From 9ba2005ba71e5087874bf629c680d3df6a2409f7 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 00:44:16 +0300 Subject: [PATCH 01/55] Add Parameters file --- FireEye-HX-Workflow-Parameter-Value.xml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 FireEye-HX-Workflow-Parameter-Value.xml diff --git a/FireEye-HX-Workflow-Parameter-Value.xml b/FireEye-HX-Workflow-Parameter-Value.xml new file mode 100644 index 00000000..b04e2a39 --- /dev/null +++ b/FireEye-HX-Workflow-Parameter-Value.xml @@ -0,0 +1,9 @@ + + + + + + + + + \ No newline at end of file From 3f09db3ab5ce1a27f15c2d66d6eb279f3b7f1e9a Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 00:45:06 +0300 Subject: [PATCH 02/55] Move into "FireEye HX" folder --- .../FireEye-HX-Workflow-Parameter-Value.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename FireEye-HX-Workflow-Parameter-Value.xml => FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml (94%) diff --git a/FireEye-HX-Workflow-Parameter-Value.xml b/FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml similarity index 94% rename from FireEye-HX-Workflow-Parameter-Value.xml rename to FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml index b04e2a39..ba7a2578 100644 --- a/FireEye-HX-Workflow-Parameter-Value.xml +++ b/FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml @@ -6,4 +6,4 @@ - \ No newline at end of file + From 9e5415345cc633f1dc880fd3447f4ccdc24080d4 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 00:46:44 +0300 Subject: [PATCH 03/55] Files uploaded --- .../FireEye-HX-Alert_Groups-Workflow copy.xml | 82 +++++++++++++ FireEye HX/FireEye-HX-Alerts-Workflow.xml | 112 ++++++++++++++++++ FireEye HX/LICENSE | 21 ++++ FireEye HX/README.md | 2 + 4 files changed, 217 insertions(+) create mode 100644 FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml create mode 100644 FireEye HX/FireEye-HX-Alerts-Workflow.xml create mode 100644 FireEye HX/LICENSE create mode 100644 FireEye HX/README.md diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml b/FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml new file mode 100644 index 00000000..cf4fb4ee --- /dev/null +++ b/FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml @@ -0,0 +1,82 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml new file mode 100644 index 00000000..866906ee --- /dev/null +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -0,0 +1,112 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/FireEye HX/LICENSE b/FireEye HX/LICENSE new file mode 100644 index 00000000..35589ce6 --- /dev/null +++ b/FireEye HX/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2022 Mohamed Al-Shabrawy + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/FireEye HX/README.md b/FireEye HX/README.md new file mode 100644 index 00000000..3eb243c7 --- /dev/null +++ b/FireEye HX/README.md @@ -0,0 +1,2 @@ +# FireEye-HX-QRadar-Workflow +IBM QRadar Universal Cloud Connector Workflow for FireEye HX From 5f27e672245135caedc0bff368630fa511ecdf14 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 00:47:07 +0300 Subject: [PATCH 04/55] Rename FireEye-HX-Alert_Groups-Workflow copy.xml to FireEye-HX-Alert_Groups-Workflow.xml --- ...s-Workflow copy.xml => FireEye-HX-Alert_Groups-Workflow.xml} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename FireEye HX/{FireEye-HX-Alert_Groups-Workflow copy.xml => FireEye-HX-Alert_Groups-Workflow.xml} (99%) diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml b/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml similarity index 99% rename from FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml rename to FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml index cf4fb4ee..2955827a 100644 --- a/FireEye HX/FireEye-HX-Alert_Groups-Workflow copy.xml +++ b/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml @@ -79,4 +79,4 @@ - \ No newline at end of file + From f4cfdaa6a71d24e7c367958873ac48de010cd508 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 00:48:37 +0300 Subject: [PATCH 05/55] Update README.md --- FireEye HX/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/FireEye HX/README.md b/FireEye HX/README.md index 3eb243c7..5559fd18 100644 --- a/FireEye HX/README.md +++ b/FireEye HX/README.md @@ -1,2 +1,2 @@ -# FireEye-HX-QRadar-Workflow -IBM QRadar Universal Cloud Connector Workflow for FireEye HX +# QRadar Workflow for FireEye HX +IBM QRadar Universal Cloud Connector Workflow for reading FireEye HX alerts through REST API From 7df22e82ca1e1a0e182b307acef94abf6f26f902 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 01:01:47 +0300 Subject: [PATCH 06/55] Update README.md --- FireEye HX/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/FireEye HX/README.md b/FireEye HX/README.md index 5559fd18..ef14275e 100644 --- a/FireEye HX/README.md +++ b/FireEye HX/README.md @@ -1,2 +1,13 @@ # QRadar Workflow for FireEye HX IBM