.0.96976. PR batch #1/1 (demisto#34717) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/xsoar-tools:1.0.0.96723. PR batch #1/1 (demisto#34719) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/ansible-runner:1.0.0.96928. PR batch #1/1 (demisto#34715) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Update RN * pre-commit * format --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jun 28, 2024
…emisto#35076) * Updated docker image to demisto/genericsql:1.1.0.96566. PR batch #1/1 (demisto#34760) Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com> * Update demisto/powershell-teams image tag * Update ConfigureAzureApplicationAccessPolicy RN * Update demisto/xsoar-tools image --------- Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jul 3, 2024
…emisto#35185) * Updated docker image to demisto/googleapi-python3:1.0.0.100240. PR batch #1/1 (demisto#35145) * Updated docker image to demisto/bs4:1.0.0.76921. PR batch #1/1 (demisto#35144) * Updated docker image to demisto/lacework:1.0.0.100340. PR batch #1/1 (demisto#35146) * Updated docker image to demisto/netmiko:1.0.0.100251. PR batch #1/1 (demisto#35147) * Update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Jul 4, 2024
…emisto#35231) * Updated docker image to demisto/yolo-coco:1.0.0.98891. PR batch #1/1 (demisto#35205) * Updated docker image to demisto/ibm-db2:1.0.0.100241. PR batch #1/1 (demisto#35204) * Updated docker image to demisto/feed-performance-test:1.0.99137. PR batch #1/1 (demisto#35203) * Update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
…emisto#35288) * Updated docker image to demisto/bs4-py3:1.0.0.100299. PR batch #1/1 (demisto#35137) * Updated docker image to demisto/jq:1.0.0.100247. PR batch #1/1 (demisto#35139) * Updated docker image to demisto/unzip:1.0.0.100283. PR batch #1/1 (demisto#35141) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python-phash:1.0.0.100267. PR batch #1/1 (demisto#35140) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * demisto/cloudshare:1.0.0.73056 | 0-100 | PR batch #1/1 (demisto#35138) * Updated docker image to demisto/cloudshare:1.0.0.73056. PR batch #1/1 * Fix text encoding --------- Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com> Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Update RN --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
…emisto#35310) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #1/19 (demisto#35234) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #9/19 (demisto#35242) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #8/19 (demisto#35241) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #7/19 (demisto#35240) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #4/19 (demisto#35237) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #11/19 (demisto#35244) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #19/19 (demisto#35252) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #3/19 (demisto#35236) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #10/19 (demisto#35243) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #12/19 (demisto#35245) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.100715. PR batch #13/19 (demisto#35246) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.100715. PR batch #14/19 (demisto#35247) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.100715. PR batch #17/19 (demisto#35250) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * demisto/python3:3.10.14.100715 | 0-100 | PR batch #15/19 (demisto#35248) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #15/19 * Fix text encoding * Update Pulsedive.yml --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * demisto/python3:3.10.14.100715 | 0-100 | PR batch #16/19 (demisto#35249) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #16/19 * Update ThousandEyes.yml --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * demisto/python3:3.10.14.100715 | 0-100 | PR batch #2/19 (demisto#35235) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #2/19 * pre-commit fixes * fix --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/python3:3.10.14.100715 | 0-100 | PR batch #6/19 (demisto#35239) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #6/19 * Empty commit * fixes * fix * space * fix --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/python3:3.10.14.100715 | 0-100 | PR batch #5/19 (demisto#35238) * Updated docker image to demisto/python3:3.10.14.100715. PR batch #5/19 * fixes * Empty commit * Empty commit * Empty commit * Empty commit --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> Co-authored-by: inbalapt1 <164751454+inbalapt1@users.noreply.github.com> * Updated docker image to demisto/python3:3.10.14.100715. PR batch #18/19 (demisto#35251) Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> * Update RN * Empty commit to re-trigger build pipeline --------- Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> Co-authored-by: inbalapt1 <164751454+inbalapt1@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
…emisto#35344) * Updated docker image to demisto/ansible-runner:1.0.0.102086. PR batch #1/1 (demisto#35324) * Updated docker image to demisto/chromium:126.0.6478.102778. PR batch #1/1 (demisto#35325) * Update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
…demisto#35346) * demisto/powershell:7.4.0.80528 | 0-100 | PR batch #1/1 (demisto#35333) * Updated docker image to demisto/powershell:7.4.0.80528. PR batch #1/1 * fixes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/py3-tools:1.0.0.102774 | 0-100 | PR batch #2/2 (demisto#35335) * Updated docker image to demisto/py3-tools:1.0.0.102774. PR batch #2/2 * fixes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/py3-tools:1.0.0.102774 | 0-100 | PR batch #1/2 (demisto#35334) * Updated docker image to demisto/py3-tools:1.0.0.102774. PR batch #1/2 * fixes * fix * fix --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * Updated docker image to demisto/python3-deb:3.11.9.102626. PR batch #1/1 (demisto#35336) * Update release notes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
* change path to relative md files integrations A-D * fix docker * fix docker * fix docker * fix DS108 * ignore rm112 * fix ds108 * type annotation fix (demisto#35317) * type annotation fix * RN * revert pack version bump * BmcITSM- fix duplicate incidents (demisto#35192) * adding logs * adding a fix to the last ticket create time * adding unit test to demonstrate the bug * adding the fix+precommit_rn * adding reason * docker fix * add to known words * Update Packs/BmcITSM/ReleaseNotes/1_0_23.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * cr fix * cr note * cr note --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * [CortexXpanse] Option to add tags to assets (demisto#35111) (demisto#35316) * change content * RN * update play * fix val error * Apply suggestions from code review * Apply suggestions from code review * John feedback * sasha recommendations * bump ver * removed (s) in survey title * update screenshot --------- Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Anomali bug (demisto#35060) * updated the authentication process, due to api changes * added rn * updated unit test * removed comment * updated do * Aws waf regions (demisto#35276) * added more regions to the region param * added rn * added regions as args as well * updated docker image * Fix Fetch-Alerts Microsoft Defender for Cloud Apps (demisto#35083) * fix the fetches issue * fix the fetches issue * RN * Update Packs/MicrosoftCloudAppSecurity/ReleaseNotes/2_2_1.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Bump google-cloud-compute from 1.19.0 to 1.19.1 (demisto#35314) Bumps [google-cloud-compute](https://github.com/googleapis/google-cloud-python) from 1.19.0 to 1.19.1. - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-compute-v1.19.0...google-cloud-compute-v1.19.1) --- updated-dependencies: - dependency-name: google-cloud-compute dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Skip python2 not support csp test (demisto#35328) * Skip python2 not supported test * [ASM] EXPANDR-9733 Cortex ASM Patching files (demisto#35114) (demisto#35332) * Patching ASM files * read me fix * add description * fixes * fixes * fixes * updated version * updated version * core pack dependency * added misc suggestions * added misc suggestions Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> * fix-ews-get-attachment (demisto#35315) * fix-ews-get-attachment * add RN * rn * Fix for XSOAR automation insights dashboard (demisto#35292) * added the relevant script to the metrics * added rn * fix * pre commit * fix * updated RN after revert * Update Packs/CommonDashboards/ReleaseNotes/1_7_4.md Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com> --------- Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com> * Fix modify edl playbook (demisto#35338) * fix modify edl playbook * added rn * fixes * add type to set incident * fixes * Update Packs/EDL/Playbooks/Modify_EDL.yml * Update Packs/EDL/Playbooks/Modify_EDL.yml * fix * fix * fix * fix * fix * fix * Zimperuim_v2_playbook (demisto#35259) * support for zimperium v2 * RN * update mapper * rn conflict * update docker ver * Fix misslocated images (demisto#35339) * moved doc files * relocate * relocate * update readme * update dockers * added rn * fixes * update contribution team members. (demisto#35330) * Update 1_34_26.md (demisto#35343) * ipv6 regex fix (demisto#35279) * ipv6 fix * docker * RN * RN * Bump pack from version CommonScripts to 1.15.23. * Bump pack from version CommonScripts to 1.15.24. * tests playbook * Update Packs/CommonScripts/ReleaseNotes/1_15_24.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CommonTypes/ReleaseNotes/3_5_7.