Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dlp enhancements #27612

Merged
merged 49 commits into from Jun 28, 2023
Merged

Dlp enhancements #27612

merged 49 commits into from Jun 28, 2023

Conversation

tomer-pan
Copy link
Contributor

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: https://jira-hq.paloaltonetworks.local/browse/CIAC-5721

Description

Enhancements to the DLP use case:
New playbooks and changes to the main playbook:

  • Enrichments
  • Approval process

Minimum version of Cortex XSOAR

  • 6.0.0
  • 6.1.0
  • 6.2.0
  • 6.5.0

Does it break backward compatibility?

  • Yes
    • Further details:
  • No

@ShirleyDenkberg ShirleyDenkberg self-assigned this Jun 27, 2023
- UserMessageApp
- ApproverMessageApp
- DenyMessage
- An approval process has been added
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- An approval process has been added
- Added an approval process.

- An approval process has been added
- Enrichment section - user details and file report.
- Communications with the user and the manager had been configured separately.
- Email communication channel was added.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Email communication channel was added.
- Added an email communication channel.

- ApproverMessageApp
- DenyMessage
- An approval process has been added
- Enrichment section - user details and file report.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Enrichment section - user details and file report.
- Added user details and file report in an Enrichment section.

- Email communication channel was added.
##### New: DLP - User Message App Check

- New: Check if the given message app exist and configured and retrieve the user details from it. (Available from Cortex XSOAR 6.8.0).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- New: Check if the given message app exist and configured and retrieve the user details from it. (Available from Cortex XSOAR 6.8.0).
New: Check if the given message app exists and is configured and retrieve the user details from it. (Available from Cortex XSOAR 6.8.0).


##### DlpAskFeedback
- Updated the Docker image to: *demisto/python3:3.10.12.63474*.
- Descriptions were updated to a more generic use case and not just upload violations.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Descriptions were updated to a more generic use case and not just upload violations.
- Updated descriptions to a more generic use case and not just upload violations.

@ShirleyDenkberg
Copy link
Contributor

@idovandijk @adi88d @DeanArbel Doc review completed.

tomer-pan and others added 3 commits June 27, 2023 16:23
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Copy link
Contributor

@idovandijk idovandijk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! Just a few comments

@tomer-pan tomer-pan merged commit 5e0f0af into master Jun 28, 2023
12 of 14 checks passed
@tomer-pan tomer-pan deleted the DLP_Enhancements branch June 28, 2023 12:56
MosheEichler pushed a commit that referenced this pull request Jul 2, 2023
* playbooks and images

* RN

* Playbooks

* Playbooks

* layout

* automation

* integration

* readme

* incident field

* image

* RN

* layout fix

* pre-commit fixes

* secret ignore

* Add EXCEPTION_DENIED as an option to command

* common fields

* layout

* RN

* RN

* ignore IF100

* remove numberoffailedevents

* change new playbook name

* Add 6.8 split for playbook and layout

* ignore 106

* layout toVersion

* pack metadata

* Readme

* Bump pack from version CommonTypes to 3.3.77.

* after review changes

* RN

* Add docs for auth

* description rename

* description rename

* Apply suggestions from docs review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from docs review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* description rename

* Apply suggestions from code review

Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com>

* RN

* RN

---------

Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com>
xsoar-bot pushed a commit to xsoar-contrib/content that referenced this pull request Jul 26, 2023
* playbooks and images

* RN

* Playbooks

* Playbooks

* layout

* automation

* integration

* readme

* incident field

* image

* RN

* layout fix

* pre-commit fixes

* secret ignore

* Add EXCEPTION_DENIED as an option to command

* common fields

* layout

* RN

* RN

* ignore IF100

* remove numberoffailedevents

* change new playbook name

* Add 6.8 split for playbook and layout

* ignore 106

* layout toVersion

* pack metadata

* Readme

* Bump pack from version CommonTypes to 3.3.77.

* after review changes

* RN

* Add docs for auth

* description rename

* description rename

* Apply suggestions from docs review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from docs review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* description rename

* Apply suggestions from code review

Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com>

* RN

* RN

---------

Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Ido van Dijk <43602124+idovandijk@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
4 participants