Cortex XSOAR Content Release Notes for version 21.7.0 (6375665)
#
Published on 06 July 2021#
Breaking ChangesThe SearchIndicatorRelationships script in the following pack includes a breaking change:
#
New: Content Management Pack v1.0.0#
Incident Fields- Branch Name
- Configuration File Path
- Configuration File Source
- Custom Packs Installed
- Custom Packs Source
- Jobs Created
- Lists Created
- Marketplace Packs Installed
#
Incident TypesConfiguration Setup
#
Layoutsconfiguration setup (Available from Cortex XSOAR 6.0.0)
#
Playbooks#
Configuration SetupPlaybook for configuration incident type.
#
Scripts#
ConfigurationSetupConfiguration loader for the Content Management pack.
#
CustomPackInstallerCustom packs installer for the Content Management pack.
#
JobCreatorJob creator for the Content Management pack.
#
ListCreatorList creator for the Content Management pack.
#
MarketplacePackInstallerMarketplace packs installer for the Content Management pack.
#
New: Google Maps Pack v1.0.0#
Integrations#
Google MapsEnables you to use the Google Maps API to retrieve the coordinates of a given physical address.
#
New: PingCastle Pack v1.0.0 (Partner Supported)#
Classifiers#
PingCastle-Report-Classifier#
PingCastle-Report-Mapper#
PingCastle#
Incident FieldsPingCastle XML Report
#
Incident TypesPingCastle
#
Integrations#
PingCastleThis integration runs a server that listens for PingCastle XML reports.
#
Playbooks#
SX - PC - PingCastle ReportThis playbook runs when a new report is sent from PingCastle. It then parses it to a JSON and renders a table. It also puts a download link to the XML report in the War Room.
#
New: Powershell Remoting Pack v1.0.0#
Integrations#
PowerShell Remoting (Beta)A comprehensive built-in remoting subsystem that is a part of Microsoft's native Windows management framework (WMF) and Windows remote management (WinRM). This feature allows you to handle most remoting tasks in any configuration you might encounter by creating a remote PowerShell session to Windows hosts and executing commands in the created session. The integration includes out-of-the-box commands which supports agentless forensics for remote hosts.
#
New: Redact/Defang Indicators (URLs, IPs, Email) Pack v1.0.0 (Community Contributed)#
Scripts#
redactindicatorEnables you to defang/redact any kind of indicator (IPv4, url, domain, and email). Optionally, you can define a "searchkey" which does not need to be case sensitive, which will be replaced as \<REDACTED>.
#
New: Strip Accent Marks From String Pack v1.0.0 (Community Contributed)#
Scripts#
StripAccentMarksFromStringStrips accent marks (diacritics) from a given string. For example: "Niรฑo ืฉืึธืืึนื Montrรฉal ุงููุณููููุงู ู ุนูููููููู ูโ" Will return: "Nino ืฉืืื Montreal ุงูุณูุงู ุนูููู "
#
New: UBIRCH Pack v1.0.0 (Partner Supported)#
Incident Types- UBIRCH Authenticity
- UBIRCH Integrity
- UBIRCH Privacy
- UBIRCH Sequence
#
Integrations#
UBIRCHThe UBIRCH solution can be seen as an external data certification provider, as a data notary service, giving data receivers the capability to verify data they receive with regard to its authenticity and integrity and correctness of sequence.
#
New: Windows Forensics Pack v1.0.0#
Incident TypesForensic Acquisition And Analysis
#
LayoutsForensic Acquisition And Analysis (Available from Cortex XSOAR 6.0.0).
#
Playbooks#
Acquire And Analyze Host ForensicsEnables gathering forensic data from a host and analyzing the acquired data by using the relevant forensics automations.
#
Forensics Tools AnalysisEnables the user to analyze forensic evidence acquired from a host, such as registry files and PCAP files.
#
PS-Remote Acquire Host ForensicsEnables the user to gather multiple forensic data from a Windows endpoint including network traffic, MFT (Master File Table), and registry export by using the PS Remote automation which enables connecting to a Windows host without the need to install any 3rd-party tools using just native Windows management tools.
#
PS Remote Get File Sample From PathLeverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire a file as forensic evidence for further analysis.
#
PS-Remote Get MFTLeverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the MFT (Master File Table) as forensic evidence for further analysis.
#
PS-Remote Get Network TrafficLeverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host. It then connects to the Netsh tool to create an ETL file which is the equivalent of a Wireshark PCAP file by using the PS-Remote integration. After receiving the resultant ETL, XSOAR will be able to convert the ETL to a PCAP file to be parsed and enriched later. Review the Microsoft documentation for how to use ETL filters (https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj129382(v=ws.11)#using-filters-to-limit-etl-trace-file-details).
#
PS-Remote Get RegistryLeverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the registry as forensic evidence for further analysis. The capture can be for the entire registry or for a specific hive or path.
#
Registry Parse Data AnalysisLeverages the RegistryParse automation to perform registry analysis and extract forensic artifacts. The automation includes common registry objects to extract which are useful for analyzing a registry, or a user provided registry path to parse.
#
Scripts#
Etl2PcapReceives an ETL file and converts it to a PCAP file.
#
RegistryParseExtracts critical forensics data from a registry file.
#
New: XSOAR Content Update Notifications Pack v1.0.0 (Community Contributed)#
Incident Fields- Content Notification Email
- Content Notification Slack Channel
- Content Notification Slack Username
- Content Pack Selection
- Content Updates Available
#
Incident TypesContent Update Check
#
LayoutsContent Update Check Layout (Available from Cortex XSOAR 6.0.0).
#
Playbooks#
Check For Content InstallationThis playbook checks for content updates.