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * pb fix * Bump pack from version CommonScripts to 1.15.25. --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * [Auto Update Docker] AUD-demisto/auto_update_docker_staging_branch_5 (demisto#35344) * Updated docker image to demisto/ansible-runner:1.0.0.102086. PR batch #1/1 (demisto#35324) * Updated docker image to demisto/chromium:126.0.6478.102778. PR batch #1/1 (demisto#35325) * Update release notes * [Auto Update Docker] AUD-demisto/auto_update_docker_staging_branch_10 (demisto#35346) * demisto/powershell:7.4.0.80528 | 0-100 | PR batch #1/1 (demisto#35333) * Updated docker image to demisto/powershell:7.4.0.80528. PR batch #1/1 * fixes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/py3-tools:1.0.0.102774 | 0-100 | PR batch #2/2 (demisto#35335) * Updated docker image to demisto/py3-tools:1.0.0.102774. PR batch #2/2 * fixes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * demisto/py3-tools:1.0.0.102774 | 0-100 | PR batch #1/2 (demisto#35334) * Updated docker image to demisto/py3-tools:1.0.0.102774. PR batch #1/2 * fixes * fix * fix --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * Updated docker image to demisto/python3-deb:3.11.9.102626. PR batch #1/1 (demisto#35336) * Update release notes --------- Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * Tenable fetch bug (demisto#35327) * fixed an issue with 404 error status code * added rn * Update Packs/Tenable_io/ReleaseNotes/2_2_5.md * Ciac 9706 (demisto#34564) * Test for CIAC 10315 * Test for CIAC 10315 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * Ciac 9706 * [CoreRESTApi] Fix httpMultipart loop (demisto#35265) * init * bump version * [Auto Update Docker] AUD-demisto/auto_update_docker_staging_branch_11 (demisto#35352) * Replace PopularNews docker image to demisto/bs4-py3 * Update RN * increased the memo for EWS Public Folders Test (demisto#35320) * CIAC-10305 Fortinet Fortigate XDM Modeling Enhancement (demisto#35311) * sort xdm fields * sort schema fields * enrich modeling rules * update release notes * fix release notes * fix schema * update schema * fixes and refactoring * fix schema * remove source application mapping * update release-notes * update release-notes * update README.md * reformat fields on release notes * concise release note * fix schema * Rewrite Whois (demisto#35050) * first commit * add yaml config * create test playbook, update docs, add ReleaseNotes * fix doc-review issues * demo issues * Change instance name for old test playbooks * update test playbook * cr issues * add abuse felid * Doc review * Akamai waf event collector missing and duplicated events issue (demisto#35350) * fixes * added rn * fixes * test fixes * Update Packs/Akamai_SIEM/ReleaseNotes/1_1_5.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * [Marketplace Contribution] - EXPANDR-7038 - Azure Resource Graph (demisto#35326) * [Marketplace Contribution] - EXPANDR-7038 - Azure Resource Graph (demisto#32121) * Add Pack ReadMe * Add integration * Add integration description, image, and secrets ignore file * Add metadata file and pack ignore * Add test files and tests first * Add Integration ReadMe * Update marketplaces * Update commands descriptions and output * Update secrets ignore * Resize image * Update integration yml commands * Update integration readme * Resize image * Address doc review and some design review comments * Update client credential flow section of ReadMe * Update list_operations_command to support a limit argument * Update azure-rg-list-operations in ReadMe * Update azure-rg-list-operations to support paging * Update azure-rg-query to support paging * Update tests * Remove Comments * Update integration configuration yml settings * Add management_groups & subscriptions parameters for query command * Add suggested changes from second review * Update Readme and Description from code review * Update integration files with code review suggestions * Update defaultValue key in YAML and docker version * Update section titles in YAML * Remove subscription_id from client and format - Subscription ID is not used during configuration - Fixed usage of wrong variable in query command * Remove DefaultValues - The default values are not necessary and would make the conditionals for limits and paging more complex * Update ReadMe * Formatting * Remove subscription_id from client in test file * Update tests and fix mypy errors * Update address mypy errors * Update README.md * Apply suggestions from code review * Update README.md --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> * DisplyHTMLWIthImages: fix embeded images (demisto#35135) * potential fix * update RN * Bump pack from version CommonScripts to 1.15.20. * Bump pack from version CommonScripts to 1.15.21. * Bump pack from version CommonScripts to 1.15.22. * Bump pack from version CommonScripts to 1.15.23. * Bump pack from version CommonScripts to 1.15.24. * Bump pack from version CommonScripts to 1.15.25. * fix * pre commit fix * Bump pack from version CommonScripts to 1.15.26. * cr changes * CR changes --------- Co-authored-by: Content Bot <bot@demisto.com> * Update docker ml (demisto#35081) * updated docker * added the rest * devdemisto/ml:1.0.0.100486 * fix tpb * return on no incidents * remove runonce * remove space * fixed * fix create incidents script * new docker * revert: fix create incidents script * add outputs to DBotFindSimilarIncidents * new tpb DBotFindSimilarIncidents-test * new docker * bump transformers * Empty-Commit * fix conf.json * more fixes * more fixes * new docker * RN * new docker * revert dockers * more stuff * redirect stderr * docker * format * format * RN * more stuff * build fixes * build fixes * fix unit-tests * more docker changes * more docker changes * build fixes * suppress logger * build fixes * build fixes * Fix ruff in CofenseTriage (demisto#35373) * fix ruff in CofenseTriage * test with infra * revert infra test * revert infra test * Raise armis event collector default limit (demisto#35371) * raise limit * update rn * Update Packs/Armis/Integrations/ArmisEventCollector/ArmisEventCollector_description.md Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> * fixes * fixes * fixes * update docker --------- Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> * Fix for 'Search For Hash In Sandbox - Generic' playbook (demisto#35354) * Fix for 'Search For Hash In Sandbox - Generic' playbook * revert unnecessary changes made by 'generate-docs' command * Update playbook-Search_For_Hash_In_Sandbox_-_Generic.yml revert unnecessary changes made by 'format' command * Update playbook-Search_For_Hash_In_Sandbox_-_Generic.yml revert unnecessary changes made by 'format' command * RN * changed the context path checked in task number 45 * CrowdStrike Falcon - Raptor release (demisto#34805) * configuration changes * rn * deprecation * readme deprecation * resolve-identity-detection * test * fix conflict * cs-falcon-search-detection * unit test * !cs-falcon-resolve-detection * cs-falcon-list-detection-summaries * fix the filter * fix * fix tests * fixes * fix * add CrowdStrike.Detections.behaviors.behavior_id * fix outputs of list-detection-summaries * finally outputs for cs-falcon-list-detection-summaries * test * fetch * mirroring * existing fetch * new fetch * add tests * revert unnecessary changes in the mapper * fix the query * fix * fis tests * last mapper * fix mapper * mirroring of new type * fixes from cr * fix * remove the raptor from the tests * fix tests * fixes * fix old mapper * legacy * RN * rn * metadata * pre commit * build fixes * build fixes #2 * Apply suggestions from code review Shirley fixes Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * More from Shirley Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * cr * cr * format * adding testing the parameters * Bump pack from version CommonTypes to 3.5.8. * fix test * cr * logs * fix a mistake * pre commit * RN * fix rn * fix rn * fix validate errors * fix test playbook * pre commit * format * RN * change output * fix test playbook --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * [Google Threat Intelligence] Add curated collections commands and improve polling commands (demisto#35376) * [Google Threat Intelligence] Add curated collections commands and improve polling commands (demisto#35348) * [GoogleThreatIntelligence] Add GTI assessment to polling commands * Lint * Add curated collections commands * Add test * Lint * Lint * Update release note * Add Feed Integration * Lint * Update Packs/GoogleThreatIntelligence/Integrations/CategorizedFeeds/CategorizedFeeds.py Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/Integrations/CategorizedFeeds/CategorizedFeeds.yml Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/Integrations/CategorizedFeeds/CategorizedFeeds_description.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/Integrations/CategorizedFeeds/README.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/Integrations/CategorizedFeeds/README.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Include feed type in table * Incremental feed * Delete feed integration * Update Packs/GoogleThreatIntelligence/ReleaseNotes/1_0_1.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/ReleaseNotes/1_0_1.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update Packs/GoogleThreatIntelligence/ReleaseNotes/1_0_1.md Co-authored-by: Daniel Pascual <danielvazquez@google.com> * Update yml * Update Packs/GoogleThreatIntelligence/ReleaseNotes/1_0_1.md Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> * Update Packs/GoogleThreatIntelligence/Integrations/GoogleThreatIntelligence/GoogleThreatIntelligence.py Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> * Update Packs/GoogleThreatIntelligence/Integrations/GoogleThreatIntelligence/GoogleThreatIntelligence.py Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> * Update Packs/GoogleThreatIntelligence/Integrations/GoogleThreatIntelligence/GoogleThreatIntelligence.py Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> --------- Co-authored-by: Daniel Pascual <danielvazquez@google.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> * add docs for commands --------- Co-authored-by: Pablo Pérez <122302023+pabloperezj@users.noreply.github.com> Co-authored-by: Daniel Pascual <danielvazquez@google.