Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cloud user investigation #28843

Merged
merged 27 commits into from Aug 14, 2023
Merged

Cloud user investigation #28843

merged 27 commits into from Aug 14, 2023

Conversation

OmriItzhak
Copy link
Contributor

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: link to the issue

Description

These playbooks perform an investigation on a specific user in cloud environments, using queries and logs from Azure Log Analytics, AWS CloudTrail, G Suite Auditor, and GCP Logging.

Must have

  • Tests
  • Documentation

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.3.88.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.3.89.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • GCP-Enrichment-Remediation pack version was bumped to 1.1.6.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@ShirleyDenkberg
Copy link
Contributor

@melamedbn Doc review completed.

OmriItzhak and others added 6 commits August 13, 2023 10:30
…nvestigation

� Conflicts:
�	Packs/CommonPlaybooks/ReleaseNotes/2_3_88.md
�	Packs/GCP-Enrichment-Remediation/ReleaseNotes/1_1_5.md
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
OmriItzhak and others added 2 commits August 13, 2023 11:25
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
@melamedbn
Copy link
Contributor

For all of the AWS filters (API Access, Failed Login, etc.) I think we should elaborate in the task details what's our goal and what are we searching for.

@melamedbn
Copy link
Contributor

Azure -
Did you choose a specific index on purpose? '[0].[1]' for the Set tasks?

@melamedbn
Copy link
Contributor

Azure, AWS and GCP - all of the playbook descriptions should be formatted and more informative.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.3.90.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@ShirleyDenkberg
Copy link
Contributor

@melamedbn Doc review completed.

OmriItzhak and others added 3 commits August 14, 2023 15:10
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…_Investigation.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
@OmriItzhak OmriItzhak merged commit b418b63 into master Aug 14, 2023
13 of 14 checks passed
@OmriItzhak OmriItzhak deleted the Cloud_User_Investigation branch August 14, 2023 14:07
xsoar-bot pushed a commit to xsoar-contrib/content that referenced this pull request Oct 5, 2023
* PB + RM cloud user investigation

* RN for the Playbooks cloud user investigation

* update skipifunavailable

* Bump pack from version CommonPlaybooks to 2.3.88.

* Bump pack from version CommonPlaybooks to 2.3.89.

* Bump pack from version GCP-Enrichment-Remediation to 1.1.6.

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* fix after doc review

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* fix after review

* fix after review

* fix after review

* Bump pack from version CommonPlaybooks to 2.3.90.

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/GCP-Enrichment-Remediation/Playbooks/playbook-GCP_-_User_Investigation.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update playbook-AWS_-_User_Investigation.yml

---------

Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
4 participants