Skip to content
This repository has been archived by the owner on Jun 27, 2023. It is now read-only.

Fwang/pr/sync fork 2023 06 26 #302

Open
wants to merge 4,434 commits into
base: master
Choose a base branch
from
Open

Conversation

fraankwang
Copy link
Collaborator

Sync the Abnormal fork with the upstream fork

edik24 and others added 30 commits June 9, 2023 11:48
…o#27103)

* Update incidentfield-Darktrace_Model_Breach_CommentCount.json

* Update pack_metadata.json

* Create 2_0_6.md

* Update 2_0_6.md

* Update 2_0_6.md

* RN

* RN

* RN
* Added get policy command

* change from AWS-Lambda to AWS_Lambda

* Added UT for policy

* Fix UT

* Fix UT

* del duplicate code

* Added list-versions and url_config

* update yml

* added 3 commands

* added 3 commands

* update docker

* lint MD

* fix yml

* update RN

* improve

* added readme and some improve

* del copy

* added docstring

* fix line to long

* test playbook and update docker

* update fromVersion

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/AWS-Lambda/Integrations/AWS_Lambda/AWS_Lambda.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* change  List of strings to list

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* change md

* autofix on

* autofix

* autofix

* Apply automatic changes

* Revert "autofix on"

This reverts commit 1039a09.

* Revert "autofix on"

This reverts commit 1039a09.

* undo pre-commit

* update docker

* fix demo

* update yml

* change file name

* change file name to aws_lambda

* update docker  and UT

* fix mypy

* fix

* undo fix

* update docker and cr

* added Principal

* update docker

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: shmuel44 <shmuel44@users.noreply.github.com>
* Change source_user arg to list

* Update yml file

* Update yml changes to pan-os and panorama

* Update release notes

* Update 1_17_5.md

* Rename 1_17_5.md to 1_17_6.md

* Delete 1_17_6.md

* Update RN

* Add UT for PR changes

* Update README.md

* Update Packs/PAN-OS/ReleaseNotes/1_17_6.md

Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com>

* Version bump

* Update docker image

* Update RN

---------

Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com>
* custom user agent on builds
* Update .devcontainer.json name

* Added cofense-report-attachment-payload-list command

* Updated context example in report attachment payload list command

* Updated docker images in all YML files

* Updated release notes

---------

Co-authored-by: Crest Data Systems <60967033+crestdatasystems@users.noreply.github.com>
Co-authored-by: crestdatasystems <crestdatasystems@users.noreply.github.com>
Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com>
* Align credentials stores part 10

* SumoLogic

* Proofpoint Feed

* required change

* adding tests
* add fetch logs to nightly build fetch integrations

* fix QRadar tests

* update release notes and docker files

* fix expansev2

* rn

* fix logs

* fix flask8

* added date field to skip incident log

* resolve conflict

* Bump pack from version QRadar to 2.4.22.

---------

Co-authored-by: Content Bot <bot@demisto.com>
* cortexDataLake

* update docker

* GenericSQL logs

* update rn

* md-atp logs

* update docker

* adding time to skip incidents

* update docker
* AWS Feed - added support for IPv6

* added tests

* cr

* tests an rn

* validation

* rn

* cr

* di
* Bump sane-pdf-report docker image

* Bump pack from version Base to 1.32.11.

---------

Co-authored-by: Content Bot <bot@demisto.com>
* fixed file name

* RN

* RN

* Update 3_3_74.md
* update setup poetry

* use pip

* change Setup Poetry to use Gr1N

* change Setup Poetry to use Gr1N in pre commit
* bug fix

* RN update

---------

Co-authored-by: xsoar-bot <xsoar-bot@paloaltonetworks.com>
* fixed a mypy issue

* added rn

* fix
* Enhancement for modeling rules.

* added telephony modeling rule

* modified modeling rule

* modified shcema file.

* Added release notes.

* Added release notes.

* updated pack metadata release notes.
* "Plug & Enrich" tags and FreeEnrichers pack

* Added tags to approved list

* Updated and corrected the readme.