#
Content Update CheckThis playbook checks to see if there are any content updates available for installed packs and notifies users via email or Slack.
#
Scripts#
FormatContentDataThis script formats the value given input from a JSON list into a table.
#
ListInstalledContentPacksThis script shows all installed content packs and whether or not they have an update.
#
ANY.RUN Pack v1.0.4#
Integrations#
ANY.RUNUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
APIVoid Pack v1.0.3#
Integrations#
APIVoidUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ARIAPacketIntelligence Pack v2.0.4 (Partner Supported)#
Integrations#
ARIA Packet Intelligence- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Abuse.ch SSL Blacklist Feed Pack v1.1.4#
Integrations#
abuse.ch SSL Blacklist FeedImproved implementation of the timestamp conversion to ISO format.
#
Acalvio ShadowPlex Pack v1.0.2 (Partner Supported)#
Integrations#
Acalvio ShadowPlexUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Accessdata Pack v1.0.2 (Partner Supported)#
Integrations#
AccessdataUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Agari Phishing Defense Pack v1.0.3 (Partner Supported)#
Integrations#
Agari Phishing DefenseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Alexa Rank Indicator Pack v1.1.4#
Integrations#
Alexa Rank IndicatorFixed an issue where the default source reliability was not set properly for integration instances configured prior to pack version 1.1.2.
#
AlienVault Feed Pack v1.1.4#
Integrations#
AlienVault Reputation FeedImproved implementation of the timestamp conversion to ISO format.
#
AlienVault USM Anywhere Pack v1.0.4#
Integrations#
AlienVault USM AnywhereUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
AlphaVantage Pack v1.0.2 (Community Contributed)#
Integrations#
AlphaVantageUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Analyst1 Pack v1.0.10 (Partner Supported)#
Integrations#
Analyst1Updated the Docker image to: demisto/python3:3.9.5.21272.
#
illuminate (Deprecated)Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Anomali Enterprise Pack v1.0.4#
Integrations#
Anomali MatchUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Ansible Powered Integrations Pack v1.0.2 (Community Contributed)#
Integrations#
Microsoft WindowsUpdated the Docker image to: demisto/ansible-runner:1.0.0.21453.
#
Ansible Tower Pack v1.0.4#
Integrations#
Ansible TowerUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ApiModules Pack v2.2.1#
Scripts#
CSVFeedApiModuleImproved implementation of the timestamp conversion to ISO format.
#
Atlassian IAM Pack v1.0.3#
Integrations#
Atlassian IAMUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
AttackIQ Platform Pack v1.0.4#
Integrations#
AttackIQ PlatformUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Azure Feed Pack v1.0.6#
Integrations#
Azure FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Bambenek Consulting Feed Pack v1.1.4#
Integrations#
Bambenek Consulting FeedImproved implementation of the timestamp conversion to ISO format.
#
Base Pack v1.12.18#
Scripts#
CreateIndicatorRelationshipFixed an issue where creating new relationships was not working for indicators that were already in the database.
#
DBotTrainClusteringFixed an issue where the script caused the associated widget to not work properly.
#
CommonServerPython- Improved the default processing logic of integration parameters when the None value is set.
- Added the execute_command wrapper function.
- Maintenance and stability enhancements.
#
SearchIndicatorRelationships- Breaking Change: Removed the STIX prefix from the option list names in the entity_types argument.
- Added the following entity types to the option list names in the entity_types argument:
- Campaign
- Course of Action
- Intrusion Set
- Infrastructure
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Bastille Networks Pack v1.0.4 (Partner Supported)#
Integrations#
Bastille NetworksUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
BeyondTrust Password Safe Pack v1.0.5#
Integrations#
BeyondTrust Password SafeUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
BitSight Pack v1.0.5 (Partner Supported)#
Integrations#
BitSight for Security Performance ManagementUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
BitcoinAbuse Feed Pack v1.0.7#
Integrations#
BitcoinAbuse FeedImproved implementation of the timestamp conversion to ISO format.
#
Blueliv ThreatCompass Pack v1.0.3 (Community Contributed)#
Integrations#
Blueliv ThreatCompassUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Blueliv ThreatContext Pack v1.0.2 (Community Contributed)#
Integrations#
Blueliv ThreatContextUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Bmc Helix Remedyforce Pack v1.0.6#
Scripts#
BMCHelixRemedyforceCreateIncidentUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
BMCHelixRemedyforceCreateServiceRequestUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Bonusly Pack v1.0.3 (Community Contributed)#
Integrations#
BonuslyUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CSV Feed Pack v1.1.3#
Integrations#
CSV FeedImproved implementation of the timestamp conversion to ISO format.
#
CVE Search Pack v1.0.6#
Playbooks#
CVE Enrichment - Generic- Deprecated. Use CVE Enrichment - Generic v2 instead.
- Maintenance and stability enhancements
#
Carbon Black Cloud Enterprise EDR Pack v1.1.5#
Integrations#
VMware Carbon Black Enterprise EDRUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Carbon Black Endpoint Standard Pack v3.0.2#
Integrations#
Carbon Black Live Response CloudMaintenance and stability enhancements.
#
Carbon Black Enterprise Protection Pack v1.0.7#
Integrations#
VMware Carbon Black App Control v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Carbon Black Enterprise Response Pack v2.0.0#
Classifiers#
New: Carbon Black EDR ClassifierClassifies Carbon Black EDR's alerts (Available from Cortex XSOAR 6.0.0).
#
Incident Fields- Carbon Black EDR Watchlist Id
- Carbon Black EDR Watchlist Name
- Carbon Black EDR IOC Value
- Carbon Black EDR Segment ID
#
Incident Types#
Integrations#
New: VMware Carbon Black EDR v2VMware Carbon Black EDR (formerly known as Carbon Black Response). (Available from Cortex XSOAR 6.0.0).
