Skip to content

Releases: Palo-Cortex/soc-optimization

V2.1.19

18 Nov 15:47
7b53c92

Choose a tag to compare

Refactor/playbooks/maintenance/playbook structure (#80)

* - Remove unused Lists

* - SOC Framework Playbook Structure

* - Upon Trigger - Evironment Detections Update
- Upon Trigger - Product Categorization Addition
- Version 2 of the Upon Trigger started.
- Updated the EP_IR_NIST_(800-61).yml with the new Upon Trigger V2.

* Adding new Lists:
- Product to Data Source to Category mapping
- Vendor Capabilities for Actions in Containment, Eradication, and Recovery
- SOC Framework Actions List

* Updates to Playbooking.
Refactoring for Modularity, Scalablity, and Easy of Use.
Updated:
- Upon Trigger to have subplaybooks for all stages
- Moved Severity Calculations to Assessment stage
- Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config
- Stopped loading SOC Optimization Config in Data Context
- Cleaning up Data Context by putting more under SOCFramework key
- Moved ShadowMode Data Context Key under SOCFramework.
- Reduced Loading for configuration (removed tasks)

* Updates to Playbooking.
Refactoring for Modularity, Scalablity, and Easy of Use.
Updated:
- Upon Trigger to have subplaybooks for all stages
- Moved Severity Calculations to Assessment stage
- Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config
- Stopped loading SOC Optimization Config in Data Context
- Cleaning up Data Context by putting more under SOCFramework key
- Moved ShadowMode Data Context Key under SOCFramework.
- Reduced Loading for configuration (removed tasks)

* Updates to Playbooking.
Refactoring for Modularity, Scalablity, and Easy of Use.
Updated:
- Upon Trigger to have subplaybooks for all stages
- Moved Severity Calculations to Assessment stage
- Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config
- Stopped loading SOC Optimization Config in Data Context
- Cleaning up Data Context by putting more under SOCFramework key
- Moved ShadowMode Data Context Key under SOCFramework.
- Reduced Loading for configuration (removed tasks)

* - Refactoring Noramlization
- Adding Product Type routing through framework
- Renamed JOBs due to id conflict.  Now they are V2
- Adding lists for command abstraction based on Core Data Sources

V2.1.15

04 Nov 14:30
0d9b023

Choose a tag to compare

Update dashboard noxsiam (#66)

* - Update to the NO XSIAM Widget in the Value Metrics dash to correctly refer to issues and not cases since current toolsets primarily use alerts.
- Bump Version

* - Bump Version

V2.1.14

04 Nov 14:04
7a58b36

Choose a tag to compare

- Update to the NO XSIAM Widget in the Value Metrics dash to correctl…

V2.1.13

15 Oct 20:39
55ec002

Choose a tag to compare

- Added Trend Micro Enrichment to Upon Trigger when enhancement pack …

V2.1.12

10 Oct 19:37
8a83cfa

Choose a tag to compare

Update trendmicro (#60)

* - Updated in Upon Trigger to Handle Trend Micro Endpoint Enrichment if the Enhancement pack is installed.

* - Added trendmicro-visionone-get-alert-details command to value_tags.json

* - Adopting playbook Foundation_Common_-_Extract_Indicators_from_alerts.yml
- Bumping version up

V2.1.11

08 Oct 22:56
6c08211

Choose a tag to compare

Update EP_MITRE_Tactic.yml (#59)

V2.1.10

06 Oct 13:55
52f7d69

Choose a tag to compare

- Update Upon Trigger logic to position normalization + alert indicat…

V2.1.9

03 Oct 21:38
8d510e7

Choose a tag to compare

Update upontrigger extractalertindicators (#54)

* - Added the Foundation Extract Indicators for the Upon Trigger
- Updated the Upon Trigger to include the Playbook

* - Adding Version 2.7 Value Metrics Dashboard with 3.X

* Bump Version

V2.1.8

26 Sep 15:37
e263216

Choose a tag to compare

Update dash (#52)

* Fixing inconsistencies in the Triage Job.

* Fixing inconsistencies in the naming and is for the Triage Job.

* Changing incidents_per_hour to divide by 24 instead of 8 in Analysts required widgets in the Value Metric Dashboard

V2.1.7

18 Sep 16:53
0a910f9

Choose a tag to compare

Fix auto triage naming (#44)

* Update pack_metadata.json

* Update xsoar_config.json