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: ipolishuk <ipolishuk@paloaltonetworks.com> * Fix SNOW files mirroring issue (demisto#35298) * fix XSUP-37069 * fix XSUP-37069 * fix * CR fix * remove prints * docker update * XSUP-38544/DisplayHtmlWithImages/fix_text_color (demisto#35367) * Updated the html text color to black * updated release notes * ruff on test file * Update Packs/CommonScripts/ReleaseNotes/1_15_26.md Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com> * fixed cr notes * fix conflicts * updated RN * updated RN * updated RN * updated RN --------- Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com> * remove IN150 from validation_config.toml (demisto#35378) * remove IN150 and IN161 from validation_config.toml * bring IN161 back * Update docker mlurlphishing (demisto#35272) * init * new docker * add tpb * update docker * update RN * Bump pack from version CommonScripts to 1.15.28. --------- Co-authored-by: adi88d <adaud@paloaltonetworks.com> Co-authored-by: Adi Daud <46249224+adi88d@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * Ciac 10278 pat enhancement (demisto#35345) * Fix fields * Add docs * Revert docs * Update README.md * Address pre-commit * Address validations * Remove redundant field * Address pre-commit * Fix imports * Fix imports * Ignore ruff * [Demisto Lock] add `polling_interval` to `demisto-lock-get` command (demisto#35374) * Add new polling_interval * Update RN * Add Wizard for Prisma Compliance usecase (demisto#35296) * Add Wizard for Prisma Compliance usecase * Update wizard name * Add second playbook * Update wizard json * Remove sandbox section * Update min_required dependency * Update supporting integrations * Update release notes * Update fetching integration name * Fix integration name in description * Add support for [Get/Export/Release]-QuarantineMessage to EWSO PS v3 (demisto#35267) (demisto#35387) * Add support for [Get/Export/Release]-QuarantineMessage to EWSO PS v3 * Remove unused params from EwsExtensionEXOPowershellV3 * Convert true/false values to boolean for *-QuarantineMessage commands in EWSOv3 * Streamline outputs of *-QuarantineMessage for EwsExtensionEXOPowershellV3 * Update EWSOv3 README.md * Disallow PSObjects to return $null * Fix context path in README.md * Fix table in README.md * Standardise quotes in EwsExtensionEXOPowershellV3.yml * Update EWSOv3 README.md * Update documentation * Exit ExoReleaseQuarantineMessage when identity or identities not present * Update content pack to 1.4.0 * Fix integration name in 1_4_0.md Co-authored-by: Aster Bandis <68644945+bandisast@users.noreply.github.com> * PrismaCloud V2 dashboard update (demisto#35106) (demisto#35369) * prismaCloud dashboard update adding sourcebrand for prismacloud v2 to the dashboard to include incidents from that integration. * Update 4_3_7.md updating to catch the syntax issues in release notes * Update 4_3_7.md updated release notes * Update 4_3_7.md release notes update * Update Packs/PrismaCloud/ReleaseNotes/4_3_7.md --------- Co-authored-by: epartington <epartington@users.noreply.github.com> Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com> Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> * Ciac 5471 exabeam fetch users (demisto#34900) * add section to yml * add command fetch_notable_users * fix referenced before assignment * format * fix fetch_notable_users * fix set_integration_context * clear TODO * add reset-notable-users-cached and classifier * add Exabeam Notable User to IncidentFields * add incident layout mapper and type * add limit to context * pre commit * rename pack & integration * add incidentType to mapping * update layout * rename incident field * add UT * update dockerimage * update layout & release note * Merge branch 'master' of github.com:demisto/content into ciac-5471-exabeam-fetch-users * add checkbox fetch_user_duplicates * replace name parameter Fetch user duplicates * release notes * fix name of filed * fix incidentfield * ReleaseNotes * IncidentFields * peck metadata * ReleaseNotes * rename incident fide in mapper * return name incident fide * mapping * ReleaseNotes * add filed to mapping * add Multi Select type fetch * fix UT * save in last run instead of context * - dev * fix layout * try to fix GR103 * fix in ReleaseNotes * ReleaseNotes * document review * Bump pack from version CommonTypes to 3.5.7. * document review * remove command reset-notable-users-cached * update readme about the fetch * Fix from CR * Add validation for interval * update docker * Updated Docker image in ReleaseNotes * Bump pack from version CommonTypes to 3.5.8. * add test to test_module * Bump pack from version CommonTypes to 3.5.9. * fix time_period --------- Co-authored-by: Content Bot <bot@demisto.com> * [Marketplace Contribution] Common Scripts - Content Pack Update (demisto#35178) * [Marketplace Contribution] Common Scripts - Content Pack Update (demisto#35115) * "contribution update to pack 'Common Scripts'" * pack resubmitted --------- Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> * add typing * add typing * more fixes * more fixes * more fixes * more fixes * more stuff * build fixes * build fixes * UTs complete * docs * marketplace selection * RN * docker * Bump pack from version CommonScripts to 1.15.29. --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> Co-authored-by: jlevypaloalto <jlevy@paloaltonetworks.com> Co-authored-by: Content Bot <bot@demisto.com> * Xsup 39381 joesecurity file value (demisto#35408) * Changed indicator to be sha256 * fixed ut * added rn * Bumped docker * Bumped RN * Bumped dicker * Update Packs/JoeSecurity/ReleaseNotes/1_1_23.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Fix CS Falcon Reopen Statuses parameter doesn't have any value (demisto#35366) * allow empty reopen status list * RN * fixed a test * Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_13_14.md Co-authored-by: Shelly Tzohar <45915502+Shellyber@users.noreply.github.com> --------- Co-authored-by: Shelly Tzohar <45915502+Shellyber@users.noreply.github.com> * Revert "checking ignore rm108 (demisto#35291)" (demisto#35318) This reverts commit 238b27d. * poetry files (demisto#35419) Co-authored-by: Content Bot <bot@demisto.com> * remove /n in html (demisto#35381) * fix * rn_pa * reply fix * fix rn * Bump pack from version MicrosoftExchangeOnline to 1.4.1. * docker-image * rn --------- Co-authored-by: Content Bot <bot@demisto.com> * [Marketplace Contribution] Common Scripts - Content Pack Update (demisto#35407) * [Marketplace Contribution] Common Scripts - Content Pack Update (demisto#35297) * "contribution update to pack 'Common Scripts'" * resolved rebase conflicts --------- Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> * add TPB * resolve conflicts * add TPB to conf.json and yml file * Bump pack from version CommonScripts to 1.15.30. * commit * remove new tpb from conf json --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: ipolishuk <ipolishuk@paloaltonetworks.com> Co-authored-by: Content Bot <bot@demisto.com> * SplunkPy: fix bug in drilldown enrichemnt (demisto#35368) * fix + RN * fix pre commit * Apply suggestions from code review Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com> --------- Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com> * Cisco ASA CRTX-121323 Invert Peer Direction Roles on relevant Teardown Events (demisto#35380) * apply network peers direction swap on teardown * minor-fixes * update release-notes * update release-notes * reformat README.md * Update Packs/CiscoASA/ReleaseNotes/1_1_7.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Un-skip the ruff hook for autoupdate docker PRs (demisto#35413) * Un-skipped the ruff hook for autoupdate docker PRs * Un-skipped the pytest-network-in-docker hook for autoupdate docker prs * added to pack ignore the validation MR108 for Tenable_io.yml (demisto#35415) * added to pack ignore the validation MR108 for Tenable_io.yml --------- Co-authored-by: noy <nodavidi.paloaltonetworks.com> * update feed-performance-test docker (demisto#35423) * update feed-performance-test docker * fix DS108 * Lookup CSV output fix (demisto#35418) * Added the outputs LookupCSV.Result * Added release notes * Updated readme file * Fixed validation * CR Fix * Bump pack from version CommonScripts to 1.15.31. * CR Fix --------- Co-authored-by: Content Bot <bot@demisto.com> * Ewso365 bug (demisto#35351) * fixed an issue where re-registering a header failed * added rn * edited the unittest * Bump pack from version MicrosoftExchangeOnline to 1.4.1. * fixed conflict in rn --------- Co-authored-by: Content Bot <bot@demisto.com> * CIAC-9928 - OpenLDAP ad-entries-search (demisto#35165) * started implementing ad-entries-search * yml and finished implemntation * finished implementing ad-entries-search * finished implementing ad-entries-search * and for provided filters * updated yml * readme * pr comments * pr comments * pr comments * pr comments * pr comments * unitests * readme * Update Packs/OpenLDAP/Integrations/OpenLDAP/OpenLDAP.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/OpenLDAP/Integrations/OpenLDAP/OpenLDAP.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/OpenLDAP/Integrations/OpenLDAP/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/OpenLDAP/Integrations/OpenLDAP/OpenLDAP.