QRadar Universal Cloud Connector Workflow for reading FireEye HX alerts through REST API + +- Author Name: Mohamed Al-Shabrawy +- Maintainer Name: @M-Shabrawy +- Version: 1.0.2 +- Endpoint Documentation: + - - https://fireeye.dev/ + - - https://fireeye.dev/apis/lighthouse/ + +- Event Types Currently Supported by the workflow: +- - Alerts: Gets a list of non-suppressed alerts known to the system +- - Alert Groups: Lists all alert_groups From fa6eb99a18731789623aab3f1f3c85cc60081779 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 07:37:19 +0300 Subject: [PATCH 07/55] Rename FireEye-HX-Workflow-Parameter-Value.xml to FireEye-HX-Alerts-Workflow-Parameter-Value.xml --- ...r-Value.xml => FireEye-HX-Alerts-Workflow-Parameter-Value.xml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename FireEye HX/{FireEye-HX-Workflow-Parameter-Value.xml => FireEye-HX-Alerts-Workflow-Parameter-Value.xml} (100%) diff --git a/FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml b/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml similarity index 100% rename from FireEye HX/FireEye-HX-Workflow-Parameter-Value.xml rename to FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml From e219484bb9de23e354f0cf792f217da77a844bf9 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 07:37:53 +0300 Subject: [PATCH 08/55] Add files via upload --- .../FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml b/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml new file mode 100644 index 00000000..b04e2a39 --- /dev/null +++ b/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml @@ -0,0 +1,9 @@ + + + + + + + + + \ No newline at end of file From 5a42d88d2d96217d3adaa03f493327bc47e4dfdd Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 18:38:58 +0300 Subject: [PATCH 09/55] Increase intial pull to 30 day and replace Merge with Set --- FireEye HX/FireEye-HX-Alerts-Workflow.xml | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml index 866906ee..ee3d6c6a 100644 --- a/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -9,7 +9,7 @@ - + @@ -58,17 +58,16 @@ - + - - - - - + + + + @@ -109,4 +108,4 @@ - \ No newline at end of file + From a2ea0ff206e35049de4eba869a784bbf4a73831a Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 10 Feb 2022 23:20:03 +0300 Subject: [PATCH 10/55] Update FireEye-HX-Alerts-Workflow.xml --- FireEye HX/FireEye-HX-Alerts-Workflow.xml | 45 +++++++++++++---------- 1 file changed, 25 insertions(+), 20 deletions(-) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml index ee3d6c6a..907271b1 100644 --- a/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -7,6 +7,7 @@ + @@ -14,24 +15,23 @@ - - - - - - + + + + + + - - - - - + + + + + - @@ -39,30 +39,33 @@ - - + - - + - + + + + + + @@ -83,18 +86,19 @@ - + + + + - - @@ -102,6 +106,7 @@ + From 22b0b924bf76c05c8a1f7561a08e6d0a8a6a1e49 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 13 Feb 2022 11:54:18 +0200 Subject: [PATCH 11/55] Update FireEye-HX-Alerts-Workflow.xml --- FireEye HX/FireEye-HX-Alerts-Workflow.xml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml index 907271b1..5578eb79 100644 --- a/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -61,9 +61,9 @@ - - - + + + From 9303cd7a0c055d67e000d7d09f96fa1c5f15a818 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 13 Feb 2022 12:05:13 +0200 Subject: [PATCH 12/55] change variable naming style --- FireEye HX/FireEye-HX-Alerts-Workflow.xml | 31 +++++++++++++---------- 1 file changed, 17 insertions(+), 14 deletions(-) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml index 5578eb79..dae9213c 100644 --- a/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -13,7 +13,7 @@ - + @@ -31,11 +31,11 @@ - + - + @@ -46,15 +46,15 @@ - + - + - - - + + + @@ -78,7 +78,7 @@ - + @@ -86,7 +86,10 @@ - + + + + @@ -94,15 +97,15 @@ - + - - - + + + From a4a65d55ba6657e602be20e5219864f03a6ef414 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 24 Feb 2022 10:36:44 +0300 Subject: [PATCH 13/55] Update FireEye-HX-Alerts-Workflow.xml correcting Offset to offset (caused infinite loop) --- FireEye HX/FireEye-HX-Alerts-Workflow.xml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/FireEye HX/FireEye-HX-Alerts-Workflow.xml index dae9213c..d775f756 100644 --- a/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -74,9 +74,11 @@ - + + + - + @@ -104,8 +106,8 @@ - - + + From cbbd6f17fb8a197fac173eec863e65f2762630bb Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 24 Feb 2022 13:02:57 +0300 Subject: [PATCH 14/55] Update README.md --- FireEye HX/README.