Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CrowdStrike Falcon Horizon CSPM Enhancement #29716

Merged
merged 98 commits into from Oct 1, 2023

Conversation

anas-yousef
Copy link
Contributor

@anas-yousef anas-yousef commented Sep 18, 2023

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: https://jira-hq.paloaltonetworks.local/browse/CIAC-3855

Description

Added 4 new commands, and new incident types, with fetching mechanism for them.
This PR will have to be force merged, explanation

Must have

  • Tests
  • Documentation

@anas-yousef anas-yousef self-assigned this Sep 18, 2023
Copy link
Contributor

@dorschw dorschw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Impressive!

@ShirleyDenkberg ShirleyDenkberg self-assigned this Sep 20, 2023
@ilaner
Copy link
Contributor

ilaner commented Sep 28, 2023

Why there is no lookback support for the new incidents?

@yuvalbenshalom
Copy link
Contributor

Force merging, accepting the change in the mapper

@yuvalbenshalom yuvalbenshalom merged commit 5ce2969 into master Oct 1, 2023
13 of 15 checks passed
@yuvalbenshalom yuvalbenshalom deleted the ay-crowdstrike-falzon-horizon branch October 1, 2023 11:15
wolyslager pushed a commit to wolyslager/content that referenced this pull request Oct 2, 2023
* Fixing fetch unit tests

* Added unit tests, need to add documentation

* Added docstrings to unit tests

* Removed trace-id

* Removed Test from yml

* Added context data to commands

* Updated fromVerion in incident fields

* Fixed format errors

* Added README to scripts

* Added commands to README

* Added RNs

* Restore pack README

* Restore pack README

* Update pack-ignore

* Added docstrings to .py file

* Updated TPB, Layout

* Revert TPB

* Added fetch incidents to README.md

* Added more documentation

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Almost done with CR

* Increased timeout of TPB, added commands to TPB

* Added docs comments

* Fixed pre-commit errors

* Updated docker image in RNs

* Removed unecessary package

* Added to secrets ignore

* Fixed desriptions

* Fixed indentation

* Removed unnecessary tests

* Fixed conflcts

* Fixed incident fields names

* Increased timeout

* Increased timeout of task in test playbook

* Added Service Type to incident fields and mappers

* Added unit tests to scripts

* Improved documentation of unit tests

* Fixed unit tests imports

* Added named parameters to unit tests

* Added new lines to scripts unit tests

* Added handling if last fetch filter is empty

* Remove unnecessary import

* Removed incorrect incident field from mapper

* Reverted old RNs changes

* Update 1_11_11.md

* Reverted old RNs changes

* Removed updated docker image from RN

* Update 1_11_11.md

* Refactored lots of code, unit tests passed :)

* Updated docs wording

* Fixed pre-commit error

* Removed unnecessary extend to previous fetched ids

* Changed pack version to minor

* Deleted unnecessary arguments

* Kept mechansim of extned

* Fixed pre-commit

* Updated docker images

* Fixed argument position

* Passed is_paginating bool to check whether we are doing pagination or not

* Added is_paginating to if statement

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
xsoar-bot pushed a commit to xsoar-contrib/content that referenced this pull request Oct 5, 2023
* Fixing fetch unit tests

* Added unit tests, need to add documentation

* Added docstrings to unit tests

* Removed trace-id

* Removed Test from yml

* Added context data to commands

* Updated fromVerion in incident fields

* Fixed format errors

* Added README to scripts

* Added commands to README

* Added RNs

* Restore pack README

* Restore pack README

* Update pack-ignore

* Added docstrings to .py file

* Updated TPB, Layout

* Revert TPB

* Added fetch incidents to README.md

* Added more documentation

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Almost done with CR

* Increased timeout of TPB, added commands to TPB

* Added docs comments

* Fixed pre-commit errors

* Updated docker image in RNs

* Removed unecessary package

* Added to secrets ignore

* Fixed desriptions

* Fixed indentation

* Removed unnecessary tests

* Fixed conflcts

* Fixed incident fields names

* Increased timeout

* Increased timeout of task in test playbook

* Added Service Type to incident fields and mappers

* Added unit tests to scripts

* Improved documentation of unit tests

* Fixed unit tests imports

* Added named parameters to unit tests

* Added new lines to scripts unit tests

* Added handling if last fetch filter is empty

* Remove unnecessary import

* Removed incorrect incident field from mapper

* Reverted old RNs changes

* Update 1_11_11.md

* Reverted old RNs changes

* Removed updated docker image from RN

* Update 1_11_11.md

* Refactored lots of code, unit tests passed :)

* Updated docs wording

* Fixed pre-commit error

* Removed unnecessary extend to previous fetched ids

* Changed pack version to minor

* Deleted unnecessary arguments

* Kept mechansim of extned

* Fixed pre-commit

* Updated docker images

* Fixed argument position

* Passed is_paginating bool to check whether we are doing pagination or not

* Added is_paginating to if statement

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
sapirshuker pushed a commit that referenced this pull request Dec 21, 2023
* Fixing fetch unit tests

* Added unit tests, need to add documentation

* Added docstrings to unit tests

* Removed trace-id

* Removed Test from yml

* Added context data to commands

* Updated fromVerion in incident fields

* Fixed format errors

* Added README to scripts

* Added commands to README

* Added RNs

* Restore pack README

* Restore pack README

* Update pack-ignore

* Added docstrings to .py file

* Updated TPB, Layout

* Revert TPB

* Added fetch incidents to README.md

* Added more documentation

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_11_10.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Almost done with CR

* Increased timeout of TPB, added commands to TPB

* Added docs comments

* Fixed pre-commit errors

* Updated docker image in RNs

* Removed unecessary package

* Added to secrets ignore

* Fixed desriptions

* Fixed indentation

* Removed unnecessary tests

* Fixed conflcts

* Fixed incident fields names

* Increased timeout

* Increased timeout of task in test playbook

* Added Service Type to incident fields and mappers

* Added unit tests to scripts

* Improved documentation of unit tests

* Fixed unit tests imports

* Added named parameters to unit tests

* Added new lines to scripts unit tests

* Added handling if last fetch filter is empty

* Remove unnecessary import

* Removed incorrect incident field from mapper

* Reverted old RNs changes

* Update 1_11_11.md

* Reverted old RNs changes

* Removed updated docker image from RN

* Update 1_11_11.md

* Refactored lots of code, unit tests passed :)

* Updated docs wording

* Fixed pre-commit error

* Removed unnecessary extend to previous fetched ids

* Changed pack version to minor

* Deleted unnecessary arguments

* Kept mechansim of extned

* Fixed pre-commit

* Updated docker images

* Fixed argument position

* Passed is_paginating bool to check whether we are doing pagination or not

* Added is_paginating to if statement

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
6 participants