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/OpenLDAP/Integrations/OpenLDAP/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * added doc string to tests --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> * Update ml dockers (demisto#35422) * update ml dockers * bump RN * fix_azure_sc_tpb (demisto#35428) * fixed the tpb * fixed the names * sdk format * bug - MD EC added debug logs (demisto#35425) * bug - MD EC added debug logs * fix pre-commit * more logs * fix logs * Update MicrosoftDefenderEventCollector.py --------- Co-authored-by: rshunim <rshunim@paloaltonetworks.com> Co-authored-by: rshunim <102469772+rshunim@users.noreply.github.com> * Yc/carbon black/ciac 9132 (demisto#35202) * Existing commands migration to the new endpoints * cbd-find-processes polling command added * added cbd-find-observation-details polling command * new version all existing commands including polling commands * added validations for required args, and cleaning * device commands added * added docs string in client functions * added docs string to all comands * description file added * mapper updated to the new response format * docs and type ignore * update and set policy commands added * done * readme file added for all commands * Migration notes added * removed -dev * test file with all commands tests * fixed build * added RN and tests * pre-commit * pre commit * format * added release note and updated docker image * rewrite * handle priority_level in CamelCase arg * docs review * docs review * deleted unneeded duplicates * Update Packs/CarbonBlackDefense/ReleaseNotes/4_0_0.md Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com> * format fixed --------- Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com> * add ThreatCrowd to skipped (demisto#35433) * Update logo to align to common prisma cloud logo (demisto#35322) * Update logo to align to common prisma cloud logo (demisto#35113) Updated logo to align to common prisma cloud logo * bump docker version. * RN change. * Bump pack from version PrismaCloud to 4.3.8. --------- Co-authored-by: epartington <epartington@users.noreply.github.com> Co-authored-by: Danny_Fried <dfried@paloaltonetworks.com> Co-authored-by: Content Bot <bot@demisto.com> * Impartner community pack (demisto#35430) * [ThreatConnectV3] Support Python 3.11 (demisto#35432) * fix * RN * Adding a command to add VM to cleanroom recovery group and changing the integration name (demisto#35229) (demisto#35411) * Changes * Add VM to cleanroom recovery group Adding command to add VM to cleanroom recovery group * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Update pack_metadata.json * remove commented code Co-authored-by: Cv-securityIQ <135146895+Cv-securityIQ@users.noreply.github.com> * Add new parameters for Sophos Central API (demisto#35357) (demisto#35412) * Add new parameters for Sophos Central API * Add contributors file * Increase version and add release notes * Update docker image * Optimize ip address parameter routine * Use argToList function * Update release notes to represent changes * Use argToBoolean for boolean parameter * Set default value for argToBoolean Co-authored-by: Nik Stuckenbrock <35262568+nikstuckenbrock@users.noreply.github.com> * Fix dynammo tpb (demisto#35406) * fix-tpb * delete-from-skipped-tests * delete hard coded * Update Packs/AWS_DynamoDB/TestPlaybooks/playbook-AWS-DynamoDB-Test.yml Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com> --------- Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com> * CIAC-10816-Bitwarden-Password-Manager-Event-Collector (demisto#35191) * init * stash * auth, fetch events * wip * wip * add fetch, and get with start and end * update yml file * add comment * fix main function * Update Packs/BitwardenPasswordManager/pack_metadata.json Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * wip * wip * Update Packs/BitwardenPasswordManager/pack_metadata.json Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/Integrations/BitwardenPasswordManagerEventCollector/BitwardenPasswordManagerEventCollector.yml Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/Integrations/BitwardenPasswordManagerEventCollector/BitwardenPasswordManagerEventCollector.yml Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * add readme and description * remove end date, update category * combine get_events to fetch_events * wip * remove logs * update readme * add image * fixing readability * use last fetch as start time * add end time to params * add end time to params * fix start+end time * remove event collector naming * add get_unique_events * fix types * wip * wip * wip * pr fixes * wip * add docstring to fetch_events * add pack readme * update readme * add unit tests * fix defaults dates format * pre commit changes * ignore IN150 validation * upgrade docker image * add nmock api url to secret ignore * ran format * add debug command * pre-commit changes * remove debug command * Update Packs/BitwardenPasswordManager/Integrations/BitwardenPasswordManager/BitwardenPasswordManager.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/Integrations/BitwardenPasswordManager/BitwardenPasswordManager_description.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/Integrations/BitwardenPasswordManager/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/BitwardenPasswordManager/README.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * change category * fix pack readme --------- Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * fix fetch-incidents returns duplicates bug (demisto#35424) * fix bug and testing and readme * readme * release notes * change argument name * pre commit * code review fixes * more code review fixes * limit+1 * shirly fixes and changed sort field * remove the dev * run pre commit * last fixes * typo fixes * rename splunk host display name (demisto#35431) * rename splunk host display name * update code and readme * test * bug - ansible dockerimage revert (demisto#35442) * bug - ansible dockerimage revert * format * Update 1_0_7.md * fix (demisto#35414) Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> * [ASM] - EXPANDER - 10154 Service Ownership Playbook ASM ServiceOwners and Ranking Score Fix (demisto#35388) * [ASM] - EXPANDER - 10154 Service Ownership Playbook ASM ServiceOwners and Ranking Score Fix (demisto#35091) * Update RankServiceOwners task to check that "accounttype" does not exist for service owners * Update release notes * Update RankServiceOwners task owners argument * Update Ranking Score key in asmserviceowner field * Update ReadMe * Update ReadMe * Update release notes * Update Packs/CortexAttackSurfaceManagement/ReleaseNotes/1_7_42.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update release notes * Update Release Version --------- Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * RN add desc under Incident Fields --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Danny_Fried <dfried@paloaltonetworks.com> * Cyberark Endpoint bug (demisto#35275) * added logs * edit * added support to platform url * removed test integration * fixed applying the update * edited unittests --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com> Co-authored-by: darbel <darbel@paloaltonetworks.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com> Co-authored-by: rshunim <102469772+rshunim@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Chait A <112722030+capanw@users.noreply.github.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: Karina Fishman <147307864+karinafishman@users.noreply.github.com> Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com> Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com> Co-authored-by: OmriItzhak <115150792+OmriItzhak@users.noreply.github.com> Co-authored-by: Danny Fried <dfried@paloaltonetworks.com> Co-authored-by: Dror Avrahami <davrahami@paloaltonetworks.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> Co-authored-by: Edi Katsenelson <85438368+edik24@users.noreply.github.com> Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com> Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com> Co-authored-by: cweltPA <129675344+cweltPA@users.noreply.github.com> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: Jasmine Beilin <71636766+JasBeilin@users.noreply.github.com> Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com> Co-authored-by: Yaakov Praisler <59408745+yaakovpraisler@users.noreply.github.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: TalNos <112805149+TalNos@users.noreply.github.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: Pablo Pérez <122302023+pabloperezj@users.noreply.github.com> Co-authored-by: Daniel Pascual <danielvazquez@google.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: ipolishuk <ipolishuk@paloaltonetworks.com> Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com> Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com> Co-authored-by: adi88d <adaud@paloaltonetworks.com> Co-authored-by: Adi Daud <46249224+adi88d@users.noreply.github.com> Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com> Co-authored-by: Erez FelmanDar <102903097+efelmandar@users.noreply.github.com> Co-authored-by: Aster Bandis <68644945+bandisast@users.noreply.github.com> Co-authored-by: epartington <epartington@users.noreply.github.com> Co-authored-by: YairGlik <148229942+YairGlik@users.noreply.github.com> Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: jlevypaloalto <jlevy@paloaltonetworks.com> Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: Shelly Tzohar <45915502+Shellyber@users.noreply.github.com> Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com> Co-authored-by: noydavidi <77931201+noydavidi@users.noreply.github.com> Co-authored-by: Maya Goldman <94686128+mayyagoldman@users.noreply.github.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> Co-authored-by: rshunim <rshunim@paloaltonetworks.com> Co-authored-by: yedidyacohenpalo <162107504+yedidyacohenpalo@users.noreply.github.com> Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> Co-authored-by: Cv-securityIQ <135146895+Cv-securityIQ@users.noreply.github.com> Co-authored-by: Nik Stuckenbrock <35262568+nikstuckenbrock@users.noreply.github.com> Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com> Co-authored-by: ilaredo <166304750+ilaredo@users.noreply.github.com> Co-authored-by: Yael Shamai <111040837+YaelShamai@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
) * Updated docker image to demisto/office-utils:2.0.0.103232. PR batch #1/1 * release notes * bump image * Bump pack from version CommonScripts to 1.15.47. * Bump pack from version CommonScripts to 1.15.48. * precommit * Bump pack from version CommonScripts to 1.15.49. * Bump pack from version CommonScripts to 1.15.50. --------- Co-authored-by: Judah Schwartz <juschwartz@paloaltonetworks.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
