Releases: Palo-Cortex/soc-optimization
Releases · Palo-Cortex/soc-optimization
V2.1.19
Refactor/playbooks/maintenance/playbook structure (#80) * - Remove unused Lists * - SOC Framework Playbook Structure * - Upon Trigger - Evironment Detections Update - Upon Trigger - Product Categorization Addition - Version 2 of the Upon Trigger started. - Updated the EP_IR_NIST_(800-61).yml with the new Upon Trigger V2. * Adding new Lists: - Product to Data Source to Category mapping - Vendor Capabilities for Actions in Containment, Eradication, and Recovery - SOC Framework Actions List * Updates to Playbooking. Refactoring for Modularity, Scalablity, and Easy of Use. Updated: - Upon Trigger to have subplaybooks for all stages - Moved Severity Calculations to Assessment stage - Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config - Stopped loading SOC Optimization Config in Data Context - Cleaning up Data Context by putting more under SOCFramework key - Moved ShadowMode Data Context Key under SOCFramework. - Reduced Loading for configuration (removed tasks) * Updates to Playbooking. Refactoring for Modularity, Scalablity, and Easy of Use. Updated: - Upon Trigger to have subplaybooks for all stages - Moved Severity Calculations to Assessment stage - Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config - Stopped loading SOC Optimization Config in Data Context - Cleaning up Data Context by putting more under SOCFramework key - Moved ShadowMode Data Context Key under SOCFramework. - Reduced Loading for configuration (removed tasks) * Updates to Playbooking. Refactoring for Modularity, Scalablity, and Easy of Use. Updated: - Upon Trigger to have subplaybooks for all stages - Moved Severity Calculations to Assessment stage - Fixed JOBs to use a more XSIAM friendly JSON formatting for SOC Optimization Config - Stopped loading SOC Optimization Config in Data Context - Cleaning up Data Context by putting more under SOCFramework key - Moved ShadowMode Data Context Key under SOCFramework. - Reduced Loading for configuration (removed tasks) * - Refactoring Noramlization - Adding Product Type routing through framework - Renamed JOBs due to id conflict. Now they are V2 - Adding lists for command abstraction based on Core Data Sources
V2.1.15
Update dashboard noxsiam (#66) * - Update to the NO XSIAM Widget in the Value Metrics dash to correctly refer to issues and not cases since current toolsets primarily use alerts. - Bump Version * - Bump Version
V2.1.14
- Update to the NO XSIAM Widget in the Value Metrics dash to correctl…
V2.1.13
- Added Trend Micro Enrichment to Upon Trigger when enhancement pack …
V2.1.12
Update trendmicro (#60) * - Updated in Upon Trigger to Handle Trend Micro Endpoint Enrichment if the Enhancement pack is installed. * - Added trendmicro-visionone-get-alert-details command to value_tags.json * - Adopting playbook Foundation_Common_-_Extract_Indicators_from_alerts.yml - Bumping version up
V2.1.11
Update EP_MITRE_Tactic.yml (#59)
V2.1.10
- Update Upon Trigger logic to position normalization + alert indicat…
V2.1.9
Update upontrigger extractalertindicators (#54) * - Added the Foundation Extract Indicators for the Upon Trigger - Updated the Upon Trigger to include the Playbook * - Adding Version 2.7 Value Metrics Dashboard with 3.X * Bump Version
V2.1.8
Update dash (#52) * Fixing inconsistencies in the Triage Job. * Fixing inconsistencies in the naming and is for the Triage Job. * Changing incidents_per_hour to divide by 24 instead of 8 in Analysts required widgets in the Value Metric Dashboard
V2.1.7
Fix auto triage naming (#44) * Update pack_metadata.json * Update xsoar_config.json