#
LayoutsNew: Carbon Black EDR Incidents - Carbon Black EDR Incident's standard layout. (Available from Cortex XSOAR 6.0.0).
#
Mappers#
New: Carbon Black EDR MapperMaps Carbon Black EDR's alert fields. (Available from Cortex XSOAR 6.0.0).
#
Playbooks#
New: Carbon Black EDR - Enrich ProcessDefault playbook for Carbon Black EDR incidents. (Available from Cortex XSOAR 6.0.0).
#
Chronicle Pack v2.0.3 (Partner Supported)#
Classifiers#
New: Chronicle - Incoming MapperMaps incoming Chronicle incident fields. (Available from Cortex XSOAR 6.0.0).
#
New: Google Chronicle Backstory(Available from Cortex XSOAR 5.0.0).
#
Incident Fields#
Integrations#
Chronicle- Added a simple_backoff_rules dictionary to track retry attempts for 429 and 500 errors and if 400 or 404 error occurs for detection of any rule.
- Added 2 commands:
- gcb-list-detections
- gcb-list-rules
- Updated the Docker image to: demisto/googleapi-python3:1.0.0.21730.
#
Scripts#
ChronicleAssetEventsForHostnameWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleAssetEventsForIPWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleAssetEventsForMACWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleAssetEventsForProductIDWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleAssetIdentifierScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleDBotScoreWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleDomainIntelligenceSourcesWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleIsolatedHostnameWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleIsolatedIPWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChronicleListDeviceEventsByEventTypeWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ChroniclePotentiallyBlockedIPWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ConvertDomainToURLsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExtractDomainFromIOCDomainMatchResUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cisco ISE Pack v1.0.4#
Integrations#
Cisco ISEUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cisco Threat Grid Pack v1.2.5#
Integrations#
Cisco Secure Malware Analytics FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cisco Umbrella Enforcement Pack v1.0.2#
Integrations#
Cisco Umbrella EnforcementUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CiscoFirepower Pack v1.0.6#
Integrations#
Cisco FirepowerUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Claroty Pack v1.0.10 (Partner Supported)#
Integrations#
ClarotyUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cofense Feed Pack v1.0.9#
Integrations#
Cofense FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cognni Pack v1.0.2 (Partner Supported)#
Integrations#
CognniUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Common Playbooks Pack v1.9.9#
Playbooks#
New: Retrieve File from Endpoint - Generic V3Retrieves a file sample from an endpoint using the following sub-playbooks:
- Get File Sample From Path - Generic v3.
- Get File Sample By Hash - Generic v3. (Available from Cortex XSOAR 6.0.0).
#
New: Get File Sample From Path - Generic V3Returns a file sample correlating to a path into the War Room using the following sub-playbooks:
- Get File Sample From Path - Powershell Remoting.
- Get File Sample From Path - VMware Carbon Black EDR (Live Response API). (Available from Cortex XSOAR 6.0.0).
#
CVE Enrichment - Generic v2Maintenance and stability enhancements
#
Common Scripts Pack v1.3.66#
Scripts#
AssignAnalystToIncidentChanged email comparison from case-sensitive to case-insensitive.
#
ShowOnMapShow addresses (or location descriptions, such as 'Paloalto Networks Tel Aviv Office') by calling the GoogleMaps integration. Make sure to have a configured instance of GoogleMaps to utilize this functionality.
#
Base64Decode- Fixed an issue where the script failed to decode special characters in Windows-1252 encoding.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
ExtractIndicatorsFromWordFileUpdated the Docker image to: demisto/office-utils:2.0.0.21435.
#
SetGridFieldUpdated the Docker image to: demisto/pandas:1.0.0.21648.
#
GetDuplicatesMlv2- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/machine-learning:1.0.0.22015.
#
WordTokenizerUpdated the Docker image to: demisto/nltk:2.0.0.19143.
#
Common Types Pack v3.1.3#
Incident Fields- Process Name
- Process Path
- Resource Type
- Associated the following fields with the CarbonBlackEDR incident type:
- Username
- Event Descriptions
- Device Id
#
Confluera Pack v1.0.2 (Partner Supported)#
Integrations#
ConflueraUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CounterCraft Deception Director Pack v1.0.2 (Partner Supported)#
Integrations#
CounterCraft Deception DirectorUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CrowdStrike FalconX Pack v1.1.3#
Integrations#
CrowdStrike Falcon XUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CrowdStrike Malquery Pack v1.0.4#
Integrations#
CrowdStrike MalqueryUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cryptocurrency Pack v1.1.5#
Integrations#
CryptocurrencyUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Scripts#
CryptoCurrenciesFormatUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
CyberArk Pack v1.0.4#
Integrations#
CyberArk PASUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Cyberint Pack v1.0.8 (Partner Supported)#
Integrations#
CyberintUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
DeHashed Pack v1.1.2#
Integrations#
DeHashedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Demisto REST API Pack v1.1.4#
Scripts#
DemistoUploadFileV2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Deprecated Content Pack v1.6.12#
Integrations#
Palo Alto Networks MineMeld (Deprecated)Updated the Docker image to: demisto/python:2.7.18.20958.
#
Azure Security Center (Deprecated)Updated the Docker image to: demisto/python:2.7.18.20958.
#
Azure Compute (Deprecated)Updated the Docker image to: demisto/python:2.7.18.20958.
#
Cymon (Deprecated)Updated the Docker image to: demisto/python:2.7.18.20958.
#
Scripts#
LCMPathFinderScanHostUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IPExtractUpdated the Docker image to: demisto/python:2.7.18.20958.