* Updated docker image to demisto/smbprotocol:1.0.0.112286. PR batch #1/1 (demisto#36482) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/stringsifter:3.20230711.112287. PR batch #1/1 (demisto#36481) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/yarapy:1.0.0.112291. PR batch #1/1 (demisto#36480) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/snowflake:1.0.0.112285. PR batch #1/1 (demisto#36479) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/ansible-runner:1.0.0.112234. PR batch #2/2 (demisto#36478) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/ansible-runner:1.0.0.112234. PR batch #1/2 (demisto#36477) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/netmiko:1.0.0.112262. PR batch #1/1 (demisto#36476) Co-authored-by: root <root@1e2de18e0cc3> --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
…tch #1/1 (demisto#36504) (demisto#36525) Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
* Updated docker image to demisto/py3ews:5.4.3.112092. PR batch #1/1 (demisto#36622) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/crypto:1.0.0.111961. PR batch #1/4 (demisto#36623) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/crypto:1.0.0.111961. PR batch #2/4 (demisto#36624) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/crypto:1.0.0.111961. PR batch #3/4 (demisto#36625) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/crypto:1.0.0.111961. PR batch #4/4 (demisto#36626) Co-authored-by: root <root@1e2de18e0cc3> --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 8, 2024
* Updated docker image to demisto/googleapi-python3:1.0.0.112316. PR batch #2/2 (demisto#36495) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/googleapi-python3:1.0.0.112316. PR batch #1/2 (demisto#36494) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/google-cloud-translate:1.0.0.112239. PR batch #1/1 (demisto#36493) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/pcap-http-extractor:1.0.0.112272. PR batch #1/1 (demisto#36492) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/xpanse-ml-ev2:1.0.0.112461. PR batch #1/1 (demisto#36491) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/readpdf:1.0.0.112283. PR batch #1/1 (demisto#36490) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/unzip:1.0.0.112289. PR batch #1/1 (demisto#36489) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/bigquery:1.0.0.112225. PR batch #1/1 (demisto#36486) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Maya Goldman <94686128+mayyagoldman@users.noreply.github.com> * Updated docker image to demisto/google-kms:1.0.0.112242. PR batch #1/1 (demisto#36485) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/ssdeep:1.0.0.112284. PR batch #1/1 (demisto#36484) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/qrcode:1.0.0.112357. PR batch #1/1 (demisto#36483) Co-authored-by: root <root@1e2de18e0cc3> * demisto/python3-deb:3.11.10.112166 | 0-100 | PR batch #1/1 (demisto#36488) * Updated docker image to demisto/python3-deb:3.11.10.112166. PR batch #1/1 * ruff py datetime-timezone-utc (UP017) * ruff py datetime-timezone-utc (UP017) * ruff py datetime-timezone-utc (UP017) * exclude from native --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: mayagoldman <mgoldman@paloaltonetworks.com> Co-authored-by: Maya Goldman <94686128+mayyagoldman@users.noreply.github.com> * demisto/google-api-py3:1.0.0.112317 | 0-100 | PR batch #1/1 (demisto#36487) * Updated docker image to demisto/google-api-py3:1.0.0.112317. PR batch #1/1 * ruff py datetime-timezone-utc (UP017) * ruff py datetime-timezone-utc (UP017) * exclude from native --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: mayagoldman <mgoldman@paloaltonetworks.com> Co-authored-by: Maya Goldman <94686128+mayyagoldman@users.noreply.github.com> * updated release notes * Update 1_15_73.md * remove palce holder --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 20, 2024
* demisto/chromium:131.0.6778.116585 | 0-100 | PR batch #1/1 (demisto#37221) * Updated docker image to demisto/chromium:131.0.6778.116585. PR batch #1/1 * Update rasterize.yml --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: inbalapt1 <164751454+inbalapt1@users.noreply.github.com> * release-notes --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 20, 2024
* Updated docker image to demisto/powershell:7.4.6.116823. PR batch #1/1 (demisto#37283) Co-authored-by: root <root@1e2de18e0cc3> * update release notes --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 20, 2024
* demisto/py3-tools3:1.0.0.116158 | 0-100 | PR batch #1/1 * update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Nov 21, 2024
* update 3.10.13.72123 * update tags * update * update 3.10.12.66339 * update 3.11.10.116439 * update 3.10.13.80014 * update 3.10.13.75921 * update 3.10.13.73190 * updates * release notes * update release notes * update 3.10.13.74666 * update release notes * update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Nov 21, 2024
* Updated docker image to demisto/pwsh-infocyte:1.1.0.116826. PR batch #1/1 (demisto#37311) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/pycountry:1.0.0.117224. PR batch #1/1 (demisto#37308) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/pyotrs:1.0.0.117228. PR batch #1/1 (demisto#37312) Co-authored-by: root <root@1e2de18e0cc3> * demisto/bottle:1.0.0.117147 | 0-100 | PR batch #1/1 (demisto#37310) * Updated docker image to demisto/bottle:1.0.0.117147. PR batch #1/1 * remove webfilerepository - timezone --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * Updated docker image to demisto/sixgill:1.0.0.117239. PR batch #1/1 (demisto#37309) Co-authored-by: root <root@1e2de18e0cc3> --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 21, 2024
* Updated docker image to demisto/taxii:1.0.0.116749. PR batch #1/1 (demisto#37292) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/mlclustering:1.0.0.117108. PR batch #1/1 (demisto#37293) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/sane-pdf-reports:1.0.0.117145. PR batch #1/1 (demisto#37294) Co-authored-by: root <root@1e2de18e0cc3> * Update DBotTrainClustering.yml * update release notes --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 21, 2024
demisto#37285) * demisto/python3:3.11.10.116439, demisto/boto3py3:1.0.0.116921, demisto/auth-utils:1.0.0.116930 | 0-100 | PR batch #1/1 * update to UTC + docker native image * remove import timezone * update release notes
DNRRomero
pushed a commit
that referenced
this pull request
Nov 27, 2024
* Updated docker image to demisto/office-utils:2.0.0.117112. PR batch #1/1 (demisto#37355) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/taxii2:1.0.0.117320. PR batch #1/1 (demisto#37356) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/bs4-py3:1.0.0.117152. PR batch #1/1 (demisto#37357) Co-authored-by: root <root@1e2de18e0cc3> * update release notes --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 27, 2024
* demisto/crypto:1.0.0.117163 | 0-100 | PR batch #1/1 (demisto#37353) * Updated docker image to demisto/crypto:1.0.0.117163. PR batch #1/1 * update tags --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * update release notes * update release * update * update * update * update * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.17.5. * remove microsoft graph mail --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Nov 27, 2024
* Updated docker image to demisto/python3:3.11.10.116949. PR batch #1/5 (demisto#37402) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.116949. PR batch #2/5 (demisto#37403) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.116949. PR batch #4/5 (demisto#37405) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.116949. PR batch #5/5 (demisto#37406) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.116949. PR batch #3/5 (demisto#37404) Co-authored-by: root <root@1e2de18e0cc3> * update to 3.11.10.115186 * remove issues * utc * remove * remove * update release notes * update * Bump pack from version Okta to 3.3.8. * remove mailsendernew * remove core * update release notes * Bump pack from version Palo_Alto_Networks_Enterprise_DLP to 2.0.13. * Bump pack from version Okta to 3.3.9. * Bump pack from version AzureSentinel to 1.5.54. * Bump pack from version PaloAltoNetworks_Threat_Vault to 2.0.15. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 3, 2024
* Updated docker image to demisto/py42:1.0.0.117258. PR batch #1/1 (demisto#37421) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/teams:1.0.0.116912. PR batch #1/1 (demisto#37419) Co-authored-by: root <root@1e2de18e0cc3> * demisto/google-cloud-storage:1.0.0.117186 | 0-100 | PR batch #1/1 (demisto#37422) * Updated docker image to demisto/google-cloud-storage:1.0.0.117186. PR batch #1/1 * remove utc --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * Updated docker image to demisto/pandas:1.0.0.117209. PR batch #1/1 (demisto#37418) Co-authored-by: root <root@1e2de18e0cc3> * update release notes * remove core * demisto/sklearn:1.0.0.117326 | 0-100 | PR batch #1/1 (demisto#37420) * Updated docker image to demisto/sklearn:1.0.0.117326. PR batch #1/1 * remove email campaign --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: iapt@paloaltonetworks.com <iapt@paloaltonetworks.com> * update release notes * update * updates * Your commit message here * update release notes * update * update * Bump pack from version CommonScripts to 1.15.98. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 5, 2024
* Updated docker image to demisto/python3:3.11.10.115186. PR batch #1/4 (demisto#37524) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.115186. PR batch #2/4 (demisto#37525) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.115186. PR batch #3/4 (demisto#37526) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.115186. PR batch #4/4 (demisto#37527) Co-authored-by: root <root@1e2de18e0cc3> * remove utc files * remove utc * ipnetwork * remove unittests issues * update release notes * update release notes --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 5, 2024
* Updated docker image to demisto/parse-emails:1.0.0.117740. PR batch #1/1 (demisto#37543) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/readpdf:1.0.0.117518. PR batch #1/1 (demisto#37541) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/dxl:1.0.0.116949. PR batch #1/1 (demisto#37542) Co-authored-by: root <root@1e2de18e0cc3> * update release notes --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 10, 2024
