Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CrowdStrike Falcon] Additional command to get IOA Rules for custom IOA rule triggered detections. #32124

Merged
merged 4 commits into from Jan 11, 2024

Conversation

content-bot
Copy link
Collaborator

Original External PR

external pull request

Contributor

@zeekforit

Contributing to Cortex XSOAR Content

Make sure to register your contribution by filling the contribution registration form

The Pull Request will be reviewed only after the contribution registration form is filled.

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

fixes: link to the issue

Description

Added a command to be able to get IOA Rules for custom IOA rule triggered detections. Allowing this command addition can enhance the detection details specifically for custom rules since we can't identify what rule was triggered using the usual Crowdstrike.Detections context.

Honestly, I can't have this tested on our environment but this is the same way how we do this using another SOAR platform. Our team will be really thankful if this feature has been added. I don't care if I don't get any credits for this or if this code was used. we just need a command that can get IOA Rules. Thank you.

Must have

  • Tests
  • Documentation

…IOA rule triggered detections. (#31992)

* [Crowdstrike Falcon] Added command to get IOARules

* Update CrowdStrikeFalcon.py

* Update CrowdStrikeFalcon.yml

* Update examples.txt

* Update README.md

* Update README.md

* Update README.md

* Update CrowdStrikeFalcon.yml

* Update CrowdStrikeFalcon.py

* Update CrowdStrikeFalcon.py

* Update pack_metadata.json

* Create 1_12_11.md

* Update CrowdStrikeFalcon.yml

* Update CrowdStrikeFalcon.py

cleaning up spacing

* Update CrowdStrikeFalcon.py

* Update CrowdStrikeFalcon.yml - changed rule_ids to required

* Update README.md

* Added 1 new command to get IOA Rules

* Delete Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_11.md

* Create 1_12_11.md

* Create 1_12_12.md

* Update pack_metadata.json

update version

* Update CrowdStrikeFalcon.py

updated function to a working http method

* Update CrowdStrikeFalcon.py

update json.dumps for get_ioarules function

* Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_12.md

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* Delete Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_11.md

* Create 1_12_11.md

* Delete 1_12_11.md

* Create 1_12_11.md

* Update CrowdStrikeFalcon.yml - update docker image

* Update CrowdStrikeFalcon.py - fixed flake8 issues

---------

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>
@content-bot content-bot added Contribution Thank you! Contributions are always welcome! Contribution Form Filled Whether contribution form filled or not. Community pending-contributor The PR is pending the response of its creator Xsoar Support Level Indicates that the contribution is for XSOAR supported pack Internal PR labels Jan 11, 2024
Copy link

