From 06df0646a0e266ec3cb73cd33ea800a40a63cd97 Mon Sep 17 00:00:00 2001 From: Mai Morag <81917647+maimorag@users.noreply.github.com> Date: Thu, 19 Sep 2024 12:58:34 +0300 Subject: [PATCH] adding integrations a-c (#36389) * adding integrations a-c * rn --- .../AnomaliThreatStream/README.md | 10 ++++---- .../Integrations/ArcSightLogger/README.md | 6 ++--- Packs/BigFix/Integrations/BigFix/README.md | 22 +++++++++--------- Packs/BitDam/Integrations/BitDam/README.md | 4 ++-- .../Carbonblackliveresponse/README.md | 14 +++++------ .../Integrations/CheckPoint/README.md | 6 ++--- .../CiscoWebexEventCollector_description.md | 2 +- Packs/CiscoSpark/ReleaseNotes/1_0_10.md | 6 +++++ .../doc_files/get_organization_id.png | Bin 233843 -> 358991 bytes Packs/CiscoSpark/pack_metadata.json | 2 +- .../Integrations/FalconHost/README.md | 20 ++++++++-------- .../Integrations/Cylance_Protect_v2/README.md | 8 +++---- 12 files changed, 53 insertions(+), 47 deletions(-) create mode 100644 Packs/CiscoSpark/ReleaseNotes/1_0_10.md diff --git a/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md b/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md index 528b72795ad7..6182cace1b62 100644 --- a/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md +++ b/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md @@ -221,7 +221,7 @@ \u0026limit=1\u0026offset=1",
"offset":0,
"previous":null,
"took":39,
"total_count":49906
},
"objects":[
{
"asn":"12849",
"confidence":100,
"country":"IL",
"created_ts":"2018-01-03T16:59:29.054Z",
"description":null,
"expiration_ts":"2018-04-12T13:37:28.417Z",
"feed_id":122,
"id":50460807643,
"import_session_id":null,
"ip":"5.29.211.60",
"is_public":false,
"itype":"tor_ip",
"latitude":"32.332900",
"longitude":"34.859900",
"meta":{
"detail2":"bifocals_deactivated_on_2018-04-10_20:32:42.816201",
"severity":"low"
},
"modified_ts":"2018-04-11T13:37:28.423Z",
"org":"HOTnet",
"owner_organization_id":2,
"rdns":null,
"resource_uri":"/api/v2/intelligence/50460807643/",
"retina_confidence":-1,
"source":"TOR Exit Nodes",
"source_reported_confidence":100,
"status":"active",
"tags":null,
"threat_type":"tor",
"threatscore":25,
"trusted_circle_ids":[
146
],
"type":"ip",
"update_id":1763222542,
"uuid":"56260f15-377a-48e7-ad40-121f8580a4c5",
"value":"5.29.211.60",
"workgroups":[

War Room Output

Command: !threatstream-intelligence limit="1" country="IL"

-

image

+

image

Check IP/domain reputation: domain

Inputs

@@ -247,7 +247,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":17,
         "country":"RO",
         "created_ts":"2017-06-02T18:09:41.986Z",
         "description":null,
         "expiration_ts":"2017-08-31T11:58:38.253Z",
         "feed_id":0,
         "id":859843899,
         "import_session_id":213529,
         "ip":"185.72.179.152",
         "is_public":true,
         "itype":"adware_domain",
         "latitude":"46.000000",
         "longitude":"25.000000",
         "meta":{  
            "detail":"",
            "detail2":"bifocals_deactivated_on_2017-08-31_12:47:29.013755",
            "severity":"low"
         },
         "modified_ts":"2017-08-31T12:47:28.926Z",
         "org":"Nix Web Solutions Pvt Ltd",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/859843899/",
         "retina_confidence":17,
         "source":"Analyst",
         "source_reported_confidence":90,
         "status":"inactive",
         "tags":[  
            {  
               "id":"rd4",
               "name":"pony"
            }
         ],
         "threat_type":"adware",
         "threatscore":4,
         "trusted_circle_ids":null,
         "type":"domain",
         "update_id":1023048164,
         "value":"kpanels.in",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !domain domain="kpanels.in" threshold="3"

