Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mandiant Threat Intelligence - Use Local Filtering #29724

Conversation

chrishultin
Copy link
Contributor

Contributing to Cortex XSOAR Content

Make sure to register your contribution by filling the contribution registration form

The Pull Request will be reviewed only after the contribution registration form is filled.

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: link to the issue

Description

Use local filtering in MATI integration in order to ensure that updates to indicator information are retrieved, even if they no longer fit the "search" criteria in use. (e.g. an indicator is created as "malicious", but is later marked as "benign". Previous versions would ignore the "benign" update)

Must have

  • Tests
  • Documentation

@content-bot content-bot added Contribution Thank you! Contributions are always welcome! External PR Partner Support Level Indicates that the contribution is for Partner supported pack labels Sep 19, 2023
@content-bot content-bot changed the base branch from master to contrib/chrishultin_mati_local_filter September 19, 2023 03:57
@content-bot
Copy link
Collaborator

Thank you for your contribution. Your generosity and caring are unrivaled! Make sure to register your contribution by filling the Contribution Registration form, so our content wizard @MichaelYochpaz will know the proposed changes are ready to be reviewed.
For your convenience, here is a link to the contributions SLAs document.

Copy link
Contributor

@MichaelYochpaz MichaelYochpaz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey, thank you for the contribution.
Looks pretty good overall. Left a few minor notes.

@MichaelYochpaz MichaelYochpaz added the pending-contributor The PR is pending the response of its creator label Sep 19, 2023
@chrishultin
Copy link
Contributor Author

Thanks for the feedback! It's all been addressed, please let me know if you've got any other comments or concerns.

@MichaelYochpaz MichaelYochpaz added the ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR. label Sep 20, 2023
@content-bot
Copy link
Collaborator

content-bot commented Sep 20, 2023

For the Reviewer: Successfully created a pipeline in Gitlab with url: https://code.pan.run/xsoar/content/-/pipelines/6425096

@MichaelYochpaz MichaelYochpaz added ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR. and removed pending-contributor The PR is pending the response of its creator ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR. labels Sep 21, 2023
@MichaelYochpaz MichaelYochpaz added ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR. and removed ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR. labels Sep 26, 2023
Copy link
Contributor

@MichaelYochpaz MichaelYochpaz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, good job :)

@MichaelYochpaz MichaelYochpaz merged commit 49925c9 into demisto:contrib/chrishultin_mati_local_filter Sep 26, 2023
33 of 40 checks passed
MichaelYochpaz added a commit that referenced this pull request Sep 27, 2023
* Mandiant Threat Intelligence - Use Local Filtering (#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
maimorag pushed a commit to LanskoyGIB/content that referenced this pull request Sep 28, 2023
* Mandiant Threat Intelligence - Use Local Filtering (demisto#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
wolyslager pushed a commit to wolyslager/content that referenced this pull request Sep 29, 2023
* Mandiant Threat Intelligence - Use Local Filtering (demisto#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
wolyslager pushed a commit to wolyslager/content that referenced this pull request Oct 2, 2023
* Mandiant Threat Intelligence - Use Local Filtering (demisto#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
xsoar-bot pushed a commit to xsoar-contrib/content that referenced this pull request Oct 5, 2023
* Mandiant Threat Intelligence - Use Local Filtering (demisto#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
tkatzir pushed a commit that referenced this pull request Dec 20, 2023
* Mandiant Threat Intelligence - Use Local Filtering (#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
sapirshuker pushed a commit that referenced this pull request Dec 21, 2023
* Mandiant Threat Intelligence - Use Local Filtering (#29724)

* Using local filtering to ensure that data doesn't become orphaned

* Bump docker version

* add missing periods

* release notes

* Addressing feedback

* Missing space

---------

Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>

* Update Docker version

---------

Co-authored-by: Christopher Hultin <chrishultin@google.com>
Co-authored-by: Michael Yochpaz <8832013+MichaelYochpaz@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contribution Form Filled Whether contribution form filled or not. Contribution Thank you! Contributions are always welcome! External PR Partner Support Level Indicates that the contribution is for Partner supported pack Partner Partner-Approved ready-for-instance-test In contribution PRs, this label will cause a trigger of a build with a modified pack from the PR.
Projects
None yet
4 participants