New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Proactive threat hunting pack latest #28853
Conversation
…nto Proactive_Threat_Hunting_Pack # Conflicts: # Packs/CommonPlaybooks/ReleaseNotes/2_3_87.md # Packs/CommonPlaybooks/pack_metadata.json
…nto Proactive_Threat_Hunting_Pack # Conflicts: # Packs/CommonPlaybooks/ReleaseNotes/2_3_89.md
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
…isto/content into Proactive_Threat_Hunting_Pack_Latest
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
…isto/content into Proactive_Threat_Hunting_Pack_Latest
This PR was automatically updated by a GitHub Action
To stop automatic version bumps, add the |
…isto/content into Proactive_Threat_Hunting_Pack_Latest
* Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Script Test * Readme fix * dependencies fix * Readme fix * Indicator Layout Fix * playbook fix * Playbook fixes * Release-note fix * Release-note fix * vix validation * Resolve conflicts * Resolve conflicts * Resolve conflicts * Resolve conflicts * Resolve conflicts * Add no indicator unittest * Add no indicator unittest * Add no indicator unittest * Add no indicator unittest * Add no indicator unittest * Add no indicator unittest * Fix readme * Script review fixes * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.2. * Wizard Trial * delete wizard * Bump pack from version CortexXDR to 5.0.8. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.3. * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Update Packs/MicrosoftDefenderAdvancedThreatProtection/Playbooks/playbook-MDE_-_Search_And_Block_Software.yml Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com> * fix docker image * Bump pack from version CommonPlaybooks to 2.3.90. * Bump pack from version CommonPlaybooks to 2.3.91. * Bump pack from version CommonPlaybooks to 2.3.92. * Bump pack from version CommonPlaybooks to 2.3.93. * Bump pack from version CortexXDR to 5.0.9. * Bump pack from version FeedLOLBAS to 1.0.7. * Bump pack from version CommonPlaybooks to 2.3.94. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.4. * Bump pack from version CortexXDR to 5.0.10. * Bump pack from version CommonPlaybooks to 2.3.95. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.5. * Bump pack from version CortexXDR to 5.0.11. * Bump pack from version CommonPlaybooks to 2.3.96. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.6. * Bump pack from version CortexXDR to 5.1.1. * Bump pack from version CommonPlaybooks to 2.3.97. * Bump pack from version CortexXDR to 5.1.2. * Bump pack from version CommonPlaybooks to 2.3.98. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.7. * Bump pack from version CommonPlaybooks to 2.3.99. * Bump pack from version CortexXDR to 5.1.3. * Bump pack from version FeedLOLBAS to 1.0.8. * Docker * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.8. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.9. * Bump pack from version CommonTypes to 3.3.85. * Bump pack from version CortexXDR to 5.1.4. * fixes * fixes * fixes * fixes * Bump pack from version CommonPlaybooks to 2.4.2. * Bump pack from version CommonTypes to 3.3.86. * Bump pack from version CortexXDR to 5.1.5. * Bump pack from version CommonPlaybooks to 2.4.3. * Bump pack from version CommonPlaybooks to 2.4.4. * Bump pack from version CommonTypes to 3.3.87. * Bump pack from version CommonTypes to 3.3.88. * Bump pack from version CortexXDR to 5.1.6. * updated docker * fix * fix * Bump pack from version CortexXDR to 5.1.7. * Bump pack from version CortexXDR to 5.1.8. * Add ons * input fix * FieldToPackIgnore * add fromversion * Cheat Sheet Fix * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.10. * Bump pack from version CommonPlaybooks to 2.4.5. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.11. * Bump pack from version FeedLOLBAS to 1.0.9. * Bump pack from version CommonPlaybooks to 2.4.6. * Bump pack from version CortexXDR to 5.1.9. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.12. * Bump pack from version CommonPlaybooks to 2.4.7. * Bump pack from version CortexXDR to 5.1.10. * Bump pack from version CommonPlaybooks to 2.4.8. * Bump pack from version CommonPlaybooks to 2.4.9. * Bump pack from version CommonPlaybooks to 2.4.10. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.13. * Bump pack from version CommonPlaybooks to 2.4.11. * Bump pack from version CommonPlaybooks to 2.4.12. * Bump pack from version CortexXDR to 5.2.1. * Bump pack from version CortexXDR to 5.2.2. * Bump pack from version FeedLOLBAS to 1.0.10. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.14. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.15. * Bump pack from version CommonPlaybooks to 2.4.13. * Bump pack from version CommonPlaybooks to 2.4.14. * Bump pack from version CortexXDR to 5.2.3. * Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1.16.16. * Bump pack from version CortexXDR to 5.2.4. * Review Fixes * Review Fixes * bump * fix * Fixes * fix README * bump * fix * fixes * fix * fix * Bump pack from version CommonPlaybooks to 2.4.18. * fix * fix rn * Bump pack from version CommonPlaybooks to 2.4.19. * Bump pack from version CommonPlaybooks to 2.4.20. * fix * rn * Bump pack from version CortexXDR to 6.0.2. * Bump pack from version CommonPlaybooks to 2.4.21. * Bump pack from version CommonPlaybooks to 2.4.22. * Bump pack from version CommonPlaybooks to 2.4.23. * add video * Bump pack from version CommonPlaybooks to 2.4.24. * udpatedockerimage --------- Co-authored-by: Content Bot <bot@demisto.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Status
Related Issues
fixes: link to the issue
Description
The "Proactive Threat Hunting" pack for XSOAR enables users to initiate threat hunting sessions with the primary goal of identifying undetected threats within their environment. This pack supports two distinct hunting methods:
SDO Hunting: Users can build hypotheses around specific STIX Data Object (SDO) indicators such as Campaigns, Intrusion Sets, or Malware. The pack allows for the search of Indicators of Compromise (IOCs) related to the selected SDO indicator, as well as the identification of tools and tactics used in the corresponding attack pattern.
Freestyle Hunt: This method empowers threat hunters to execute custom queries, upload their own IOCs, and conduct comprehensive searches and data enrichment on entities within the environment.
Additionally, both hunting methods in the pack offer the capability to take remediation actions directly from the hunting session layout. This includes the ability to block IOCs, isolate endpoints, block accounts, and quarantine files, providing a holistic approach to threat hunting and response.
Overall, the "Proactive Threat Hunting" pack enhances XSOAR's capabilities by allowing security teams to proactively explore and identify potential threats, providing a powerful toolset to enhance the organization's cybersecurity posture.
Must have