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/FireEye HX/README.md b/FireEye HX/README.md index ef14275e..36c0aab1 100644 --- a/FireEye HX/README.md +++ b/FireEye HX/README.md @@ -1,6 +1,10 @@ # QRadar Workflow for FireEye HX IBM QRadar Universal Cloud Connector Workflow for reading FireEye HX alerts through REST API +## Requirements: +User account to access FireEye HX Controller with api_analyst role + +## Workflow information - Author Name: Mohamed Al-Shabrawy - Maintainer Name: @M-Shabrawy - Version: 1.0.2 @@ -8,6 +12,6 @@ IBM QRadar Universal Cloud Connector Workflow for reading FireEye HX alerts thro - - https://fireeye.dev/ - - https://fireeye.dev/apis/lighthouse/ -- Event Types Currently Supported by the workflow: +## Event Types Currently Supported by the workflow: - - Alerts: Gets a list of non-suppressed alerts known to the system -- - Alert Groups: Lists all alert_groups +- - Alert Groups: Lists all alert_groups From 9ab5e4729c61fad4ad0e4fda0b32eef5caf09953 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:29:22 +0300 Subject: [PATCH 15/55] Update FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml Co-authored-by: Chris Collins --- FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml b/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml index 2955827a..d864cc08 100644 --- a/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml +++ b/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml @@ -68,7 +68,7 @@ - + From 0b63501996a9d332bb6e849cbf72518826268018 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:34:36 +0300 Subject: [PATCH 16/55] Rename FireEye HX/README.md to Community Developed/FireEye HX/README.md Moving to new folder structure --- {FireEye HX => Community Developed/FireEye HX}/README.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {FireEye HX => Community Developed/FireEye HX}/README.md (100%) diff --git a/FireEye HX/README.md b/Community Developed/FireEye HX/README.md similarity index 100% rename from FireEye HX/README.md rename to Community Developed/FireEye HX/README.md From 55bce66350ee1bb18ceb742205d5c2f63f4d94a6 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:35:40 +0300 Subject: [PATCH 17/55] Rename FireEye HX/LICENSE to Community Developed/FireEye HX/LICENSE Move to new folder structure --- {FireEye HX => Community Developed/FireEye HX}/LICENSE | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {FireEye HX => Community Developed/FireEye HX}/LICENSE (100%) diff --git a/FireEye HX/LICENSE b/Community Developed/FireEye HX/LICENSE similarity index 100% rename from FireEye HX/LICENSE rename to Community Developed/FireEye HX/LICENSE From 1ea7d008a0bb61fbcba1b8722f6269a04e7aeaa1 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:36:19 +0300 Subject: [PATCH 18/55] Rename FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml to Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml Move to new folder structure --- .../FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename {FireEye HX => Community Developed/FireEye HX}/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml (94%) diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml similarity index 94% rename from FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml rename to Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml index b04e2a39..ba7a2578 100644 --- a/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml @@ -6,4 +6,4 @@ - \ No newline at end of file + From 61fb663ed5ba727a51316b1ee48f872ec90c42ef Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:36:53 +0300 Subject: [PATCH 19/55] Rename FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml to Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml Move to new folder structure --- .../FireEye HX}/FireEye-HX-Alert_Groups-Workflow.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {FireEye HX => Community Developed/FireEye HX}/FireEye-HX-Alert_Groups-Workflow.xml (100%) diff --git a/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml similarity index 100% rename from FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml rename to Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml From 8213986390aba2e22b2ccc494ada0073d4fe0853 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:37:38 +0300 Subject: [PATCH 20/55] Rename FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml to Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml Move to new folder structure --- .../FireEye HX}/FireEye-HX-Alerts-Workflow-Parameter-Value.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {FireEye HX => Community Developed/FireEye HX}/FireEye-HX-Alerts-Workflow-Parameter-Value.xml (100%) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml similarity index 100% rename from FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml rename to Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml From d26059b17b9cb5d6d3659956843fa8ab1827f1ba Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:38:02 +0300 Subject: [PATCH 21/55] Rename FireEye HX/FireEye-HX-Alerts-Workflow.xml to Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml Move to new folder structure --- .../FireEye HX}/FireEye-HX-Alerts-Workflow.