* Updated docker image to demisto/chromium:131.0.6778.117810. PR batch #1/1 (demisto#37568) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/m2crypto:1.0.0.117200. PR batch #1/1 (demisto#37569) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/google-k8s-engine:1.0.0.117480. PR batch #1/1 (demisto#37570) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/syslog:1.0.0.117331. PR batch #1/1 (demisto#37572) Co-authored-by: root <root@1e2de18e0cc3> * Update CofenseTriagev2.yml * Update rasterize.yml * update release notes --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Dec 10, 2024
* Updated docker image to demisto/bs4-py3:1.0.0.117152. PR batch #1/1 (demisto#37619) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/bs4-tld:1.0.0.117606. PR batch #1/1 (demisto#37618) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/office-utils:2.0.0.117810. PR batch #1/1 (demisto#37617) Co-authored-by: root <root@1e2de18e0cc3> * update release notes * update --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/python3:3.11.10.115186. PR batch #1/2 (demisto#37564) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/python3:3.11.10.115186. PR batch #2/2 (demisto#37565) Co-authored-by: root <root@1e2de18e0cc3> * remove issues * remove utc * update fireeyeetp * remove elias * ipnetwork check old dockerimage * remove ipnetwork * update release notes * update core * update core release * Bump pack from version Core to 3.2.3. * Empty commit * update * fix * Bump pack from version CommunityCommonScripts to 1.3.8. * Bump pack from version Use_Case_Builder to 1.0.11. * update release notes * remove cortexcorexqlquery * Update 2_0_23.md * remove zeroFox * remove zeroFox --------- Co-authored-by: Koby Meir <kobymeir@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
demisto#37759) * Updated docker image to demisto/armorblox:1.0.0.117139. PR batch #1/1 (demisto#37729) Co-authored-by: root <root@1e2de18e0cc3> * RN --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/rubrik-polaris-sdk-py3:1.0.0.117242. PR batch #1/1 (demisto#37798) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/octoxlabs:1.0.0.1796617. PR batch #1/1 (demisto#37796) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/glpi:1.0.0.117350. PR batch #1/1 (demisto#37795) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/opnsense:1.0.0.117205. PR batch #1/1 (demisto#37794) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/gdetect:1.0.0.117177. PR batch #1/1 (demisto#37790) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/illumio:1.0.0.117187. PR batch #1/1 (demisto#37793) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> * Updated docker image to demisto/keeper-ksm:1.0.0.117307. PR batch #1/1 (demisto#37792) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> * Updated docker image to demisto/cyjax:1.0.0.117170. PR batch #1/1 (demisto#37791) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> * RN * revert * revert --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/powershell-ubuntu:7.4.6.116823. PR batch #1/1 (demisto#37773) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/pcap-http-extractor:1.0.0.117511. PR batch #1/1 (demisto#37772) Co-authored-by: root <root@1e2de18e0cc3> * demisto/google-cloud-storage:1.0.0.117186 | 0-100 | PR batch #1/1 (demisto#37774) * Updated docker image to demisto/google-cloud-storage:1.0.0.117186. PR batch #1/1 * UP017 --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: shmuel44 <skroizer@paloaltonetworks.com> * demisto/datadog-api-client:1.0.0.1832460 | 0-100 | PR batch #1/1 (demisto#37771) * Updated docker image to demisto/datadog-api-client:1.0.0.1832460. PR batch #1/1 * UP017 --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: shmuel44 <skroizer@paloaltonetworks.com> * RN * Bump pack from version Core to 3.2.15. * Bump pack from version Core to 3.2.16. * Bump pack from version CommonScripts to 1.19.2. * pylint * Bump pack from version Core to 3.2.17. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/sklearn:1.0.0.1858294. PR batch #1/1 (demisto#37961) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#37959) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/chromium:131.0.6778.117810. PR batch #1/1 (demisto#37957) Co-authored-by: root <root@1e2de18e0cc3> * Add RN * . * Bump pack from version CommonScripts to 1.19.5. * Bump pack from version Mattermost to 2.0.7. * Bump pack from version CommonScripts to 1.19.6. * Bump pack from version CommonScripts to 1.19.7. * Bump pack from version CommonScripts to 1.19.8. * Bump pack from version CommonScripts to 1.19.9. * . * . * . --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/xsoar-tools:1.0.0.1902141. PR batch #1/1 (demisto#37927) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com> * Add RN * Bump pack from version CommonScripts to 1.19.7. * Bump pack from version CommonScripts to 1.19.8. * Bump pack from version Base to 1.39.13. * Bump pack from version CommonScripts to 1.19.9. * . * . * Bump pack from version Base to 1.39.14. * Bump pack from version Base to 1.39.15. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#38166) Co-authored-by: root <root@1e2de18e0cc3> * Add RN --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#38166) Co-authored-by: root <root@1e2de18e0cc3> * Add RN * demisto/pcap-miner:1.0.0.117211 | 0-100 | PR batch #1/1 (demisto#38167) * Updated docker image to demisto/pcap-miner:1.0.0.117211. PR batch #1/1 * @aaron1535 Change the image to demisto/pcap-miner:1.0.0.2020843. * Add RN --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Aaron <4101535@gmail.com> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com> --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/graphql:1.0.0.117182. PR batch #1/1 (demisto#38235) * Updated docker image to demisto/powershell-teams:1.0.0.116826. PR batch #1/1 (demisto#38222) * Updated docker image to demisto/snowflake:1.0.0.117522. PR batch #1/1 (demisto#38223) * Updated docker image to demisto/stringsifter:3.20230711.117524. PR batch #1/1 (demisto#38224) * Updated docker image to demisto/smbprotocol:1.0.0.117523. PR batch #1/1 (demisto#38225) * Updated docker image to demisto/pwsh-exchangev3:1.0.0.116826. PR batch #1/1 (demisto#38226) * Updated docker image to demisto/pwsh-exchange:1.0.0.116826. PR batch #1/1 (demisto#38227) * Updated docker image to demisto/pwsh-exchange:1.0.0.116826. PR batch #1/1 (demisto#38228) * Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#38230) * Updated docker image to demisto/stringsifter:3.20230711.117524. PR batch #1/1 (demisto#38231) * Updated docker image to demisto/smbprotocol:1.0.0.117523. PR batch #1/1 (demisto#38232) * Updated docker image to demisto/pwsh-exchangev3:1.0.0.116826. PR batch #1/1 (demisto#38233) * Updated docker image to demisto/powershell-teams:1.0.0.116826. PR batch #1/1 (demisto#38234) * Updated docker image to demisto/snowflake:1.0.0.117522. PR batch #1/1 (demisto#38229) * Add RN --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/faker3:1.0.0.1976220. PR batch #1/1 * Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#38166) Co-authored-by: root <root@1e2de18e0cc3> * Add RN --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Aaron <4101535@gmail.com> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* changed memberof with members * release notes * Delete invalid file (demisto#38111) * Fix MISPV3 that returned indicator with DBot score unknown (demisto#38106) * commit * commit * update RN * remove all debug * Update Packs/MISP/ReleaseNotes/2_1_50.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Change all paths in Readme and Description file-part6 (demisto#38099) * fix * Fix Pylint errors in AWS (demisto#38042) * aws pylint * apimodule * aws secret manager * apimodule_test * fix unit test * pylint fix * response * update dynamo test playbook * fromversion: 5.0.0 * Fix Pylint errors in C packs (demisto#38048) * c packs pylint * fix rn * pack version * Fix Pylint errors in S part 1 packs (demisto#38082) * pylint S1 packs * rn * docker image update * Fix Pylint errors in S part 2 packs (demisto#38084) * pylint S2 packs * docker image update * AlibabaActionTrail Event Collector - Fixed a parsing error related to the First fetch time interval parameter (demisto#38074) * Fixed the first fetch param parsing error * pre-commit fixes * Ignored the specific my py error * Updated the docker image tag to the latest * Updated the RN file * XSUP 45126 Cyberark Identity Update (demisto#38071) * Updated ModelingRules ParsingRules * Updated pack_metadata * Updated README * Updated README * Updated README * Update Packs/CyberArkIdentity/README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update pack_metadata.json * Updated ReleaseNotes * Updated ReleaseNotes --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Nozomi make result per run configurble (demisto#37531) (demisto#38057) * NNPANXSOAR-6 * use record_created_at to paginate * fix tests * NNPANXSOAR-6 * use requests as http client to fix verify SSL issues * make code more stable * NNPANXSOAR-6 * updated documentation * NNPANXSOAR-6 * make linter happy * * add form Incidents per run * add logic to return every run the incidents size passed * * add form Incidents per run * add logic to return every run the incidents size passed * * add release notes * bump version * * add release notes * bump version * * update release notes * make linter happy * * make linter happy again * * make linter happy again * * use bearer token to auth every http call * add sign_in * fallback to basic auth * * fix default error response * * make app more robust * add more case * * fix proxy issue * add tests * * bumpversion * update readme * update release notes * * wip new pagination * * refactoring * make linter happy * remove dev logs * * refactoring * make linter happy * remove dev logs * * fix yml * * fix yml * * remove secrets * * remove secrets * * executed demisto-sdk split command on yml * fix linter issues * * fix release notes format * * bump docker image version Co-authored-by: Nicolò <nicolo.ereni@nozominetworks.com> * part 7 - fixing relative files (demisto#38083) * part 7 - fixing relative files * fix * Fix Pylint errors in O packs (demisto#38067) * remove o * skip CRTX-116483 * [EWS v2] Fix issue with files not opening (demisto#37963) * [EWS v2] Fix issue with files not opening * Fix in fetch_attachments_for_message * CRTX-146122-ProofPoint-Email-Security (demisto#37954) * added support for audit log type * added release notes * added release notes * added release notes * fix * fix * fix * fix * fix * added parsing * fix yml * fix notes * added tags * New Playbook - Suspicious Local Administrator Login (demisto#37933) * new playbook * added trigger and RN * c * added error to pack ignore * trigger fixed * namefix * fix * fix for the trigger * Bump pack from version CortexResponseAndRemediation to 1.0.2. * fix RN * fix * fixx * fix for disable command * Update Packs/CortexResponseAndRemediation/Playbooks/playbook-Suspicious_Local_Administrator_Login.