#
BinaryReputationPyUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AwsStartInstanceUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaGetUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMDetectedEntitiesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaActivateUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ExchangeDeleteIDsFromContextUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWFindEventsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPORetrieveCurrentDATVersionUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMHostsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraSettingsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusShowEditorTemplatesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPTaskStatusUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraTriageUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CBFindHashUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AwsCreateVolumeSnapshotUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraCreateIssueUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMIndicatorsForEntityUpdated the Docker image to: demisto/python:2.7.18.20958.
#
MD5ExtractUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CSActorsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ParseEmailHeadersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPORepositoryComplianceCheckUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraClassifierUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADIsUserMemberUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBLockoutsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetEmailForUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetAllUsersEmailUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsGmailSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBNotableUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CheckWhitelistUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ProofpointDecodeURLUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ExchangeSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraGetDetetctionsByIdUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ElasticsearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMResolveHostUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWObservationDetailsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaCreateUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWEventPcapInfoUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADListUsersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADExpirePasswordUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetUserGroupsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CheckFilesWildfirePyUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaUpdateUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AwsCreateImageUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraSummaryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SplunkSearchJsonPyUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CheckIPsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusScanDetailsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusListScansUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CheckURLsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IsContextSetUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetComputerGroupsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SetSeverityByScoreUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CYFileRepUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ConferSetSeverityUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADUserLogonInfoUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusHostDetailsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IngestCSVUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetGroupUsersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SlackAskUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraIssueQueryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetComputerUpdated the Docker image to: demisto/python:2.7.18.20958.
#
URLExtractUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPShowAccessRulebaseUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IncidentSetUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPCreateBackupUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsListUsersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IncidentToContextUpdated the Docker image to: demisto/python:2.7.18.20958.
#
QrFullSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMAcknowledgeHostUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AwsStopInstanceUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBTriggeredRulesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMDetectedIndicatorsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
RunSqlQueryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusCreateScanUpdated the Docker image to: demisto/python:2.7.18.20958.
#
QrOffensesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADListUsersExUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPOUpdateEndpointsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusGetReportUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SlackSendUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ClassifierNotifyAdminUpdated the Docker image to: demisto/python:2.7.18.20958.
#
QrSearchesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SendEmailUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraGetHostByIdUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWEventsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBInfoUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWObservationsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetEmailForAllUsersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWSensorsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SNListTicketsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SNUpdateTicketUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsGetUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NetwitnessSAUpdateIncidentUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LCMSetHostCommentUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPOUpdateRepositoryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
vmray_getResultsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraGetIssueUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraHostsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
QrGetSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AdSearchUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPShowBackupStatusUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusLaunchScanUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsGmailGetMailUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWEventDetailsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
XBTimelineUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VMRayUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraIssueAddLinkUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetGroupMembersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
WhoisLookupUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaDeactivateUserUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADSetNewPasswordUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsRevokeUserRoleUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPDeleteRuleUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SandboxDetonateFileUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AwsRunInstanceUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaGetGroupsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CommonIntegrationPythonUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraIssueUploadFileUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPODetermineRepositoryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
LocateAttachmentUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetCommonGroupsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GetContextValueUpdated the Docker image to: demisto/python:2.7.18.20958.
#
PWObservationPcapInfoUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPBlockIPUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPShowHostsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPORepoListUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CSHuntByIOCUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADListComputersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetGroupComputersUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraDetectionsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VirustotalIsMaliciousUpdated the Docker image to: demisto/python:2.7.18.20958.
#
DocumentationAutomationUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraSensorsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
JiraIssueAddCommentUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CSIndicatorsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
VectraHealthUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SNOpenTicketUpdated the Docker image to: demisto/python:2.7.18.20958.
#
AggregateIOCsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CPSetRuleUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ConferIncidentDetailsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ExtractDomainFromURLUpdated the Docker image to: demisto/python:2.7.18.20958.
#
SlackMirrorUpdated the Docker image to: demisto/python:2.7.18.20958.
#
IPInfoQueryUpdated the Docker image to: demisto/python:2.7.18.20958.
#
NessusScanStatusUpdated the Docker image to: demisto/python:2.7.18.20958.
#
ADGetUsersByEmailUpdated the Docker image to: demisto/python:2.7.18.20958.
#
OktaSetPasswordUpdated the Docker image to: demisto/python:2.7.18.20958.
#
QrGetSearchResultsUpdated the Docker image to: demisto/python:2.7.18.20958.
#
EPOCheckLatestDATUpdated the Docker image to: demisto/python:2.7.18.20958.
#
CSCountDevicesForIOCUpdated the Docker image to: demisto/python:2.7.18.20958.
#
GoogleappsGetUserRolesUpdated the Docker image to: demisto/python:2.7.18.20958.
#
DevSecOps Pack v1.0.1 (Community Contributed)#
Integrations#
GitLab- Added the following commands:
- gitlab-pipelines-schedules-list
- gitlab-pipelines-list
- gitlab-jobs-list
- gitlab-artifact-get
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Digital Guardian Pack v1.0.4 (Partner Supported)#
Integrations#
Digital GuardianUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Druva Ransomware Response Pack v1.0.2 (Partner Supported)#
Integrations#
Druva Ransomware ResponseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Elasticsearch Monitoring Pack v1.0.1#
Dashboards#
Elasticsearch MonitoringFixed an issue where the Elasticsearch Active Shards widget was displaying incorrectly in red.