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {FireEye HX => Community Developed/FireEye HX}/FireEye-HX-Alerts-Workflow.xml (100%) diff --git a/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml similarity index 100% rename from FireEye HX/FireEye-HX-Alerts-Workflow.xml rename to Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml From 5254d5613ceb2ca634c623247529954e6b0350b5 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:44:15 +0300 Subject: [PATCH 22/55] Update FireEye-HX-Alerts-Workflow.xml Adding Insecure parameter to all Endpoint calls to control allowUntrustedServerCertificate --- .../FireEye HX/FireEye-HX-Alerts-Workflow.xml | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml index d775f756..3cb8a662 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -6,6 +6,7 @@ + @@ -17,7 +18,9 @@ - + + + @@ -36,6 +39,9 @@ + + + @@ -58,6 +64,9 @@ + + + @@ -81,6 +90,9 @@ + + + @@ -100,7 +112,9 @@ - + + + From 05c7f226c8b6184032b6d3a560385063eb92bb03 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:46:02 +0300 Subject: [PATCH 23/55] Update FireEye-HX-Alerts-Workflow-Parameter-Value.xml Added ignore_selfsigned_certificate parameter --- .../FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml index ba7a2578..3c519f5a 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml @@ -6,4 +6,5 @@ + From fcf186083a4ac8bb2cd2c43d86f13402828bbb30 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:46:29 +0300 Subject: [PATCH 24/55] Update README.md --- Community Developed/FireEye HX/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Community Developed/FireEye HX/README.md b/Community Developed/FireEye HX/README.md index 36c0aab1..55347f9a 100644 --- a/Community Developed/FireEye HX/README.md +++ b/Community Developed/FireEye HX/README.md @@ -7,7 +7,7 @@ User account to access FireEye HX Controller with api_analyst role ## Workflow information - Author Name: Mohamed Al-Shabrawy - Maintainer Name: @M-Shabrawy -- Version: 1.0.2 +- Version: 1.0.3 - Endpoint Documentation: - - https://fireeye.dev/ - - https://fireeye.dev/apis/lighthouse/ From 39cee4dea540ca3713d1fbbf47955b9c021ec431 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:48:48 +0300 Subject: [PATCH 25/55] Update README.md Update version --- Community Developed/FireEye HX/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Community Developed/FireEye HX/README.md b/Community Developed/FireEye HX/README.md index 55347f9a..cddbf7c4 100644 --- a/Community Developed/FireEye HX/README.md +++ b/Community Developed/FireEye HX/README.md @@ -1,5 +1,5 @@ # QRadar Workflow for FireEye HX -IBM QRadar Universal Cloud Connector Workflow for reading FireEye HX alerts through REST API +IBM QRadar Universal Cloud Connector Workflow for reading Trellix/FireEye HX alerts through REST API ## Requirements: User account to access FireEye HX Controller with api_analyst role From d57c70b3f5ef78ae769230d6a18271c383f338db Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:49:25 +0300 Subject: [PATCH 26/55] Update FireEye-HX-Alerts-Workflow.xml Update version information --- Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml index 3cb8a662..11109345 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml @@ -1,5 +1,5 @@ - + From b294e3d73042bd66c03c9fbc168615c8587e0797 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:58:10 +0300 Subject: [PATCH 27/55] Update FireEye-HX-Alert_Groups-Workflow.xml Indentation and adding allowUntrustedServerCertificate control --- .../FireEye-HX-Alert_Groups-Workflow.xml | 100 ++++++++++-------- 1 file changed, 54 insertions(+), 46 deletions(-) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml index d864cc08..69d3f5ed 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml @@ -5,6 +5,7 @@ + @@ -15,62 +16,69 @@ - - - + + + + + - - - + + + - - - - - + + + + + - - - - - - - - - - - - - - + + + + - - + + + + + + + + + + + + + + + - - - - - - - - - + + + + + + + + + - - + + + - - - - - - - - + + + + + + + + + From 27f067e9089c69bbaaf1448f9f739e94ad0d981e Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Tue, 23 Aug 2022 08:59:06 +0300 Subject: [PATCH 28/55] Update FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml Added ignore_selfsigned_certificate parameter --- .../FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml index ba7a2578..3c519f5a 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml +++ b/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml @@ -6,4 +6,5 @@ + From 49ad1b4b9d6751ac756aa9754e4030f41620746b Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 19 Dec 2024 13:10:19 +0200 Subject: [PATCH 29/55] Update README.md Update brand name to Trellix --- Community Developed/FireEye HX/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Community Developed/FireEye HX/README.md b/Community Developed/FireEye HX/README.md index cddbf7c4..99b605b2 100644 --- a/Community