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexResponseAndRemediation/Playbooks/playbook-Suspicious_Local_Administrator_Login.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexResponseAndRemediation/Playbooks/playbook-Suspicious_Local_Administrator_Login_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexResponseAndRemediation/ReleaseNotes/1_0_2.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexResponseAndRemediation/Playbooks/playbook-Suspicious_Local_Administrator_Login_README.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/CortexResponseAndRemediation/ReleaseNotes/1_0_2.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * fix for read me * fix * fix for command * new image * Adi's review changes * Bump pack from version CortexResponseAndRemediation to 1.0.3. * fixes * Bump pack from version CortexResponseAndRemediation to 1.0.4. * fix * last version * added description * white image of the playbook * read me fix --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * remove native (demisto#38098) * fix * fix * fix * fix * Bump pack from version ThreatIntelReports to 1.0.21. * Bump pack from version Whois to 1.5.21. * cr * cr --------- Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com> Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: Nicolò <nicolo.ereni@nozominetworks.com> Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: sdaniel6 <sdaniel@paloaltonetworks.com> Co-authored-by: Karina Fishman <147307864+karinafishman@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * fix (demisto#38104) * change all paths in readme and description - part 8 (demisto#38107) * change all paths in readme and description - part 8 * fix * Fix remote-access documentation (demisto#38081) * init * Shirley Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * a pylint (demisto#38093) * pylint n packs (demisto#38064) * [Panorama] MyPy In Docker (demisto#37932) * mypy * rn * pylint * [McAfeeNSMv2] MyPy In Docker (demisto#37995) * fix * fix * RN * E501 Line too long * autopep8 * Change all paths in Readme and Description file-part9 (demisto#38108) * fix * fix * CIAC-12287/Add-Extract-Indicators-to-Suspicious-msiexec-execution-PB (demisto#38047) * Add extract indicators for the playbook * Update release notes * Update release notes * Bump pack from version CortexResponseAndRemediation to 1.0.4. * Bump pack from version CortexResponseAndRemediation to 1.0.5. * Fix review comments --------- Co-authored-by: Content Bot <bot@demisto.com> * Add logs to xql query (demisto#38097) * add logs * add rn * fix log * [EWSO365] MyPy In Docker (demisto#37990) * fix * RN * autopep8 * add retry (demisto#38105) * add retry * RN * update RN * Aud demisto/auto update docker staging branch 89 (demisto#37977) * Updated docker image to demisto/sklearn:1.0.0.1858294. PR batch #1/1 (demisto#37961) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/netutils:1.0.0.118055. PR batch #1/1 (demisto#37959) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/chromium:131.0.6778.117810. PR batch #1/1 (demisto#37957) Co-authored-by: root <root@1e2de18e0cc3> * Add RN * . * Bump pack from version CommonScripts to 1.19.5. * Bump pack from version Mattermost to 2.0.7. * Bump pack from version CommonScripts to 1.19.6. * Bump pack from version CommonScripts to 1.19.7. * Bump pack from version CommonScripts to 1.19.8. * Bump pack from version CommonScripts to 1.19.9. * . * . * . --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com> * Enhancement for Exchange forwarding rule (demisto#38063) * new * fix * Added RN * Update Packs/CortexResponseAndRemediation/ReleaseNotes/1_0_4.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Bump pack from version CortexResponseAndRemediation to 1.0.5. * fix * Bump pack from version CortexResponseAndRemediation to 1.0.6. * Tomer's review fix * fix * skip if added * fix * RN * RN update * fixed rn * fixed rn * fixed rn --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * Change all paths in Readme and Description file-part10 (demisto#38122) * Ciac 10837/content path (demisto#37898) * InvalidMarkdownFileName - CIAC-10840 * InvalidDepthOneFolder - CIAC-10839 * InvalidIntegrationScriptFileName - CIAC-10841 * test * test * test * test * InvalidIntegrationScriptFileName - CIAC-10841 * fix paths and readme * fix paths * ignore validation * remove change * remove change added rn * added test * removed * pre-commit * pre-commit * remove rn * integration in skip * commit * XSUP-45578 (demisto#38109) * fix bug * fix pre-commit * fix pre-commit * Update Packs/CommonScripts/ReleaseNotes/1_19_9.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Bump pack from version CommonScripts to 1.19.10. --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> * A small fix in CSP, FireEye, O365 for supporting python 3.12 (demisto#38051) * make the docstring a raw str * RN * add some more fixes * rn * rn --------- Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> * Fix Pylint errors in R packs (demisto#38077) * pylint R packs * remove native from pytest-in-docker * update docker image * update test playbook Rundeck_test * update Rundeck_test to run only in xsoar saas * convert to relative - fm (demisto#38056) * convert to relative * fix * fix * Fix remote-access documentation (demisto#38081) * init * Shirley Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * a pylint (demisto#38093) * pylint n packs (demisto#38064) * [Panorama] MyPy In Docker (demisto#37932) * mypy * rn * pylint * [McAfeeNSMv2] MyPy In Docker (demisto#37995) * fix * fix * RN * E501 Line too long * autopep8 * Change all paths in Readme and Description file-part9 (demisto#38108) * fix * fix * CIAC-12287/Add-Extract-Indicators-to-Suspicious-msiexec-execution-PB (demisto#38047) * Add extract indicators for the playbook * Update release notes * Update release notes * Bump pack from version CortexResponseAndRemediation to 1.0.4. * Bump pack from version CortexResponseAndRemediation to 1.0.5. * Fix review comments --------- Co-authored-by: Content Bot <bot@demisto.com> * Add logs to xql query (demisto#38097) * add logs * add rn * fix log * revert * Bump pack from version Phishing to 3.6.31. --------- Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> Co-authored-by: Erez FelmanDar <102903097+efelmandar@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> * AUD-demisto/auto_update_docker_staging_branch_88 (demisto#38052) * Updated docker image to demisto/xsoar-tools:1.0.0.1902141. PR batch #1/1 (demisto#37927) Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com> * Add RN * Bump pack from version CommonScripts to 1.19.7. * Bump pack from version CommonScripts to 1.19.8. * Bump pack from version Base to 1.39.13. * Bump pack from version CommonScripts to 1.19.9. * . * . * Bump pack from version Base to 1.39.14. * Bump pack from version Base to 1.39.15. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com> * Update ruff version to 0.8.0 (demisto#37930) * update ruff * [tool.ruff] * [BoxV2] MyPy In Docker (demisto#38133) * fix * update docker * RN * [SymantecEmailSecurity] MyPy In Docker (demisto#38137) * fix * docker * RN * Add ErrorReasons to 'core-action-status-get' Command (demisto#37483) * add errorReasons * add error_description to HR * add outputs * add RN * add polling output * change to No Tests * change output path * UT * readme * precommit * doc review * fix build fail (demisto#38146) * fix * fix * Revert "Update ruff version to 0.8.0 (demisto#37930)" (demisto#38138) This reverts commit cb44cac. * Fix-cs-t1059-playbook (demisto#38148) * Fixed playbook conditional task for creating new incident + added additional endpoint fields to the layout * RN * Update Packs/CrowdStrikeFalcon/ReleaseNotes/2_1_6.md Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> --------- Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Create new 1Password pack for Cortex XSIAM (demisto#37730) * Fix additional ruff errors (demisto#38144) * E721 * rn * update rn * 10611 finshes part 3 1 (demisto#38150) * convert to relative * fix * fix * [MongoDBAtlasEventCollector] MyPy In Docker (demisto#38139) * fix * docker * RN * [FindEmailCampaign] MyPy In Docker (demisto#38140) * fix * RN * [Alibaba] MyPy In Docker (demisto#38136) * Alibaba * docker * RN * unfreeze autoupdate flow cyberark (demisto#38154) * unfreeze * rn * undo rn * 10611 finshes part 3_3 (demisto#38161) * 10611 finshes part 3_3 * 10611 finshes part 3_3 * Fix protectwise uploaded file README image (demisto#38157) * Fix Microsoft Defender incoming mapper / XSUP-45575 (demisto#38155) * init * rn * rn * Fix CS Falcon outgoing mapper (demisto#38087) * fix * rn * improves * Bump pack from version CrowdStrikeFalcon to 2.1.6. * works * rn * add test * add test * pre commit * Bump pack from version CrowdStrikeFalcon to 2.1.7. --------- Co-authored-by: Content Bot <bot@demisto.com> * [ASM] - UVEM-790 - RankServiceOwners Update (demisto#38091) (demisto#38164) * Update RankSO Script and Release Notes * Update alertsource to ownerrelatedfield * Refactor output logic to write_output_to_context_key function * Refactor variables and update ReadMe * add error for wrong tenant * predefined/stringify * Apply suggestions from code review * changed wording --------- Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: jwilkes <jwilkes@paloaltonetworks.