#
EmailRepIO Pack v1.0.3#
Integrations#
EmailRep.ioUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Endace Pack v1.1.5 (Partner Supported)#
Integrations#
EndaceUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Exabeam Pack v2.1.2#
Integrations#
ExabeamUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Expanse (Deprecated) Pack v1.2.2 (Partner Supported)#
Integrations#
Expanse (Deprecated)Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Scripts#
ExpanseParseRawIncidentUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Expanse v2 Pack v1.7.0#
Incident Fields- Expanse Activity Status
- Expanse Asset
- Expanse Asset Organization Unit
- Expanse Asset Owner
- Expanse Assignee
- Expanse Business Units
- Expanse Category
- Expanse Certificate
- Expanse Cloud Management Status
- Expanse Created
- Expanse Domain
- Expanse Geolocation
- Expanse IP
- Expanse Initial Evidence
- Expanse Issue ID
- Expanse Issue Type
- Expanse Latest Evidence
- Expanse ML Features
- Expanse Modified
- Expanse Port
- Expanse Priority
- Expanse Progress Status
- Expanse Protocol
- Expanse Provider
- Expanse Region
- Expanse Service
- Expanse Shadow IT
- Expanse Tags
#
Incident Types#
Integrations#
Expanse v2- Updated User Agent String.
- Updated expanse-get-iprange include parameter.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Expanse Expander FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
LayoutsExpanse Issue Layout - Fixed section locations.
#
Mappers#
ExpanseV2 - Incoming Mapper- Added Xpanse Issue - Generic to the mapper.
- Mapped Alert Type ID with the issue type ID.
#
Playbooks#
New: Xpanse Incident Handling - GenericA generic playbook for handling Xpanse issues. The logic behind this playbook is to work with an internal exclusions list which will help the analyst to get to a decision or, if configured, close incidents automatically. The phases of this playbook are: 1) Check if assets (IP, Domain, or Certificate) associated with the issue are excluded in the exclusions list and optionally, close the incident automatically. 2) Optionally, enrich indicators and calculate the severity of the issue, using sub-playbooks. 3) Optionally, allow the analyst to add associated assets (IP, Domain, or Certificate) to the exclusions list. 4) Tag associated assets. 5) Update the status of the issue.
#
Expanse Load-Create List- Added the ListValues playbook input.
- Changed the internal task to use the above value.
#
Handle Expanse Incident- Added "{}" as an input for the "Expanse Load-Create List" sub-playbook.
- Corrected spelling errors.
- Add "else" statement to task 169.
- Updated to include the Expanse VM Enrich sub-playbook.
- Updated to include the Expanse Unmanaged Cloud sub-playbook.
#
Expanse AttributionUpdated to include the ServiceNow CMDB Search sub-playbook and a new script for result aggregation.
#
New: Expanse Unmanaged CloudSub-playbook for bringing rogue cloud accounts under management. (Available from Cortex XSOAR 6.0.0). Helps identify owners of unknown cloud assets so they can be brought under management in Prisma Cloud.
#
Expanse VM EnrichUpdated to include asset vulnerability results as evidence.
#
Scripts#
ExpanseAggregateAttributionDeviceUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpanseAggregateAttributionIPUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpanseAggregateAttributionUserUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpanseEnrichAttributionUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpanseEvidenceDynamicSectionUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpansePrintSuggestionsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ExpanseRefreshIssueAssetsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
MatchIPinCIDRIndicatorsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
New: ExpanseAggregateAttributionCI- Aggregate entries from the ServiceNow CMDB into AttributionCI (Available from Cortex XSOAR 6.0.0).
- Updated the Docker image to: demisto/python3:3.9.5.20958.
#
F5 Silverline Pack v1.0.1#
Integrations#
F5 SilverlineMaintenance and stability enhancements.
#
F5 firewall Pack v1.2.2#
Integrations#
F5 Application Security Manager (WAF)Updated the Docker image to: demisto/python3:3.9.5.21272.
#
FireEye Central Management Pack v1.1.0#
Integrations#
FireEye Central Management- Internal code improvements.
- Added the timeout argument to the fireeye-cm-get-alert-details command.
- Fixed an issue where the fetch-incidents command was not fetching new alerts in some cases.
#
FireEye Email Security (EX) Pack v2.0.0#
Classifiers#
New: FireEye Email Security - ClassifierClassifies FireEye Email Security Alerts.
#
Integrations#
New: FireEye Email SecurityAdded the FireEye Email Security integration.
#
FireEye Feed Pack v2.0.2#
Integrations#
FireEye FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
FireEye Helix Pack v1.0.4#
Integrations#
FireEye HelixUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
FortiManager Pack v1.0.2#
Integrations#
FortiManagerUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Gamma Pack v1.0.2 (Partner Supported)#
Integrations#
GammaUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Genians Pack v1.0.5 (Partner Supported)#
Integrations#
GeniansUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Get License ID Pack v1.0.3#
Scripts#
GetLicenseIDUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetServerURL Pack v1.0.2#
Scripts#
GetServerURLUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GitHub Pack v1.2.11#
Integrations#
GitHubAdded the Github-list-issue-events command.
#
Google Key Management Service Pack v1.0.3#
Integrations#
Google Key Management ServiceUpdated the Docker image to: demisto/google-kms:1.0.0.21967.
#
Google Safe Browsing Pack v2.0.3#
Integrations#
Google Safe Browsing v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
GreatHorn Pack v1.0.2 (Partner Supported)#
Integrations#
GreatHornUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
HashiCorp Vault Pack v1.0.1#
Integrations#
HashiCorp Vault- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/hashicorp:1.0.0.19034.
#
Hello World IAM Pack v1.0.5#
Integrations#
Hello World IAMUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
HelloWorld Pack v1.2.5 (Community Contributed)#
Integrations#
HelloWorld FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
HelloWorldUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
HostIo Pack v1.0.2#
Integrations#
HostIoUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Humio Pack v1.0.7 (Partner Supported)#
Integrations#
HumioUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
IBM QRadar Pack v2.0.16#
Integrations#
IBM QRadar v2- Set a predefined amount of incident samples to be generated by the long-running-execution instance.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
IBM QRadar v3- Set a predefined amount of incident samples to be generated by the long-running-execution instance.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
IBM QRadar (Deprecated)- Deprecated. Use the IBM QRadar v2 or IBM QRadar v3 integration instead.