Developed/FireEye HX/README.md +++ b/Community Developed/FireEye HX/README.md @@ -1,4 +1,4 @@ -# QRadar Workflow for FireEye HX +# QRadar Workflow for Trellix HX Alerts IBM QRadar Universal Cloud Connector Workflow for reading Trellix/FireEye HX alerts through REST API ## Requirements: @@ -7,7 +7,7 @@ User account to access FireEye HX Controller with api_analyst role ## Workflow information - Author Name: Mohamed Al-Shabrawy - Maintainer Name: @M-Shabrawy -- Version: 1.0.3 +- Version: 1.0.4 - Endpoint Documentation: - - https://fireeye.dev/ - - https://fireeye.dev/apis/lighthouse/ From c52b7091022660442b61b2c8b854bf1d50de349c Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 19 Dec 2024 13:22:34 +0200 Subject: [PATCH 30/55] Update and rename FireEye-HX-Alerts-Workflow.xml to Trellix-HX-Alerts-Workflow.xml - Updated file name to reflect brand name change. - Remove the use of Bypass SSL, as it's now part of DSM configuration. - Update variable names --- .../Trellix-HX-Alerts-Workflow.xml} | 35 ++++++------------- 1 file changed, 11 insertions(+), 24 deletions(-) rename Community Developed/{FireEye HX/FireEye-HX-Alerts-Workflow.xml => Trellix HX/Trellix-HX-Alerts-Workflow.xml} (78%) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml similarity index 78% rename from Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml rename to Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml index 11109345..5a6526cb 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml @@ -1,12 +1,11 @@ - + - @@ -18,30 +17,24 @@ - - - - + - + - + - - - @@ -51,7 +44,7 @@ - + @@ -64,9 +57,6 @@ - - - @@ -76,23 +66,20 @@ - - - - + + + + - - + + - - - From 4109bf4afc431104e11d8829d4ec17b1f8a19416 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 19 Dec 2024 13:23:31 +0200 Subject: [PATCH 31/55] Rename README.md to README.md --- Community Developed/{FireEye HX => Trellix HX}/README.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/{FireEye HX => Trellix HX}/README.md (100%) diff --git a/Community Developed/FireEye HX/README.md b/Community Developed/Trellix HX/README.md similarity index 100% rename from Community Developed/FireEye HX/README.md rename to Community Developed/Trellix HX/README.md From a4091a03174a26d08edde75d32abe88c6fbef296 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 19 Dec 2024 13:24:22 +0200 Subject: [PATCH 32/55] Rename FireEye-HX-Alerts-Workflow-Parameter-Value.xml to Trellix-HX-Alerts-Workflow-Parameter-Value.xml --- .../Trellix-HX-Alerts-Workflow-Parameter-Value.xml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/{FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml => Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml} (100%) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml similarity index 100% rename from Community Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml rename to Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml From 2318b8709445abe63ca192e3670c0eeec7578008 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Thu, 19 Dec 2024 13:26:37 +0200 Subject: [PATCH 33/55] Update Trellix-HX-Alerts-Workflow-Parameter-Value.xml Removed Ignore Self-Signed Certificate parameter --- .../Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml index 3c519f5a..f3a8c00c 100644 --- a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml @@ -1,10 +1,9 @@ - + - From 100f3353fc3155201f6452db91e07e0f0908fae8 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 10:59:49 +0200 Subject: [PATCH 34/55] Update and rename FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml to FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml Updated to use the new brand name and removed ignore self-signed certificate --- ...reEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml} | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) rename Community Developed/{FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml => Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml} (81%) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml similarity index 81% rename from Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml rename to Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml index 3c519f5a..f3a8c00c 100644 --- a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml +++ b/Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml @@ -1,10 +1,9 @@ - + - From 6471a0fda7ddd1076164e75683ba765754e31c83 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:01:00 +0200 Subject: [PATCH 35/55] Rename FireEye-HX-Alert_Groups-Workflow.xml to Trellix-HX-Alert_Groups-Workflow.xml Updated to reflect new brand name --- .../Trellix-HX-Alert_Groups-Workflow.xml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/{FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml => Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml} (100%) diff --git