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * ReversingLabs A1000 v2.4.4 (demisto#38112) (demisto#38170) * Update version to 2.4.4 * Update readme * Fix minor bugs in classification commands. * Add the contributors file * Add release notes Co-authored-by: Mislav Sever <46045160+MislavReversingLabs@users.noreply.github.com> * Fix Pylint errors in P packs (demisto#38069) * pylint p packs * docker image updates * rn * Bump pack from version ProofpointThreatResponse to 2.0.21. * Bump pack from version PrismaCloudCompute to 1.7.11. * fix error * pylint error * revert some changes * added memory_threshold to PAN-OS - Block IP - Custom Block Rule Test * added memory_threshold to PAN-OS - Block IP - Static Address Group Test * added memory_threshold PAN-OS - Block URL - Custom URL Category Test * added memroty_treshold to all panorama test playbooks --------- Co-authored-by: Content Bot <bot@demisto.com> * 10611 finshes part 3_4 (demisto#38162) * 10611 finshes part 3_4 * 10611 finshes part 3_4 * 10611 finshes part 3_4 * reverrt change * 10611 finshes part 3_2 (demisto#38160) * 10611 finshes part 3_2 * wop * poetry files (demisto#38171) Co-authored-by: Content Bot <bot@demisto.com> * fix ruff warnings (demisto#38143) * Update content before upgrading pylint (demisto#37732) * pylint errors * more pylint and rn * Bump pack from version EmailCommunication to 2.0.37. * more pylint and rn * pylint errors and rn * Bump pack from version Base to 1.39.3. * pylint errors and rn * pylint errors and rn * Bump pack from version Zoom to 1.6.20. * Bump pack from version CommonScripts to 1.18.4. * pylint errors and rn * pylint errors and rn * pylint errors and rn * run on the my sdk branch * remove changes from autofocus * ruff pre-commit fixes * delete some changes * Bump pack from version Base to 1.39.4. * fix validations * pylint and mypy errors * Bump pack from version CheckpointFirewall to 2.3.25. * fixes * pycln updates * rn and updates * autopop8 and fixes * Bump pack from version cisco-ise to 1.0.24. * Bump pack from version Netskope to 4.0.4. * Bump pack from version Base to 1.39.5. * fixes * Bump pack from version SuspiciousDomainHunting to 1.0.10. * Bump pack from version PrismaCloudCompute to 1.7.10. * Bump pack from version PAN-OS to 2.3.2. * Bump pack from version Palo_Alto_Networks_Enterprise_DLP to 2.0.15. * fixed missing pylint and errors * fixes * validations * autopop8 reco and poly * fix * docker image PolySwarm * fix line too long * pre-commit updates * Bump pack from version PaloAltoNetworks_SecurityAdvisories to 1.0.9. * use INFRA_BRANCH * docker images * fixed rn * Bump pack from version Base to 1.39.6. * base version update * docker images * Bump pack from version CommunityCommonScripts to 1.3.10. * Bump pack from version ctf01 to 1.0.36. * Bump pack from version ApiModules to 2.2.36. * Bump pack from version CrowdStrikeFalcon to 2.1.2. * updating version and release notes for apimodules * Bump pack from version TrendMicroVisionOne to 4.2.1. * updated the version of base * updated the docker image to 3.11 * pre-commit updates * removed code duplications * remove no longer needed pylint fix * remove duplications * fix rn * fix uptycs * pack version * Bump pack from version CrowdStrikeFalcon to 2.1.3. * Bump pack from version AWS-SecurityHub to 1.3.41. * remove aws * awsapimodule+secret manager * remove base * remove commonscripts + common community scripts + cs falcon * remove mattermost * pre-commit updates * remove c packs * remove e packs * remove f * remove * remove i + j * remove m * remove n * remove o * remove p * remove r * remove s1 * remove s2 * remove vmware * remove t * remove a * remove native from pylint-in-docker * Bump pack from version Whois to 1.5.21. * Bump pack from version Whois to 1.5.22. * update the test playbook Whois A new layout implemented with python-whois service * add Whois A new layout implemented with python-whois service to the tests of the integration * Bump pack from version ctf01 to 1.0.37. --------- Co-authored-by: Content Bot <bot@demisto.com> * revert docker (demisto#38169) * revert docker * revert docker * Update Packs/RTIR/ReleaseNotes/1_0_22.md Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com> * empty * empty * added section to the .yml * removed unrelated changes * update the docker image --------- Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com> Co-authored-by: israelpoli <72099621+israelpoli@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com> Co-authored-by: RotemAmit <ramit@paloaltonetworks.com> Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com> Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com> Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: Nicolò <nicolo.ereni@nozominetworks.com> Co-authored-by: sdaniel6 <sdaniel@paloaltonetworks.com> Co-authored-by: Karina Fishman <147307864+karinafishman@users.noreply.github.com> Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com> Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com> Co-authored-by: Erez FelmanDar <102903097+efelmandar@users.noreply.github.com> Co-authored-by: Tal Carmeli <158452762+tcarmeli1@users.noreply.github.com> Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com> Co-authored-by: azonenfeld <117573492+aaron1535@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> Co-authored-by: rshunim <102469772+rshunim@users.noreply.github.com> Co-authored-by: Adi Bamberger Edri <72088126+BEAdi@users.noreply.github.com> Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com> Co-authored-by: Kamal Qarain <45042524+kamalq97@users.noreply.github.com> Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com> Co-authored-by: Moshe Eichler <78307768+MosheEichler@users.noreply.github.com> Co-authored-by: John <40349459+BigEasyJ@users.noreply.github.com> Co-authored-by: johnnywilkes <32227961+johnnywilkes@users.noreply.github.com> Co-authored-by: jwilkes <jwilkes@paloaltonetworks.com> Co-authored-by: Mislav Sever <46045160+MislavReversingLabs@users.noreply.github.com> Co-authored-by: Sapir Shuker <49246861+sapirshuker@users.noreply.github.com> Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/exodusintelligence:1.0.0.2027898. PR batch #1/1 (demisto#38283) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/google-vision-api:1.0.0.2032298. PR batch #1/1 (demisto#38281) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/lacework:1.0.0.117192. PR batch #1/1 (demisto#38280) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/greynoise:1.0.0.117184. PR batch #1/1 (demisto#38279) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/pcap-http-extractor:1.0.0.2034848. PR batch #1/1 (demisto#38278) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/accessdata:1.1.0.2005648. PR batch #1/1 (demisto#38276) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/bottle:1.0.0.2057122. PR batch #1/1 (demisto#38275) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/sane-doc-reports:1.0.0.2023828. PR batch #1/1 (demisto#38274) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/ntlm:1.0.0.2034747. PR batch #1/1 (demisto#38272) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/feed-performance-test:1.0.117321. PR batch #1/1 (demisto#38271) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/tidy:1.0.0.2020237. PR batch #1/1 (demisto#38273) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/tesseract:1.0.0.2038079. PR batch #1/1 (demisto#38277) Co-authored-by: root <root@1e2de18e0cc3> * Add RN * change UTC time zone (Ruff issue) * . * . * . * . * demisto/yarapy:1.0.0.1941591 | 0-100 | PR batch #1/1 (demisto#38282) * Updated docker image to demisto/yarapy:1.0.0.1941591. PR batch #1/1 * . --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Aaron <4101535@gmail.com> * Add Yara RN * . --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* Updated docker image to demisto/argus-toolbelt:3.0.0.2055215. PR batch #1/1 (demisto#38323) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/office-utils:2.0.0.2020302. PR batch #1/1 (demisto#38322) Co-authored-by: root <root@1e2de18e0cc3> * Add RN --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
DNRRomero
pushed a commit
that referenced
this pull request
Jan 28, 2025
* demisto/readpdf:1.0.0.2034953 | 0-100 | PR batch #1/1 (demisto#38316) * Updated docker image to demisto/readpdf:1.0.0.2034953. PR batch #1/1 * add RN --------- Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Aaron <4101535@gmail.com> * Bump pack from version CommonScripts to 1.19.14. --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3> Co-authored-by: Content Bot <bot@demisto.com>
DNRRomero
pushed a commit
that referenced
this pull request
Feb 10, 2025
* Updated docker image to demisto/pwsh-infocyte:1.1.0.117365. PR batch #1/1 (demisto#38543) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/aquatone:2.0.0.2017685. PR batch #1/1 (demisto#38544) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/snowflake:1.0.0.2108833. PR batch #1/1 (demisto#38546) Co-authored-by: root <root@1e2de18e0cc3> * Updated docker image to demisto/powershell:7.4.6.117357. PR batch #1/1 (demisto#38547) Co-authored-by: root <root@1e2de18e0cc3> * add RN --------- Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com> Co-authored-by: root <root@1e2de18e0cc3>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Sort imports to avoid the use of wildcard imports, and include submit_threat command
following integration requirements in
ZFE-70221
Contributing to Cortex XSOAR Content
Make sure to register your contribution by filling the contribution registration form
The Pull Request will be reviewed only after the contribution registration form is filled.
Status
Related Issues
fixes: link to the issue
Description
A few sentences describing the overall goals of the pull request's commits.
Screenshots
Paste here any images that will help the reviewer
Minimum version of Cortex XSOAR
Does it break backward compatibility?
Must have