github-actions bot commented Jan 11, 2024

Coverage

Coverage Report
FileStmtsMissCoverMissing
Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon
   CrowdStrikeFalcon.py274176871%355–356, 364, 408, 412, 422–427, 429–430, 438, 445, 456–463, 480, 602, 605, 633–642, 663, 738, 776–777, 779, 782–784, 832, 862, 921–922, 924, 929, 932–933, 948–950, 955, 958–959, 974–975, 977, 982, 985–986, 1014, 1016, 1021–1022, 1032, 1034, 1039–1040, 1150, 1267, 1269, 1296, 1313–1314, 1317–1322, 1324–1325, 1346, 1350, 1385, 1389, 1480, 1492–1493, 1495–1496, 1499, 1501, 1505–1506, 1542, 1551, 1556, 1585, 1587, 1615, 1619, 1651, 1653, 1780, 1785, 1796–1798, 1807–1811, 1824, 1827–1834, 1836, 1838, 1851, 1855, 1864, 1867–1868, 1871, 1880, 1883–1884, 1887, 1903, 1935, 1941–1944, 1947, 1951, 2001–2002, 2004, 2008, 2011, 2014, 2018–2019, 2022, 2037, 2193–2197, 2201, 2204, 2207–2208, 2211–2213, 2215, 2224, 2273–2274, 2276–2277, 2279–2281, 2314–2318, 2403, 2442–2445, 2448, 2451, 2453–2454, 2497–2499, 2502–2504, 2506, 2527, 2617, 2640–2641, 2698–2699, 2747, 2999–3000, 3185, 3289–3290, 3292, 3330–3335, 3385–3388, 3457, 3464, 3502, 3591, 3606, 3624, 3637, 3658–3661, 3674–3678, 3680–3681, 3683–3684, 3692–3700, 3707, 3751, 3757, 3785–3793, 3795–3796, 3804–3817, 3819–3821, 3823–3825, 3827–3829, 3831, 3833, 3835, 3847–3855, 3857–3867, 3875–3878, 3886–3889, 3925–3928, 3947–3952, 3954–3955, 3957–3964, 3974–3975, 3978, 4194–4196, 4203, 4225–4228, 4240, 4271–4274, 4290, 4322–4325, 4345–4346, 4356, 4369–4370, 4372, 4381–4384, 4425–4426, 4444–4447, 4492–4495, 4527, 4532–4533, 4558, 4562, 4574, 4576–4577, 4614–4615, 4621, 4642–4643, 4659–4660, 4674, 4688, 4691–4692, 4700, 4703–4704, 4715, 4719, 4758–4760, 4768–4770, 4772, 4799–4808, 4839, 4906–4909, 4912–4913, 4917–4920, 4923–4924, 4933–4934, 4936, 4938, 4940, 4942–4944, 4948, 4962–4966, 5031–5033, 5035, 5038, 5040, 5043, 5045–5047, 5049, 5051–5052, 5056–5059, 5064, 5066–5067, 5071–5072, 5074–5078, 5082, 5142, 5163–5164, 5243–5252, 5262, 5266, 5268, 5272, 5587, 5598, 5669, 5671, 5680, 5686, 5753, 5760, 5765, 5767, 5777, 5783, 5788, 5790–5791, 5793–5795, 5797, 5805, 5823, 5832, 5838, 5856, 5864, 5869, 5871–5872, 5874–5876, 5878, 5886, 5916, 5922, 5927, 5929, 5938, 5944, 5949, 5951–5952, 5954–5956, 5958, 5966, 6020, 6022–6023, 6025–6026, 6028, 6072–6073, 6075–6076, 6083, 6085, 6090, 6169, 6198–6199, 6207–6209, 6213, 6277, 6329, 6382, 6479, 6553–6554, 6556, 6558, 6575–6577, 6579–6584, 6586–6649, 6651–6662, 6669–6682, 6684–6685, 6687–6688, 6696–6697, 6699–6700, 6702–6703, 6705–6706, 6708–6712, 6716–6720, 6724–6725, 6727–6732, 6734–6737, 6739–6744, 6746–6789, 6791–6804, 6806, 6808–6809
TOTAL274176871% 

Tests Skipped Failures Errors Time
298 0 💤 0 ❌ 0 🔥 4.997s ⏱️

@yucohen yucohen merged commit 1f42c28 into master Jan 11, 2024
20 checks passed
@yucohen yucohen deleted the contrib/zeekforit_master branch January 11, 2024 15:55
dantavori pushed a commit that referenced this pull request Jan 14, 2024
…IOA rule triggered detections. (#32124)

* [CrowdStrike Falcon] Additional command to get IOA Rules for custom IOA rule triggered detections. (#31992)

* [Crowdstrike Falcon] Added command to get IOARules

* Create 1_12_11.md

* Create 1_12_12.md

* Update pack_metadata.json

* Update CrowdStrikeFalcon.py - fixed flake8 issues

---------

Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>

* fixes

* known words

---------

Co-authored-by: zeekforit <42007707+zeekforit@users.noreply.github.com>
Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>
Co-authored-by: yucohen <yucohen@paloaltonetworks.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Community Contribution Form Filled Whether contribution form filled or not. Contribution Thank you! Contributions are always welcome! docs-approved Internal PR pending-contributor The PR is pending the response of its creator Xsoar Support Level Indicates that the contribution is for XSOAR supported pack
Projects
None yet
3 participants