a/Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml similarity index 100% rename from Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml rename to Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml From 672717293d7e07eb2f3f533fb08acc4c8c711fc7 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:05:49 +0200 Subject: [PATCH 36/55] Update Trellix-HX-Alert_Groups-Workflow.xml Removed ignore self-signed certificate, and update variable naming style --- .../Trellix-HX-Alert_Groups-Workflow.xml | 36 +++++++------------ 1 file changed, 13 insertions(+), 23 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml index 69d3f5ed..81e7b6f8 100644 --- a/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml @@ -5,40 +5,33 @@ - - + - - - - + - - - + + + - + - + - - - - + @@ -49,15 +42,15 @@ - - + + - + - + @@ -66,10 +59,7 @@ - - - - + From 557bc6b5ec26ebb40058c390167e4e538ee51c20 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:06:37 +0200 Subject: [PATCH 37/55] Update and rename LICENSE to LICENSE --- Community Developed/{FireEye HX => Trellix HX}/LICENSE | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename Community Developed/{FireEye HX => Trellix HX}/LICENSE (96%) diff --git a/Community Developed/FireEye HX/LICENSE b/Community Developed/Trellix HX/LICENSE similarity index 96% rename from Community Developed/FireEye HX/LICENSE rename to Community Developed/Trellix HX/LICENSE index 35589ce6..15286d7a 100644 --- a/Community Developed/FireEye HX/LICENSE +++ b/Community Developed/Trellix HX/LICENSE @@ -1,6 +1,6 @@ MIT License -Copyright (c) 2022 Mohamed Al-Shabrawy +Copyright (c) 2024 Mohamed Al-Shabrawy Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal From f4eba812293bfa4f92150d5396b58319b115c3a6 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:15:01 +0200 Subject: [PATCH 38/55] Update Trellix-HX-Alerts-Workflow.xml Updated bookmark update section --- Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml index 5a6526cb..26573a02 100644 --- a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml @@ -73,8 +73,7 @@ - - + From db82bf2099c2e23fae302de0b12b862856d4314e Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:18:09 +0200 Subject: [PATCH 39/55] Update Trellix-HX-Alerts-Workflow.xml Changing FE to Trellix and added logging --- .../Trellix HX/Trellix-HX-Alerts-Workflow.xml | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml index 26573a02..9da4efcf 100644 --- a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml @@ -23,7 +23,7 @@ - + @@ -45,10 +45,10 @@ - + - + @@ -61,10 +61,10 @@ - + - + @@ -74,6 +74,7 @@ + @@ -87,13 +88,13 @@ - + - + @@ -106,7 +107,7 @@ - + From 8a48d19b605a6792c0071b785a6310a037f5514a Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 11:21:36 +0200 Subject: [PATCH 40/55] Create Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml --- ...rellix-HX-ProcessTracker-Workflow-Parameter-Value.xml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml new file mode 100644 index 00000000..f3a8c00c --- /dev/null +++ b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml @@ -0,0 +1,9 @@ + + + + + + + + + From b426fa3984983f849125b49b6132bfe7c298e17b Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Sun, 22 Dec 2024 12:13:23 +0200 Subject: [PATCH 41/55] Create Trellix-HX-ProcessTracker-Workflow.xml Initial version --- .../Trellix-HX-ProcessTracker-Workflow.xml | 103 ++++++++++++++++++ 1 file changed, 103 insertions(+) create mode 100644 Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml new file mode 100644 index 00000000..470173cd --- /dev/null +++ b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + From 8f66a7871f82b6cf52cb5201f2fd022ab643343e Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Mon, 23 Dec 2024 16:15:06 +0200 Subject: [PATCH 42/55] Update Trellix-HX-Alerts-Workflow.xml --- .../Trellix HX/Trellix-HX-Alerts-Workflow.xml | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml index 9da4efcf..59ca5f9e 100644 --- a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml @@ -10,12 +10,9 @@ - + - - - - + @@ -29,16 +26,14 @@ - - + - @@ -48,14 +43,16 @@ - + - + + + From d8d1900d69635e2e1ea57bdc9a292d27114c0369 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Mon, 23 Dec 2024 21:32:18 +0200 Subject: [PATCH 43/55] Update Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml Removed Limit parameter --- .../Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml | 2 -- 1 file changed, 2 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml index f3a8c00c..ac21019f 100644 --- a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml +++ b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml @@ -4,6 +4,4 @@ - - From 547b8737886b18258f30152b5c8bff43b819c8f6 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Mon, 23 Dec 2024 21:34:23 +0200 Subject: [PATCH 44/55] Update Trellix-HX-ProcessTracker-Workflow.xml First working version --- .../Trellix-HX-ProcessTracker-Workflow.xml | 76 ++++++++++--------- 1 file changed, 41 insertions(+), 35 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml index 470173cd..47e81d69 100644 --- a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml @@ -5,7 +5,6 @@ - @@ -21,68 +20,75 @@ - + - - - - + + + + + - + - + - + + + + + + - + - - - - - - - - - - - - - + + + + - - - + + + - - - + + + + + + + + + + + + + + + + + - + - - - @@ -97,7 +103,7 @@ - + From f3e23bb741654bd97429c125b25e337d38b4b40c Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Mon, 23 Dec 2024 21:37:09 +0200 Subject: [PATCH 45/55] Update README.md Added Process Tracker workflow information --- Community Developed/Trellix HX/README.