Граф коммитов

318 Коммитов

Автор SHA1 Сообщение Дата
Pete Bryan 6f5b8b28a5 schema and naming updates 2021-03-07 17:16:27 -08:00
Pete Bryan 2f571bab92
format changes 2021-03-07 14:54:29 -08:00
Pete Bryan b890d23e46
format test 2021-03-07 14:52:48 -08:00
Pete Bryan 58fbab17b7
format test 2021-03-07 14:51:07 -08:00
Pete Bryan ca4383fa2d
Changing file extension to reflect jsonl format 2021-03-07 14:45:52 -08:00
Pete Bryan 19e3f82f56
fomatting 2021-03-07 14:45:07 -08:00
Pete Bryan db4045f2e9
Testing format changes 2021-03-07 14:34:14 -08:00
Pete Bryan e4b05970af
More format testing 2021-03-07 14:32:32 -08:00
Pete Bryan 0b8397090e
Update json format for testing 2021-03-07 14:26:18 -08:00
Shain 2563d25282
Update MSTICIoCs-ExchangeServerVulnerabilities-March2021.json
removing spaces, just in case that is causing validation issues
2021-03-06 08:24:29 -08:00
Pete Bryan 5a6a24f593 Test 2021-03-05 18:53:07 -08:00
Pete Bryan 086d2717c9 JSON template and query 2021-03-05 18:35:53 -08:00
Pete Bryan b72e06f89c Test data 2021-03-05 18:00:24 -08:00
Pete Bryan f4735ba256 format test 2021-03-05 17:56:37 -08:00
Pete Bryan 6b2c152577 Testing 2021-03-05 17:51:29 -08:00
Pete Bryan ab5b9808d3 MTPQueries&IOCPlaceholder 2021-03-05 15:00:41 -08:00
Aorimn a4b997efde
Add MessageType=2 examples
This is needed as per this comment: https://github.com/Azure/Azure-Sentinel/pull/1662/files#r578946390
2021-03-03 09:37:40 +01:00
sschuur 7d3e9c97b4
Merge branch 'master' into Infoblox-CDC-dataconnector 2021-03-01 19:42:45 -08:00
v-jayakal 1c9d02195f
Merge pull request #1812 from adirDev/CognniDataConnector
Add Cognni data connector,  including:
2021-03-01 15:19:09 -08:00
v-jayakal 52ff0bdb21
Merge pull request #1797 from socprime/box_data_conn
Box Data Connector
2021-02-25 10:45:28 -08:00
Alex Verbniak 89849e4503 SlackAudit: Datasample added 2021-02-23 16:09:15 +02:00
v-jayakal 20f012c15c
Merge pull request #1679 from socprime/JiraAuditConnector
Jira audit connector
2021-02-22 22:47:40 -08:00
adirDev cfe0559e46 Add Cognni data connector including:
* The data connector json file
* Cognni logo
* Cognni sample data
* Detection queries
* Cognni workbook with preview images
2021-02-22 10:43:16 +02:00
sschuur fe9d1b4b00
Merge branch 'master' into Infoblox-CDC-dataconnector 2021-02-21 15:54:29 -08:00
Sergiy Prystaiko c96d3f4715 oracle db audit - added sample data 2021-02-19 18:59:24 +02:00
Sergiy Prystaiko 4994b13274 mcafeeepo - added sample data 2021-02-19 18:58:30 +02:00
Vitalii Uslystyi 014608161f box data conn - added sample data 2021-02-19 16:10:19 +02:00
v-jayakal af03fa3565
Merge pull request #1731 from SunRift/darktrace-workbook-and-rename-clean
renaming and updating of connector documentation
2021-02-18 23:03:01 -08:00
Shain 972ada635a
Merge pull request #1551 from acnccd/acn_cd_crowdstrike_parser01
ACN_CD_CrowdStrikeFalcon_Parser01
2021-02-17 21:53:51 -08:00
v-jayakal 597526d9e5
Merge pull request #1614 from socprime/nginx_data_connector
NGINX data connector
2021-02-15 04:42:06 -08:00
sschuur 1a5c36b9af
Reuploaded sample data file to reflect new B1TD CEF fields in recent update 2021-02-11 17:24:46 -08:00
SunRift 1a986563bc renaming and updating of connector documentation
A remake of the previous renaming/updated workbook branch without any notebook changes.
2021-02-08 11:01:10 +00:00
chicduong da7bf82652 new sample data 2021-02-05 15:25:02 -08:00
sschuur 026a7f55f5
Added InfobloxCDC sample data csv 2021-02-05 15:00:42 -08:00
v-jayakal c6806df548
Merge pull request #1608 from Azure/feature/v-admahe/ForcePointCloud
onboard Forcepoint Cloud Security Gateway
2021-02-02 23:01:31 +05:30
Alex Verbniak 52303d6216 JiraAudit: data sample 2021-01-28 16:47:35 +02:00
v-jayakal c68dfab32b
Merge pull request #1446 from cyberpion-yotam/cyberpion-sl-connector
Cyberpion sl connector
2021-01-21 10:47:11 +05:30
v-jayakal 570b3c3428
Merge pull request #1560 from techwriter-dev/nxlog-bsm-macos
NXLog BSM macOS (Custom) data connector
2021-01-21 10:44:08 +05:30
Sergiy Prystaiko 3ad4d0f0bb Added NGINX data connector 2021-01-20 14:14:14 +02:00
v-admahe 3f87f4e07d Changes for ForcepointCloudSecurity 2021-01-20 13:15:01 +05:30
Shain 18436b46c0
Merge pull request #1501 from chicduong/acn_cd_sepparser03
ACN_CD_SymantecEndpointProtection_Parser_03
2021-01-19 20:43:05 -08:00
John Kirch f1c16795d2 NXLog BSM macOS (Custom) data connector
1. Connector UX: `NXLogBSMmacOS.json`
2. Sample Data:  `BSMmacOS_CL.json`
3. Logo:         `NXLog.svg`
2021-01-07 12:35:54 -06:00
Roi Vaknin fc57db99a7
Morphiesc DataConnector (#1435)
* Morphiesc DataConnector