- Maintenance and stability enhancements.
#
Playbooks#
QRadarFullSearchMaintenance and stability enhancements.
#
Imperva WAF Pack v1.0.3#
Integrations#
Imperva WAFUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Infoblox Pack v1.0.5#
Integrations#
InfobloxUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Integrations & Incidents Health Check Pack v1.1.20#
Scripts#
CopyLinkedAnalystNotesUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetFailedTasksUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
IncidentsCheck-NumberofIncidentsNoOwnerUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
IncidentsCheck-NumberofIncidentsWithErrorsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
IncidentsCheck-NumberofTotalEntriesErrorsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Intel471 Feed Pack v2.0.1 (Partner Supported)#
Integrations#
Intel471 Actors FeedCustom user agent added.
#
Intel471 Malware Feed (Deprecated)Custom user agent added.
#
Intel471 Malware Indicator FeedCustom user agent added.
#
IronNet Pack v1.1.6 (Partner Supported)#
Integrations#
IronDefenseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Jask Pack v1.1.0#
Integrations#
Jask (Deprecated)Deprecated. Use the Sumo Logic Cloud SIEM integration from the Sumo Logic Cloud SIEM pack.
#
JsonWhoIs Pack v1.0.5#
Integrations#
JsonWhoIsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Kaspersky Security Center Pack v1.0.2#
Integrations#
Kaspersky Security Center (Beta)Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Kenna Pack v1.1.2#
Integrations#
Kenna v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Lockpath Keylight Pack v1.1.2#
Integrations#
Lockpath KeyLight v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Scripts#
KeylightCreateIssueUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
LogPoint SIEM Integration Pack v1.2.1 (Partner Supported)#
Integrations#
LogPoint SIEM IntegrationUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Logz.io Pack v1.1.6 (Partner Supported)#
Integrations#
Logz.ioUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Machine Learning Pack v1.3.1#
Scripts#
ExportMLModelUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ImportMLModelUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Majestic Million Feed Pack v1.1.3#
Integrations#
Majestic Million FeedImproved implementation of the timestamp conversion to ISO format.
#
Maltiverse Pack v1.0.5#
Integrations#
MaltiverseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Manage Engine Service Desk Plus Pack v2.0.2#
Integrations#
Service Desk PlusUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
McAfee ESM Pack v1.1.9#
Integrations#
McAfee ESM v2- Fixed an issue where alarms were fetched only for the user who was configured for authentication.
- Added a default value of CURRENT_DAY to the timeRange argument of the esm-fetch-alarms command.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Microsoft 365 Defender Pack v1.0.2#
Integrations#
Microsoft 365 Defender (Beta)Updated the description and README file.
#
Microsoft Azure AD Connect Health Feed Pack v1.0.2#
Integrations#
Azure AD Connect Health Feed- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/btfl-soup:1.0.1.20928.
#
Microsoft Graph Groups Pack v1.0.7#
Integrations#
Microsoft Graph GroupsUpdated the Docker image to: demisto/crypto:1.0.0.19032.
#
MobileIron-UEM Pack v1.0.4 (Partner Supported)#
Integrations#
MobileIronCLOUDUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
MobileIronCOREUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ModulesManagement Pack v1.0.2#
Scripts#
GetInstancesUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Netcraft Pack v1.0.3#
Integrations#
NetcraftUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Netscout Arbor Edge Defense - AED Pack v1.0.3#
Integrations#
Netscout Arbor Edge DefenseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Nozomi Networks Pack v1.0.3 (Partner Supported)#
Integrations#
Nozomi NetworksUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Nutanix Hypervisor Pack v1.0.3#
Integrations#
Nutanix HypervisorUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Office 365 Feed Pack v1.1.7#
Integrations#
Office 365 FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Okta Pack v2.1.11#
Integrations#
Okta IAMUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Okta v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
OpenCTI Feed Pack v2.0.1#
Integrations#
OpenCTI Feed 3.X- Fixed an issue where the Tags integration parameter was not handled properly.
- Updated the Docker image to: demisto/opencti:1.0.0.19143.
#
OpenCTI Feed 4.X- Fixed an issue where the Tags integration parameter was not handled properly.
- Updated the Docker image to: demisto/opencti-v4:1.0.0.19143.
#
OpenPhish Pack v2.0.4#
Integrations#
OpenPhish v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Opsgenie v2 Pack v1.0.2 (Community Contributed)#
Integrations#
Opsgenie v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Orca Pack v1.0.6 (Partner Supported)#
Integrations#
OrcaUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
PAN-OS to Cortex Data Lake Monitoring Pack v1.0.6 (Community Contributed)#
Scripts#
PANOStoCortexDataLakeMonitoringUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
PANW Comprehensive Investigation Pack v1.3.7#
Scripts#
PanwIndicatorCreateQueriesUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Palo Alto Networks BPA Pack v1.2.8#
Integrations#
Palo Alto Networks BPA- Updated the description for the Server URL integration parameter.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Palo Alto Networks Cortex XDR - Investigation and Response Pack v3.0.17#
Integrations#
Palo Alto Networks Cortex XDR - Investigation and ResponseImproved the error message for the test-module command in case the Cortex XDR server is not in sync with Cortex XSOAR.