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/Community Developed/Trellix HX/README.md b/Community Developed/Trellix HX/README.md index 99b605b2..d844f0a0 100644 --- a/Community Developed/Trellix HX/README.md +++ b/Community Developed/Trellix HX/README.md @@ -1,5 +1,5 @@ # QRadar Workflow for Trellix HX Alerts -IBM QRadar Universal Cloud Connector Workflow for reading Trellix/FireEye HX alerts through REST API +IBM QRadar Universal Cloud Connector Workflows for reading Trellix/FireEye HX Alerts and Events through REST API ## Requirements: User account to access FireEye HX Controller with api_analyst role @@ -7,7 +7,7 @@ User account to access FireEye HX Controller with api_analyst role ## Workflow information - Author Name: Mohamed Al-Shabrawy - Maintainer Name: @M-Shabrawy -- Version: 1.0.4 +- Version: 1.0.5 - Endpoint Documentation: - - https://fireeye.dev/ - - https://fireeye.dev/apis/lighthouse/ @@ -15,3 +15,4 @@ User account to access FireEye HX Controller with api_analyst role ## Event Types Currently Supported by the workflow: - - Alerts: Gets a list of non-suppressed alerts known to the system - - Alert Groups: Lists all alert_groups +- - Process Tracker Module events From 5b71d649a65d71ebed1aecf07662552660934d58 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Mon, 23 Dec 2024 21:37:36 +0200 Subject: [PATCH 46/55] Update README.md --- Community Developed/Trellix HX/README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Community Developed/Trellix HX/README.md b/Community Developed/Trellix HX/README.md index d844f0a0..82ed0549 100644 --- a/Community Developed/Trellix HX/README.md +++ b/Community Developed/Trellix HX/README.md @@ -13,6 +13,6 @@ User account to access FireEye HX Controller with api_analyst role - - https://fireeye.dev/apis/lighthouse/ ## Event Types Currently Supported by the workflow: -- - Alerts: Gets a list of non-suppressed alerts known to the system -- - Alert Groups: Lists all alert_groups -- - Process Tracker Module events +- Alerts: Gets a list of non-suppressed alerts known to the system +- Alert Groups: Lists all alert_groups +- Process Tracker Module events From 6658de3946428a52c8c41439f66d86ed3274fe18 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:47:02 +0200 Subject: [PATCH 47/55] Update Trellix-HX-ProcessTracker-Workflow.xml Update workflow logic to count for non-linear Event IDs --- .../Trellix-HX-ProcessTracker-Workflow.xml | 189 +++++++++++------- 1 file changed, 112 insertions(+), 77 deletions(-) diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml index 47e81d69..896bb695 100644 --- a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml +++ b/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml @@ -1,17 +1,17 @@ - + - + - + @@ -20,85 +20,120 @@ - + - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + From 3c95ec88099465708030d56b1e1a9cf1dcfc9354 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:52:27 +0200 Subject: [PATCH 48/55] Rename Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml Reorganization --- .../{ => Process Tracker}/Trellix-HX-ProcessTracker-Workflow.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{ => Process Tracker}/Trellix-HX-ProcessTracker-Workflow.xml (100%) diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml similarity index 100% rename from Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow.xml rename to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml From 72cff029550cf2e2a77dd488ad3e6b00b03bcf84 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:52:59 +0200 Subject: [PATCH 49/55] Rename Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml Reorganization --- .../Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{ => Process Tracker}/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml (100%) diff --git a/Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml similarity index 100% rename from Community Developed/Trellix HX/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml rename to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml From cda8eaea37e5177f4f1e36c449fa8872f7cdfd20 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:53:25 +0200 Subject: [PATCH 50/55] Rename Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml Reorganization --- .../Trellix HX/{ => Alerts}/Trellix-HX-Alerts-Workflow.