Skip to main content

SOC Framework Pack Manager

This Integration is part of the SOC Framework Pack Manager Pack.#

Supported versions

Available on Cortex XSIAM.

SOC Framework Pack Manager โ€” internal HTTP layer used by the SOCFWPackManager script to install SOC Framework content packs as system content. End users do not invoke this integration directly.

Architecture#

This integration is paired with the SOCFWPackManager script in the same pack. The script reads the SOC Framework pack catalog, sequences pack installs, configures integration instances and jobs, and synchronizes the value_tags lookup. Because Cortex XSIAM scripts can call demisto.executeCommand, all orchestration lives there.

This integration stores the tenant URL, credentials, TLS verification setting, and the pack catalog location. It exposes two commands: socfw-install-pack, which downloads a pack ZIP and installs it on the tenant, and socfw-catalog-url-get, which returns the configured catalog location so the script can read it. Cortex XSIAM integrations cannot call demisto.executeCommand, so the integration deliberately performs only the work that needs raw HTTP.

End users run !SOCFWPackManager action=apply pack_id=... from the XSIAM Playground. The script invokes socfw-install-pack on this integration internally.

Configure SOC Framework Pack Manager on Cortex XSIAM#

  1. Navigate to Settings > Configurations > API Keys and create a Standard API key.
  2. Copy the Key, the Key ID, and click Copy URL to capture the tenant Server URL.
  3. Navigate to Settings > Configurations > Integrations.
  4. Search for SOC Framework Pack Manager.
  5. Click Add instance to create and configure a new integration instance.
ParameterDescriptionRequired
Server URLThe tenant API URL or tenant URL. The integration adds the api- prefix when it is missing.True
API Key IDThe numeric ID of the Standard API key, shown in the API Keys table.True
API KeyThe secret value of the Standard API key.True
Trust any certificate (not secure)Whether to disable TLS certificate validation. Off by default.False
Use system proxy settingsWhether to route HTTP traffic through the system proxy. Off by default.False
Pack catalog URLThe location of the SOC Framework pack_catalog.json. Override to point at a fork or branch. Leave empty to use the SOC Framework repository default.False
  1. Click Test to validate the URL and credentials, then Done.

Commands#

You can execute these commands from the Cortex XSIAM CLI as part of an automation or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

socfw-install-pack#


Downloads a SOC Framework pack ZIP from the supplied URL and installs it on the tenant. After the upload the command reads the installed pack version back from the tenant and compares it against the version in the ZIP filename; if they disagree the command fails rather than reporting success, so an upload that left the tenant on its previous version is not reported as an upgrade.

Note that this check confirms only that the version record changed. A tenant registers a pack's version separately from its content, so a pack can carry the expected version while none of its scripts, lists, playbooks, or rules were installed. Confirming an install means reading the content items back off the tenant, rather than reading the version. Called by the SOCFWPackManager script โ€” do not invoke directly.

Base Command#

socfw-install-pack

Input#

Argument NameDescriptionRequired
urlURL of the pack ZIP to install (typically a GitHub release asset).Required
filenameAsset filename, including the .zip extension. Derived from the URL when omitted.Optional
use_sdkWhether to install through the demisto-sdk path, which builds the content graph and installs the pack's content items. Setting false uses a direct ZIP upload that registers the pack version WITHOUT installing its content -- it is not a faster install, it is a different and almost always wrong one. Possible values are: true, false. Default is true.Optional

Context Output#

PathTypeDescription
SOCFramework.PackInstall.filenameStringInstalled pack filename.
SOCFramework.PackInstall.urlStringSource URL the pack was downloaded from.
SOCFramework.PackInstall.statusStringInstall status (success on completion).
SOCFramework.PackInstall.responseUnknownRaw response from the demisto-sdk upload step.

Command example#

!socfw-install-pack url=https://github.com/Palo-Cortex/secops-framework/releases/download/soc-optimization-unified-v3.6.3/soc-optimization-unified-v3.6.3.zip

Context Example#

{
"SOCFramework": {
"PackInstall": {
"filename": "soc-optimization-unified-v3.6.3.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-optimization-unified-v3.6.3/soc-optimization-unified-v3.6.3.zip",
"status": "success",
"response": {
"success": true,
"message": "Uploaded /home/demisto/Packs/soc-optimization-unified-v3.6.3"
}
}
}
}

Human Readable Output#

Pack soc-optimization-unified-v3.6.3.zip installed successfully (verified).

socfw-catalog-url-get#


Returns the SOC Framework pack catalog URL configured on this instance. Called by the SOCFWPackManager script so the catalog location is set once on the instance instead of passed as an argument on every run.

Base Command#

socfw-catalog-url-get

Input#

Argument NameDescriptionRequired

Context Output#

PathTypeDescription
SOCFramework.PackManager.CatalogURLStringThe pack catalog URL configured on this instance, or the SOC Framework default when the field is empty.