* Another small fix of a typo in readme

* Reverted accidentally removing pack name

* Better formatting

* Added "Free Enricher" to all "Plug & Fetch" enrichers
* fix type

* Add UTs for changed add_reply function

* add credential defaults, improve UT

---------

Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com>
* Added code for integration of events

* Code review Feedback

* changes in fetch incident

* PR Review change

* PR Review change

* changes in read me file

* Changed read me file based on the review

* Changes for playbook and intergration

* changes in the read me file

* PR changes

* changes in image and docker image

* change in services in alert

* changes for alert

* Changes in docker image

* Changes for docker image

* Update Packs/CybleThreatIntel/Integrations/CybleThreatIntel/CybleThreatIntel.yml



* Update Packs/CybleEventsV2/Integrations/CybleEventsV2/CybleEventsV2.yml



---------

Co-authored-by: cyble-dev <101622497+cyble-dev@users.noreply.github.com>
Co-authored-by: RotemAmit <71597826+RotemAmit@users.noreply.github.com>
…ass (new grid field) (demisto#27352)

* Added rank to domain

* RN

* Update CommonServerPython.py

* RN
* SplunkPy - fix uninformative error message when missing timezone in mirroring

* Added RNs

* Updated readme

* CR updates

* Update Packs/SplunkPy/ReleaseNotes/3_0_20.md

Co-authored-by: yuvalbenshalom <ybenshalom@paloaltonetworks.com>

* Updated Docker Image

---------

Co-authored-by: yuvalbenshalom <ybenshalom@paloaltonetworks.com>
merit-maita and others added 30 commits June 25, 2023 14:47
* switched to poetry

* added dependencies to toml

* added --with ci flag

* edit after validation failed

* edit

* added dateparser

* locked the file

* removed pipfile

* returned files

* edit yml

* reverted changes

* reverted changes

* moved dateparser to dev

* locked poetry

* removed flake8

* edited poetry lock

* edited poetry lock

* fixed the action to run on this specific pr

* fixed the action to run on this specific pr

* edit

* edit

* edit

* reverted changes to filled form and handle external pr

* edited handle stale prs

* edited handle stale prs again

* edited handle stale prs with ci

* check sync-contrib-base-branch, and revert stale branches

* reverted the base branch, and check base branch on change

* reverted the base branch, and check base branch on change

* reverted the base branch, and check base branch on change

* test close pr

* test close pr
* Added Opensearch support for Elasticsearch feed (demisto#27333)

* Added Opensearch support for Elasticsearch feed

* Updated release notes and readme

* Updated release notes and readme

* Revert changes to poetry lock

* Update docker image.
Remove tested on version x.x in README.

* Fix flake8 errors.

* Update docker comment in RN.

* Trying to add opensearchpy dependency for test

* fix flake8 errors.

* Adding known_words section

* Moving opensearch-py to dev-packages section.

* Update docker image

* Align yml docker with RN docker.

---------

Co-authored-by: Danny_Fried <dfried@paloaltonetworks.com>

* Updating docker image.

---------

Co-authored-by: anilagr <40182783+anilagr@users.noreply.github.com>
Co-authored-by: Danny_Fried <dfried@paloaltonetworks.com>
* Align credentials stores - part 22

* fix

* fix

* cr note
…atX, RedCanary (demisto#27679)

* RedCanary complete

* ThreatX complete

* GSuiteSecurityAlertCenter complete

* Akamai_SIEM complete

* fixed integrations

* fixed integrations 2

* update ThreatX

* update ThreatX
* Add support for epoch in milliseconds

* Update release notes

* update conversion to epoch milliseconds

* Fix release notes validations

* Update release notes

* Fix review comments

* Update 2_4_24.md
* Created a new playbook to perform YARA scan

* Created a new playbook to perform YARA scan

* Added pack readme
* Updated Metadata Of Pack CofenseTriage

* Added release notes to pack CofenseTriage

* Packs/CofenseTriage/Integrations/CofenseTriagev3/CofenseTriagev3.yml Docker image update

* Updated Metadata Of Pack SumoLogic_Cloud_SIEM

* Added release notes to pack SumoLogic_Cloud_SIEM

* Packs/SumoLogic_Cloud_SIEM/Integrations/SumoLogicCloudSIEM/SumoLogicCloudSIEM.yml Docker image update

* Updated Metadata Of Pack CiscoUmbrellaReporting

* Added release notes to pack CiscoUmbrellaReporting

* Packs/CiscoUmbrellaReporting/Integrations/CiscoUmbrellaReporting/CiscoUmbrellaReporting.yml Docker image update

* Updated Metadata Of Pack IronscalesEventCollector

* Added release notes to pack IronscalesEventCollector

* Packs/IronscalesEventCollector/Integrations/IronscalesEventCollector/IronscalesEventCollector.yml Docker image update

* Updated Metadata Of Pack TeamViewer

* Added release notes to pack TeamViewer

* Packs/TeamViewer/Integrations/TeamViewerEventCollector/TeamViewerEventCollector.yml Docker image update

* Updated Metadata Of Pack Palo_Alto_Networks_Enterprise_DLP

* Added release notes to pack Palo_Alto_Networks_Enterprise_DLP

* Packs/Palo_Alto_Networks_Enterprise_DLP/Integrations/Palo_Alto_Networks_Enterprise_DLP/Palo_Alto_Networks_Enterprise_DLP.yml Docker image update