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{ => Alerts}/Trellix-HX-Alerts-Workflow.xml (100%) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml similarity index 100% rename from Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow.xml rename to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml From 18ed4ca164dbc126908cf51f841bfb0ef7782f4a Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:53:52 +0200 Subject: [PATCH 51/55] Rename Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml Reorganization --- .../{ => Alerts}/Trellix-HX-Alerts-Workflow-Parameter-Value.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{ => Alerts}/Trellix-HX-Alerts-Workflow-Parameter-Value.xml (100%) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml similarity index 100% rename from Community Developed/Trellix HX/Trellix-HX-Alerts-Workflow-Parameter-Value.xml rename to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml From 35d3f562185e92234bd0da37b3dcfeb7e3983328 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:54:30 +0200 Subject: [PATCH 52/55] Rename Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml Reorganization --- .../{ => Alert Groups}/Trellix-HX-Alert_Groups-Workflow.xml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{ => Alert Groups}/Trellix-HX-Alert_Groups-Workflow.xml (100%) diff --git a/Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml similarity index 100% rename from Community Developed/Trellix HX/Trellix-HX-Alert_Groups-Workflow.xml rename to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml From 746b04b52023d6148a4edb0ee5161ce8f9309745 Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:55:11 +0200 Subject: [PATCH 53/55] Rename Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml Reorganization --- .../Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Community Developed/Trellix HX/{FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml => Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml} (100%) diff --git a/Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml similarity index 100% rename from Community Developed/Trellix HX/FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml rename to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml From 0bec7679c6b4ca878c977e86f01b0e6c61accb7a Mon Sep 17 00:00:00 2001 From: Mohamed Al-Shabrawy <12400622+M-Shabrawy@users.noreply.github.com> Date: Wed, 25 Dec 2024 18:58:01 +0200 Subject: [PATCH 54/55] Update README.md Updated descriptions --- Community Developed/Trellix HX/README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Community Developed/Trellix HX/README.md b/Community Developed/Trellix HX/README.md index 82ed0549..2f0be395 100644 --- a/Community Developed/Trellix HX/README.md +++ b/Community Developed/Trellix HX/README.md @@ -1,4 +1,4 @@ -# QRadar Workflow for Trellix HX Alerts +# QRadar Workflows for Trellix HX IBM QRadar Universal Cloud Connector Workflows for reading Trellix/FireEye HX Alerts and Events through REST API ## Requirements: @@ -13,6 +13,6 @@ User account to access FireEye HX Controller with api_analyst role - - https://fireeye.dev/apis/lighthouse/ ## Event Types Currently Supported by the workflow: -- Alerts: Gets a list of non-suppressed alerts known to the system -- Alert Groups: Lists all alert_groups -- Process Tracker Module events +- Alerts: Collects non-suppressed alerts known to the system. +- Alert Groups: Collects alert_groups. +- Process Tracker: Collects Process Tracker module events. From 5900a194edba4a7da85ebc7757a4e6ba7d6050b8 Mon Sep 17 00:00:00 2001 From: Mohamed AlShabrawy Date: Thu, 26 Dec 2024 15:55:40 +0300 Subject: [PATCH 55/55] - Updated missing first event ID logic - minor bugs Signed-off-by: Mohamed Al-Shabrawy <@M-Shabrawy> --- .../Alerts/Trellix-HX-Alerts-Workflow.xml | 183 ++++++++++-------- .../Trellix-HX-ProcessTracker-Workflow.xml | 21 +- 2 files changed, 119 insertions(+), 85 deletions(-) diff --git a/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml index 59ca5f9e..f5c9fe5c 100644 --- a/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml +++ b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml @@ -7,107 +7,138 @@ - - - - - + + - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + - - - + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + - + + + + + + + + diff --git a/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml index 896bb695..d67517e1 100644 --- a/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml +++ b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml @@ -40,8 +40,8 @@ - - + + @@ -57,7 +57,7 @@ - + @@ -74,8 +74,8 @@ - - + + @@ -90,12 +90,15 @@ - + - + + + + @@ -112,7 +115,7 @@ - + @@ -123,7 +126,7 @@ - +