#
Palo Alto Networks IoT Pack v1.0.4#
Integrations#
Palo Alto Networks IoTUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Palo Alto Networks PAN-OS EDL Service Pack v2.0.6#
Integrations#
Palo Alto Networks PAN-OS EDL ServiceAdded the Use Legacy Queries integration parameter. When enabled, the integration will query the server using full queries. Enable this query mode, if you've been instructed by support, or you've encountered in the log errors of the form: msgpack: invalid code.
#
Palo Alto Networks Threat Vault Pack v1.0.5#
Integrations#
Palo Alto Networks Threat VaultUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Palo Alto Networks WildFire Pack v1.3.8#
Integrations#
Palo Alto Networks WildFire v2- Fixed an issue where the wildfire-get-report-command command failed due to incorrect handling of chunked HTTP responses.
- Added support for the Source Reliability integration parameter.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
PassiveTotal Pack v2.0.10 (Partner Supported)#
Integrations#
PassiveTotal v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Scripts#
RiskIQPassiveTotalComponentsWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalHostPairsChildrenWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalHostPairsParentsWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalPDNSWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalSSLForIssuerEmailWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalSSLForSubjectEmailWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalSSLWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalTrackersWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQPassiveTotalWhoisWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
PhishTank Pack v2.0.8#
Integrations#
PhishTank v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Phishing Pack v2.2.6#
Playbooks#
Get Original Email - EWSMaintenance and stability enhancements.
#
Scripts#
FindDuplicateEmailIncidents- Fixed an issue where passing an empty string as a query argument would cause the script to fail.
- Updated the Docker image to: demisto/sklearn:1.0.0.22039.
#
PhishingDedupPreprocessingRuleMaintenance and stability enhancements.
#
Phishing Campaign Pack v2.0.6#
Scripts#
FindEmailCampaign- Added EmailCampaign.fieldsToDisplay to the context output, which indicates which headers should be displayed.
- Updated the Docker image to: demisto/sklearn:1.0.0.21733.
#
GetCampaignIncidentsInfo- The script will now display only the headers specified in the EmailCampaign.fieldsToDisplay context entry.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Polygon Pack v1.0.4 (Partner Supported)#
Integrations#
Group-IB TDS PolygonUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Proofpoint Feed Pack v1.0.5#
Integrations#
Proofpoint FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Proofpoint Protection Server Pack v2.0.5#
Integrations#
Proofpoint Protection Server v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Proofpoint TAP Pack v1.1.3#
Integrations#
Proofpoint TAP v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Qualys Pack v1.0.4#
Integrations#
QualysMaintenance and stability enhancements.
#
New: Qualys v2Qualys Vulnerability Management lets you:
- Create, run, fetch, and manage reports.
- Launch and manage vulnerability and compliance scans.
- Manage the host assets you want to scan for vulnerabilities and compliance. (Available from Cortex XSOAR 5.5.0).
#
Playbooks#
New: Launch And Fetch Remediation Report - QualysLaunches a remediation report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Host Based Findings Report - QualysLaunches a host-based report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch VM Scan - QualysLaunches a scan and fetches the scan when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Scheduled Report - QualysLaunches a scheduled report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Compliance Policy Report - QualysLaunches a compliance policy report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Map Report - QualysLaunches a map scan report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Scan Based Findings Report - QualysLaunches a scan based report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch PC Scan - QualysLaunches a PC scan and fetches the scan when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Patch Report - QualysLaunches a patch report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Launch And Fetch Compliance Report - QualysLaunches a compliance report and fetches the report when it is ready. (Available from Cortex XSOAR 5.5.0).
#
New: Vulnerability Management - Qualys (Job) - V2Updated the V1 playbook to V2.
#
Quantum Security Systems Pack v1.0.2 (Partner Supported)#
Integrations#
QSSUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
QueryAI Pack v1.0.6 (Partner Supported)#
Integrations#
QueryAIUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RSA Archer Pack v1.1.18#
Integrations#
RSA Archer v2- Fixed an issue where the archer-search-records-by-report command failed to handle a report with only one record.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
RST Threat Feed Pack v1.0.3 (Partner Supported)#
Integrations#
RST Cloud - Threat Feed APIUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Rapid Breach Response Pack v1.6.9#
Playbooks#
HAFNIUM - Exchange 0-day exploitsRemoved duplicated playbook tasks related to indicators.
#
New: CVE-2021-1675 - PrintNightmareCVE-2021-1675 is a vulnerability dubbed โPrintNightmareโ which allows remote code execution on Windows Print Spooler.
Microsoft patched the vulnerability in June, but an exploit proof of concept, and complete technical analysis were made publicly available online.
This playbook includes the following tasks:
- Manual actions to mitigate the exploit.
- Search vulnerable devices using CVE.
- Search vulnerable devices using the SIEM.
The playbook will also query the firewall and Cortex XDR to detect malicious activity and compromised hosts.
This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs.
Updates to the pack during the beta phase might include non-backward compatible features.
We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
#
Rapid7 InsightIDR Pack v1.0.3#
Integrations#
Rapid7 InsightIDRUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Recorded Future Feed Pack v1.0.11#
Integrations#
Recorded Future RiskList FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Red Canary Pack v1.1.2#
Integrations#
Red CanaryUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ReplaceMatchGroup Pack v1.0.3#
Scripts#
ReplaceMatchGroupUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
RiskIQ Digital Footprint Pack v1.0.8 (Partner Supported)#
Integrations#
RiskIQ Digital FootprintUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Scripts#
RiskIQDigitalFootprintAssetDetailsWidgetScriptUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Rubrik Polaris Pack v1.0.3 (Partner Supported)#
Integrations#
Rubrik RadarUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Rundeck Pack v1.0.4#
Integrations#
RundeckUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
SailPoint IdentityNow Pack v1.0.2 (Partner Supported)#
Integrations#
SailPoint IdentityNowUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Securonix Pack v1.1.6#
Integrations#
SecuronixSupport for this pack will move to a partner on or about October 1, 2021.
