Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix for playbooks that uses deprecated sub-playbooks #31330

Merged
merged 40 commits into from Dec 11, 2023

Conversation

karinafishman
Copy link
Contributor

Contributing to Cortex XSOAR Content

Make sure to register your contribution by filling the contribution registration form

The Pull Request will be reviewed only after the contribution registration form is filled.

Status

  • [] In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: https://jira-dc.paloaltonetworks.com/browse/CIAC-9110
realtes: https://jira-dc.paloaltonetworks.com/browse/CIAC-8740

Description

Updating all the playbooks that use deprecated version of playbooks.
Detonate File - Generic
Ransomware Enrich and Contain
Detonate URL - Generic v1.5
Cortex XDR - Malware Investigation

Must have

  • Tests
  • Documentation

@karinafishman karinafishman changed the title Fix-sub-playbooks Fix for playbooks that use deprecated sub-playbooks Dec 6, 2023
@karinafishman karinafishman changed the title Fix for playbooks that use deprecated sub-playbooks Fix for playbooks that uses deprecated sub-playbooks Dec 6, 2023
Copy link
Contributor

@ssokolovich ssokolovich left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. General note for RNs - pls mention the new PB name.
  2. Pls add the updated PB images to the PR (as you changed some of the tasks' names).
  3. Just make sure that the outputs of the new playbooks are the same as the old ones so it won't brake up the PB logic + they will be set properly also as the parent PB output.

@karinafishman karinafishman self-assigned this Dec 10, 2023
@ShirleyDenkberg
Copy link
Contributor

@ssokolovich Doc review completed.

karinafishman and others added 15 commits December 11, 2023 14:53
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…ADME.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…ADME.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…ADME.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…c_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
…ADME.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
@karinafishman karinafishman merged commit 7a8b0be into master Dec 11, 2023
16 of 17 checks passed
@karinafishman karinafishman deleted the Fix-for-sub-playbooks branch December 11, 2023 15:09
sapirshuker pushed a commit that referenced this pull request Dec 21, 2023
* The sub-playbook of wildfire detonate file was changed to v2

* Replaced the old version of Cortex XDR - Retrieve File with the new version

* Crowdstrike detonate file was changed to a new version

* release notes update

* release notes update

* readme files updated

* release note

* fix for taskid and task field

* fixes for taskid and task not equal value

* release notes fix

* added new images for the playbooks

* Unique value fix

* RN updated

* fixes for PR

* RN fix

* fix

* fix

* RN fix

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>

* PN fix and unique fix

* fix for error in the build

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/ReleaseNotes/3_0_3.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CortexXDR/ReleaseNotes/6_0_8.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

---------

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
maimorag pushed a commit that referenced this pull request Dec 31, 2023
* The sub-playbook of wildfire detonate file was changed to v2

* Replaced the old version of Cortex XDR - Retrieve File with the new version

* Crowdstrike detonate file was changed to a new version

* release notes update

* release notes update

* readme files updated

* release note

* fix for taskid and task field

* fixes for taskid and task not equal value

* release notes fix

* added new images for the playbooks

* Unique value fix

* RN updated

* fixes for PR

* RN fix

* fix

* fix

* RN fix

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>

* PN fix and unique fix

* fix for error in the build

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/ReleaseNotes/3_0_3.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CortexXDR/ReleaseNotes/6_0_8.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/Playbooks/playbook-Detonate_URL_-_Generic_v1.5.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/CommonPlaybooks/ReleaseNotes/2_4_39.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/Core/Playbooks/playbook-Ransomware_Enrich_and_Contain_README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

---------

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
3 participants