Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proactive threat hunting pack latest #28853

Merged
merged 367 commits into from Nov 19, 2023
Merged

Conversation

ArikDay
Copy link
Contributor

@ArikDay ArikDay commented Aug 8, 2023

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: link to the issue

Description

The "Proactive Threat Hunting" pack for XSOAR enables users to initiate threat hunting sessions with the primary goal of identifying undetected threats within their environment. This pack supports two distinct hunting methods:
SDO Hunting: Users can build hypotheses around specific STIX Data Object (SDO) indicators such as Campaigns, Intrusion Sets, or Malware. The pack allows for the search of Indicators of Compromise (IOCs) related to the selected SDO indicator, as well as the identification of tools and tactics used in the corresponding attack pattern.
Freestyle Hunt: This method empowers threat hunters to execute custom queries, upload their own IOCs, and conduct comprehensive searches and data enrichment on entities within the environment.
Additionally, both hunting methods in the pack offer the capability to take remediation actions directly from the hunting session layout. This includes the ability to block IOCs, isolate endpoints, block accounts, and quarantine files, providing a holistic approach to threat hunting and response.
Overall, the "Proactive Threat Hunting" pack enhances XSOAR's capabilities by allowing security teams to proactively explore and identify potential threats, providing a powerful toolset to enhance the organization's cybersecurity posture.

Must have

  • Tests
  • Documentation

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.4.20.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CortexXDR pack version was bumped to 6.0.2.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.4.21.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.4.22.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.4.23.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonPlaybooks pack version was bumped to 2.4.24.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@ArikDay ArikDay merged commit f36e7fd into master Nov 19, 2023
16 of 17 checks passed
@ArikDay ArikDay deleted the Proactive_Threat_Hunting_Pack_Latest branch November 19, 2023 08:46
sapirshuker pushed a commit that referenced this pull request Dec 21, 2023
* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Script Test

* Readme fix

* dependencies fix

* Readme fix

* Indicator Layout Fix

* playbook fix

* Playbook fixes

* Release-note fix

* Release-note fix

* vix validation

* Resolve conflicts

* Resolve conflicts

* Resolve conflicts

* Resolve conflicts

* Resolve conflicts

* Add no indicator unittest

* Add no indicator unittest

* Add no indicator unittest

* Add no indicator unittest

* Add no indicator unittest

* Add no indicator unittest

* Fix readme

* Script review fixes

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.2.

* Wizard Trial

* delete wizard

* Bump pack from version CortexXDR to 5.0.8.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.3.

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/MicrosoftDefenderAdvancedThreatProtection/Playbooks/playbook-MDE_-_Search_And_Block_Software.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* fix docker image

* Bump pack from version CommonPlaybooks to 2.3.90.

* Bump pack from version CommonPlaybooks to 2.3.91.

* Bump pack from version CommonPlaybooks to 2.3.92.

* Bump pack from version CommonPlaybooks to 2.3.93.

* Bump pack from version CortexXDR to 5.0.9.

* Bump pack from version FeedLOLBAS to 1.0.7.

* Bump pack from version CommonPlaybooks to 2.3.94.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.4.

* Bump pack from version CortexXDR to 5.0.10.

* Bump pack from version CommonPlaybooks to 2.3.95.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.5.

* Bump pack from version CortexXDR to 5.0.11.

* Bump pack from version CommonPlaybooks to 2.3.96.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.6.

* Bump pack from version CortexXDR to 5.1.1.

* Bump pack from version CommonPlaybooks to 2.3.97.

* Bump pack from version CortexXDR to 5.1.2.

* Bump pack from version CommonPlaybooks to 2.3.98.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.7.

* Bump pack from version CommonPlaybooks to 2.3.99.

* Bump pack from version CortexXDR to 5.1.3.

* Bump pack from version FeedLOLBAS to 1.0.8.

* Docker

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.8.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.9.

* Bump pack from version CommonTypes to 3.3.85.

* Bump pack from version CortexXDR to 5.1.4.

* fixes

* fixes

* fixes

* fixes

* Bump pack from version CommonPlaybooks to 2.4.2.

* Bump pack from version CommonTypes to 3.3.86.

* Bump pack from version CortexXDR to 5.1.5.

* Bump pack from version CommonPlaybooks to 2.4.3.

* Bump pack from version CommonPlaybooks to 2.4.4.

* Bump pack from version CommonTypes to 3.3.87.

* Bump pack from version CommonTypes to 3.3.88.

* Bump pack from version CortexXDR to 5.1.6.

* updated docker

* fix

* fix

* Bump pack from version CortexXDR to 5.1.7.

* Bump pack from version CortexXDR to 5.1.8.

* Add ons

* input fix

* FieldToPackIgnore

* add fromversion

* Cheat Sheet Fix

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.10.

* Bump pack from version CommonPlaybooks to 2.4.5.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.11.

* Bump pack from version FeedLOLBAS to 1.0.9.

* Bump pack from version CommonPlaybooks to 2.4.6.

* Bump pack from version CortexXDR to 5.1.9.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.12.

* Bump pack from version CommonPlaybooks to 2.4.7.

* Bump pack from version CortexXDR to 5.1.10.

* Bump pack from version CommonPlaybooks to 2.4.8.

* Bump pack from version CommonPlaybooks to 2.4.9.

* Bump pack from version CommonPlaybooks to 2.4.10.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.13.

* Bump pack from version CommonPlaybooks to 2.4.11.

* Bump pack from version CommonPlaybooks to 2.4.12.

* Bump pack from version CortexXDR to 5.2.1.

* Bump pack from version CortexXDR to 5.2.2.

* Bump pack from version FeedLOLBAS to 1.0.10.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.14.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.15.

* Bump pack from version CommonPlaybooks to 2.4.13.

* Bump pack from version CommonPlaybooks to 2.4.14.

* Bump pack from version CortexXDR to 5.2.3.

* Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.16.

* Bump pack from version CortexXDR to 5.2.4.

* Review Fixes

* Review Fixes

* bump

* fix

* Fixes

* fix README

* bump

* fix

* fixes

* fix

* fix

* Bump pack from version CommonPlaybooks to 2.4.18.

* fix

* fix rn

* Bump pack from version CommonPlaybooks to 2.4.19.

* Bump pack from version CommonPlaybooks to 2.4.20.

* fix

* rn

* Bump pack from version CortexXDR to 6.0.2.

* Bump pack from version CommonPlaybooks to 2.4.21.

* Bump pack from version CommonPlaybooks to 2.4.22.

* Bump pack from version CommonPlaybooks to 2.4.23.

* add video

* Bump pack from version CommonPlaybooks to 2.4.24.

* udpatedockerimage

---------

Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
5 participants