#
Sepio Pack v1.0.3 (Partner Supported)#
Integrations#
SepioUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Server Message Block (SMB) Pack v2.0.3#
Integrations#
Server Message Block (SMB) v2Fixed an issue where a request failed when the SMB2 protocol response header contained a bad epoch time.
#
ServerLogs Pack v1.0.1 (Community Contributed)#
Scripts#
ServerLogs- Added the required dependency for the Remote Access integration.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
ServiceNow Pack v2.1.25#
Integrations#
ServiceNow CMDBUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ServiceNow IAMUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ServiceNow v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Playbooks#
New: ServiceNow CMDB Search- Sub-playbook for finding configuration item records in the ServiceNow CMDB. (Available from Cortex XSOAR 6.0.0).
- Enriches context with configuration items that match a given query.
- Prompts analysts to add missing records to their CMDB.
#
Shift Management Pack v1.2.4#
Scripts#
GetNumberOfUsersOnCallUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetOnCallHoursPerUserUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetRolesPerShiftUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetShiftsPerUserUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetUsersOOOUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
GetUsersOnCallUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
TimeToNextShiftUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Silverfort Pack v1.0.5 (Partner Supported)#
Integrations#
SilverfortUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Sixgill Darkfeed - Annual Subscription Pack v2.0.2 (Partner Supported)#
Scripts#
SixgillSearchIndicatorsUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
SlashNext Phishing Incident Response - Annual Subscription (Direct Subscription) Pack v1.2.2 (Partner Supported)#
Integrations#
SlashNext Phishing Incident ResponseUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Sophos XG Firewall Pack v1.0.4#
Integrations#
Sophos FirewallUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Sumo Logic Cloud SIEM Pack v1.0.2 (Partner Supported)#
Integrations#
Sumo Logic Cloud SIEMUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Symantec Endpoint Protection Pack v1.0.3#
Integrations#
Symantec Endpoint Protection v2Improved the error message that is returned when an invalid request is sent within all of the integration's commands.
#
Symantec Management Center Pack v1.0.4#
Integrations#
Symantec Management CenterUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Syslog Sender Pack v1.0.3#
Integrations#
Syslog SenderUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
TAXII Server Pack v1.0.8#
Integrations#
TAXII ServerUpdated the Docker image to: demisto/taxii-server:1.0.0.21219.
#
TOPdesk Pack v1.0.3#
Integrations#
TOPdesk- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Talos Feed Pack v1.0.3 (Community Contributed)#
Integrations#
Talos FeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Tanium Pack v1.0.7#
Integrations#
Tanium v2- Updated the authentication process of the integration to support both OAuth 2.0 and basic authentication.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Threat Intelligence Management Pack v1.0.4#
Scripts#
ThreatIntelManagementGetIncidentsPerFeedUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ThreatExchange Pack v2.0.2#
Integrations#
ThreatExchange v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
ThreatQ Pack v1.0.9 (Partner Supported)#
Integrations#
ThreatQ v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Tidy Pack v1.0.6#
Integrations#
TidyUpdated the Docker image to: demisto/tidy:1.0.0.22176.
#
Trello Pack v1.0.3 (Community Contributed)#
Integrations#
TrelloUpdated the Docker image to: demisto/python3]:3.9.5.21272.
#
Trend Micro Apex One Pack v2.0.1#
Integrations#
Trend Micro Apex One- Documentation and metadata improvements.
- Updated the Docker image to: demisto/pycef:1.0.0.19330.
#
Tripwire Pack v1.0.3#
Integrations#
TripwireUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Troubleshoot Pack v2.0.2#
Scripts#
TroubleshootExecuteCommand- Maintenance and stability enhancements.
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
TrustwaveSEG Pack v1.0.2#
Integrations#
Trustwave Secure Email GatewayUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Twinwave Pack v1.0.3 (Partner Supported)#
Integrations#
Twinwave- Fixed an issue where the proxy parameter did not work as expected.
- You can now pass multiple values to the engines argument in the following commands:
- twinwave-submit-url
- twinwave-submit-file
- Updated the Docker image to: demisto/python3:3.9.5.21272.
#
URLhaus Pack v1.0.5#
Integrations#
URLhausUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
VMRay Pack v1.0.4#
Integrations#
VMRayFixed an issue where the vmray-upload-sample command failed for file entry IDs whose names included backslashes.
#
Vectra Pack v1.0.2#
Integrations#
Vectra v2Updated the Docker image to: demisto/python3:3.9.5.21272.
#
Windows Forensics Pack v1.0.1#
Playbooks#
PS Remote Get File Sample From PathMaintenance and stability enhancements.
#
WootCloud Pack v1.0.5 (Partner Supported)#
Integrations#
WootCloudUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
X509Certificate Pack v1.0.6#
Scripts#
CertificateReputationUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
XSOAR Mirroring Pack v2.0.3#
Integrations#
XSOAR MirroringUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
ZeroFox Pack v1.0.2#
Integrations#
ZeroFoxUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Zimperium Pack v1.0.8#
Integrations#
ZimperiumUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
iLert Pack v1.0.2 (Partner Supported)#
Integrations#
iLertUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
xMatters Pack v1.0.2 (Partner Supported)#
Integrations#
xMattersUpdated the Docker image to: demisto/python3:3.9.5.21272.
#
Assets- Download Content Zip (Cortex XSOAR 5.5 and earlier): content_new.zip
- Download Marketplace Packs (Cortex XSOAR 6.0 and later): content_marketplace_packs.zip
- Browse the Source Code: Content Repo @ 21.7.0