New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CrowdStrike Falcon] Additional command to get IOA Rules for custom IOA rule triggered detections. #32124
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…IOA rule triggered detections. (#31992) * [Crowdstrike Falcon] Added command to get IOARules * Update CrowdStrikeFalcon.py * Update CrowdStrikeFalcon.yml * Update examples.txt * Update README.md * Update README.md * Update README.md * Update CrowdStrikeFalcon.yml * Update CrowdStrikeFalcon.py * Update CrowdStrikeFalcon.py * Update pack_metadata.json * Create 1_12_11.md * Update CrowdStrikeFalcon.yml * Update CrowdStrikeFalcon.py cleaning up spacing * Update CrowdStrikeFalcon.py * Update CrowdStrikeFalcon.yml - changed rule_ids to required * Update README.md * Added 1 new command to get IOA Rules * Delete Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_11.md * Create 1_12_11.md * Create 1_12_12.md * Update pack_metadata.json update version * Update CrowdStrikeFalcon.py updated function to a working http method * Update CrowdStrikeFalcon.py update json.dumps for get_ioarules function * Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.yml Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * Update Packs/CrowdStrikeFalcon/Integrations/CrowdStrikeFalcon/CrowdStrikeFalcon.py Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * Update Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_12.md Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * Delete Packs/CrowdStrikeFalcon/ReleaseNotes/1_12_11.md * Create 1_12_11.md * Delete 1_12_11.md * Create 1_12_11.md * Update CrowdStrikeFalcon.yml - update docker image * Update CrowdStrikeFalcon.py - fixed flake8 issues --------- Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>
content-bot
added
Contribution
Thank you! Contributions are always welcome!
Contribution Form Filled
Whether contribution form filled or not.
Community
pending-contributor
The PR is pending the response of its creator
Xsoar Support Level
Indicates that the contribution is for XSOAR supported pack
Internal PR
labels
Jan 11, 2024
zeekforit
approved these changes
Jan 11, 2024
yucohen
approved these changes
Jan 11, 2024
zeekforit
approved these changes
Jan 11, 2024
5 tasks
dantavori
pushed a commit
that referenced
this pull request
Jan 14, 2024
…IOA rule triggered detections. (#32124) * [CrowdStrike Falcon] Additional command to get IOA Rules for custom IOA rule triggered detections. (#31992) * [Crowdstrike Falcon] Added command to get IOARules * Create 1_12_11.md * Create 1_12_12.md * Update pack_metadata.json * Update CrowdStrikeFalcon.py - fixed flake8 issues --------- Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> * fixes * known words --------- Co-authored-by: zeekforit <42007707+zeekforit@users.noreply.github.com> Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com> Co-authored-by: yucohen <yucohen@paloaltonetworks.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Community
Contribution Form Filled
Whether contribution form filled or not.
Contribution
Thank you! Contributions are always welcome!
docs-approved
Internal PR
pending-contributor
The PR is pending the response of its creator
Xsoar Support Level
Indicates that the contribution is for XSOAR supported pack
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Original External PR
external pull request
Contributor
@zeekforit
Contributing to Cortex XSOAR Content
Make sure to register your contribution by filling the contribution registration form
The Pull Request will be reviewed only after the contribution registration form is filled.
Status
Related Issues
fixes: link to the issue
Description
Added a command to be able to get IOA Rules for custom IOA rule triggered detections. Allowing this command addition can enhance the detection details specifically for custom rules since we can't identify what rule was triggered using the usual Crowdstrike.Detections context.
Honestly, I can't have this tested on our environment but this is the same way how we do this using another SOAR platform. Our team will be really thankful if this feature has been added. I don't care if I don't get any credits for this or if this code was used. we just need a command that can get IOA Rules. Thank you.
Must have