-

image

+

image

Check file's checksum reputation: file

Inputs

@@ -273,7 +273,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":45,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":92,
         "country":null,
         "created_ts":"2017-06-07T13:01:10.143Z",
         "description":null,
         "expiration_ts":"2017-09-04T13:31:00.194Z",
         "feed_id":0,
         "id":872721081,
         "import_session_id":214717,
         "ip":null,
         "is_public":true,
         "itype":"apt_md5",
         "latitude":null,
         "longitude":null,
         "meta":{  
            "detail":"",
            "detail2":"imported by user 3096",
            "severity":"very-high"
         },
         "modified_ts":"2017-06-07T13:03:03.200Z",
         "org":"",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/872721081/",
         "retina_confidence":-1,
         "source":"Analyst",
         "source_reported_confidence":92,
         "status":"active",
         "tags":[  
            {  
               "id":"03e",
               "name":"trickbot"
            }
         ],
         "threat_type":"apt",
         "threatscore":79,
         "trusted_circle_ids":null,
         "type":"md5",
         "update_id":854928373,
         "value":"3e5d63b93a68d715f7559f42285223f4",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !file file="3e5d63b93a68d715f7559f42285223f4" threshold="3"

-

image

+

image

Check Email Address Reputation: threatstream-email-reputation

Inputs

@@ -299,7 +299,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":17,
         "country":"RO",
         "created_ts":"2017-06-02T18:09:41.986Z",
         "description":null,
         "expiration_ts":"2017-08-31T11:58:38.253Z",
         "feed_id":0,
         "id":859843899,
         "import_session_id":213529,
         "ip":"185.72.179.152",
         "is_public":true,
         "itype":"adware_domain",
         "latitude":"46.000000",
         "longitude":"25.000000",
         "meta":{  
            "detail":"",
            "detail2":"bifocals_deactivated_on_2017-08-31_12:47:29.013755",
            "severity":"low"
         },
         "modified_ts":"2017-08-31T12:47:28.926Z",
         "org":"Nix Web Solutions Pvt Ltd",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/859843899/",
         "retina_confidence":17,
         "source":"Analyst",
         "source_reported_confidence":90,
         "status":"inactive",
         "tags":[  
            {  
               "id":"rd4",
               "name":"pony"
            }
         ],
         "threat_type":"adware",
         "threatscore":4,
         "trusted_circle_ids":null,
         "type":"domain",
         "update_id":1023048164,
         "value":"kpanels.in",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !threatstream-email-reputation email="mailonline_16@filposcv.com" threshold="3"

-

image

+

image

Check IP Reputation: ip

Inputs

@@ -325,7 +325,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"12400",
         "confidence":69,
         "country":"IL",
         "created_ts":"2018-03-13T10:45:16.182Z",
         "description":null,
         "expiration_ts":"2018-03-20T10:45:16.178Z",
         "feed_id":112,
         "id":50591222843,
         "import_session_id":null,
         "ip":"176.228.66.70",
         "is_public":false,
         "itype":"scan_ip",
         "latitude":"31.964200",
         "longitude":"34.804400",
         "meta":{  
            "detail2":"bifocals_deactivated_on_2018-03-20_13:56:34.918843",
            "severity":"medium"
         },
         "modified_ts":"2018-03-20T13:56:34.461Z",
         "org":"Orange Israel",
         "owner_organization_id":2,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/50591222843/",
         "retina_confidence":69,
         "source":"Anomali Labs MHN",
         "source_reported_confidence":70,
         "status":"inactive",
         "tags":null,
         "threat_type":"scan",
         "threatscore":25,
         "trusted_circle_ids":[  
            145
         ],
         "type":"ip",
         "update_id":1695845308,
         "uuid":"09688972-7581-4fb9-8e50-7c99a02cd442",
         "value":"176.228.66.70",
         "workgroups":[  

         ]
      }
   ]
}

War Room Output

Command: !ip ip="176.228.66.70" threshold="3"

-

image

+

image

Troubleshooting

The integration was tested with the v2 API on version 2.5.4.

-

This may indicate that a large amount of data returned from Arcsight Logger. To resolve this error, try to limit the search time range or the events list length.  See additional ways to set the search time range in ‘Additional info’ above.
DBot error snap-shot
 

+

This may indicate that a large amount of data returned from Arcsight Logger. To resolve this error, try to limit the search time range or the events list length.  See additional ways to set the search time range in ‘Additional info’ above.
DBot error snap-shot