-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Marketplace Contribution] Abnormal Security - Content Pack Update #32959
[Marketplace Contribution] Abnormal Security - Content Pack Update #32959
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @vipulkaneriya,
Thank you for your contribution!
Good work :)
Please see my comments
You can add the fixes / changes by using the resubmit option resubmit-a-content-pack, or by using GitHub Codespaces - GitHub Codespaces documentation.
For the Reviewer: Successfully created a pipeline in Gitlab with url: https://gitlab.xdr.pan.local/xdr/cortex-content/content/-/pipelines/871737 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi, the code looks good!
We're ready for a demo. Please check this page, and let me know when you're available for one over DFIR.
Hi @vipulkaneriya |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1 on behalf of Abnormal Security
…urity' into vipulkaneriya-contrib-AbnormalSecurity
f96448e
into
demisto:contrib/xsoar-contrib_vipulkaneriya-contrib-AbnormalSecurity
Thank you for your contribution. Your external PR has been merged and the changes are now included in an internal PR for further review. The internal PR will be merged to the master branch within 3 business days. |
…33462) * [Marketplace Contribution] Abnormal Security - Content Pack Update (#32959) * "contribution update to pack "Abnormal Security"" * Update Packs/AbnormalSecurity/ReleaseNotes/2_3_0.md * Rename 2_3_0.md to 2_2_7.md --------- Co-authored-by: JudithB <[email protected]> * pre commit * pre commit --------- Co-authored-by: xsoar-bot <[email protected]> Co-authored-by: JudithB <[email protected]> Co-authored-by: jbabazadeh <[email protected]>
Hi @vipulkaneriya, |
…emisto#33462) * [Marketplace Contribution] Abnormal Security - Content Pack Update (demisto#32959) * "contribution update to pack "Abnormal Security"" * Update Packs/AbnormalSecurity/ReleaseNotes/2_3_0.md * Rename 2_3_0.md to 2_2_7.md --------- Co-authored-by: JudithB <[email protected]> * pre commit * pre commit --------- Co-authored-by: xsoar-bot <[email protected]> Co-authored-by: JudithB <[email protected]> Co-authored-by: jbabazadeh <[email protected]>
Status
Contributor
@vipulkaneriya
Notes
We had a challenge searching Threat log and Abuse campaign with limited search filter available for "abnormal-security-list-abuse-mailbox-campaigns" and "abnormal-security-list-threats". I reviewed the Abnormal Security API documentation and found out that we can narrow down list of Threat log and Abuse campaign by adding more search parameters. I added list result by sender, recipient, subject etc and hope your other customer will also benefits from this.
I request you to review other "list" command and add more search parameters.
refer:
https://app.swaggerhub.com/apis/abnormal-security/abx/1.4.2#/Abuse%20Mailbox/get_abusecampaigns
https://app.swaggerhub.com/apis/abnormal-security/abx/1.4.2#/Threats/get_threats
Video Link
Short demo video of the Pack usage. Speeds up the review. Optional but recommended. Use a video sharing service such as Google Drive or YouTube.