* Updated Metadata Of Pack Twitter

* Added release notes to pack Twitter

* Packs/Twitter/Integrations/Twitterv2/Twitterv2.yml Docker image update

* Updated Metadata Of Pack CyberTriage

* Added release notes to pack CyberTriage

* Packs/CyberTriage/Integrations/CyberTriage/CyberTriage.yml Docker image update

* Updated Metadata Of Pack Rapid7_Nexpose

* Added release notes to pack Rapid7_Nexpose

* Packs/Rapid7_Nexpose/Integrations/Rapid7_Nexpose/Rapid7_Nexpose.yml Docker image update

* Updated Metadata Of Pack FortinetFortiwebVM

* Added release notes to pack FortinetFortiwebVM

* Packs/FortinetFortiwebVM/Integrations/FortinetFortiwebVM/FortinetFortiwebVM.yml Docker image update
* Updated Metadata Of Pack FeedAWS

* Added release notes to pack FeedAWS

* Packs/FeedAWS/Integrations/FeedAWS/FeedAWS.yml Docker image update
* Updated Metadata Of Pack FeedMalwareBazaar

* Added release notes to pack FeedMalwareBazaar

* Packs/FeedMalwareBazaar/Integrations/MalwareBazaarFeed/MalwareBazaarFeed.yml Docker image update

* Updated Metadata Of Pack FeedGCPWhitelist

* Added release notes to pack FeedGCPWhitelist

* Packs/FeedGCPWhitelist/Integrations/FeedGoogleIPRanges/FeedGoogleIPRanges.yml Docker image update

* Updated Metadata Of Pack AccentureCTI_Feed

* Added release notes to pack AccentureCTI_Feed

* Packs/AccentureCTI_Feed/Integrations/ACTIIndicatorFeed/ACTIIndicatorFeed.yml Docker image update
* added notes to ms teams readme

* fixed notes

* updated readme

* removed the app studio method

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftTeams/Integrations/MicrosoftTeams/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* removed the app studio method

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
* Updated Metadata Of Pack ExpanseV2

* Added release notes to pack ExpanseV2

* Packs/ExpanseV2/Integrations/FeedExpanse/FeedExpanse.yml Docker image update

* Packs/ExpanseV2/Integrations/ExpanseV2/ExpanseV2.yml Docker image update

* Packs/ExpanseV2/Scripts/ExpanseEvidenceDynamicSection/ExpanseEvidenceDynamicSection.yml Docker image update

* Packs/ExpanseV2/Scripts/ExpanseAggregateAttributionDevice/ExpanseAggregateAttributionDevice.yml Docker image update

* Updated Metadata Of Pack PaloAltoNetworks_IoT

* Added release notes to pack PaloAltoNetworks_IoT

* Packs/PaloAltoNetworks_IoT/Integrations/PaloAltoNetworks_IoT/PaloAltoNetworks_IoT.yml Docker image update
* Added TIM to marketplacev2

* update RN

* excluded incident types

* added docs where missing

* fix marketplaces field

* fix marketplaces field

* validation

* pack ignore

* pack ignore

* update RN

* pack ignore

* pack ignore
* Google align credentials stores - part 25

* fix
* Microsoft Align credentials stores -part 23

* fix lint

* RL

* fix

* fix

* fix

* fix rl

* fix client bug for  for Michal's request

* fixes
* fix syntax

* RN

* CC

* Update Packs/AzureSecurityCenter/ReleaseNotes/2_0_2.md

Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>

---------

Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>
* Add debug logs

* Add differentiation between authentication methods

* Remove extra debug logs

* Update docker image

* Update release notes

* Add known_words section to .pack-ignore fille

* Update Release Notes

* Update authentication related UTs
* hide widgets

* BC

* [known_words]

* remove those 2 packs

* Update Packs/CommonWidgets/ReleaseNotes/1_2_23.json

Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>

* RN

* RN

* Update Packs/CommonWidgets/ReleaseNotes/1_2_23.md

Co-authored-by: yuvalbenshalom <ybenshalom@paloaltonetworks.com>

---------

Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>
Co-authored-by: yuvalbenshalom <ybenshalom@paloaltonetworks.com>
* Align credentials stores - part 28

* Empty commit
…isto#27712)

* free feed

* Free Enrichers

* change free feed

* Dror fixes
demisto#27722)

* Changed the 'key' input value of the 'Get full detection details' task

* RN

* Added a a period (.) to the end of the RN line

* changed RN and YML tests configs

* added the 'system: true' to the YML file after it was removed by formatting command
…27600)

* [marketplace contributions] - fix issue where support labels are not added

* add unit-tests

* update comment

* update path of test

* path cwd

* fallback to master in case checkout failed

* docstrings improvments

* update print string

* add prints
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.