- Morphisec Data connector configuration
- Morphisec parser function
- Morphisec logo
- Morphisec events sample as csv

* Updated files

- changed logo into smaller file without xmlns
- changed id
- fixed links to parser
- added IsPreview
- Fixed -O for python

* Update logo file

* Fixed logo

Added xmlns and remove title

Co-authored-by: Roi <roi@morphisec.com>
2021-01-05 18:13:12 -08:00
chicduong b7399dea5c CrowdStrike Falcon Parser 2021-01-04 17:09:51 -08:00
Yotam Rosenmann 29922b4c16 Merge branch 'master' into cyberpion-sl-connector 2020-12-24 12:34:52 +02:00
Yotam Rosenmann 8d0a4e8ad1 Fixed sample data format 2020-12-23 14:05:10 +02:00
chicduong dca6ac46f5 parser updates 2020-12-22 12:55:53 -08:00
Pete Bryan 453cd3f0ae format external data 2020-12-22 19:17:14 +00:00
Pete Bryan a454a613c1 Moved VPS providers to external data 2020-12-22 19:06:20 +00:00
chicduong 5e26eb5c1e parser updates 2020-12-17 15:19:01 -08:00
Shain adf08b9bf9
Merge pull request #1368 from AlsidOfficial/AFAD-connector
New Alsid for AD connector, workbooks and analytics templates
2020-12-14 14:45:52 -08:00
Shain d84a1281dc
Merge pull request #1413 from chicduong/acn_cd_qualyskbparser01
ACN_CD_QualysKB_Parser01
2020-12-14 14:41:51 -08:00
Shain 5b01275af3
Merge pull request #1433 from chicduong/acn_cd_merakiparser01
ACN_CD_CiscoMeraki_Parser01
2020-12-14 14:37:59 -08:00
SunRift 413fca0b8a
Darktrace connector (#1359)
* Darktrace Connector info

initial 3 required files for connector PR

* Update Darktrace.json

added KQL query

* Update Darktrace.svg

removed xlink

* Update Darktrace.svg

Changed logo fill as requested

* Darktrace Connector workbook added

Added relevant files required for the darktrace workbook, which contains a variety of KQL queries.

* Updated Connector Description

Updated description to be more specific as per change request.

* Update WorkbooksMetadata.json

spaces added

* Removing additional Character

Removing additional Character at the beginning of the file in Darktrace workbook json

Co-authored-by: v-jayakal <v-jayakal@microsoft.com>
2020-12-11 17:56:52 -08:00
v-jayakal 90eeb9dcc3
Removing special character
Removing special character at the beginning of the file.
2020-12-11 16:42:43 -08:00
Donny Maasland 6a43d4da21
Add ESET Enterprise Inspector REST API connector (#1417)
* initial commit of eei connector

* add custom permissions

* add sample data

* remove actual URL

* trim sample data

* change package URL

* remove locale from comment

* update zip

* remove extra space

* remove extra double quote
2020-12-11 15:58:33 -08:00
Yotam Rosenmann e5d762782f Merge branch 'master' into cyberpion-sl-connector 2020-12-11 11:40:04 +02:00
Yotam Rosenmann 87d4529039 Created Cyberpion connector 2020-12-11 11:14:00 +02:00
Eric Shulze 1225b2d57a
Trend Micro XDR Initial Commit (#1353)
* Trend Micro XDR - Initial Commit

* Fixed Rendering of onboarding steps

* Inital Rule Templates - Trend Micro XDR

* Fixed: Format Error

* Added Trend Micro XDR Overview Workbench, and supporting files.

* Fixed extra addition

* Rebased file issue

* Added Missing KQL Validation table format

* ARM Template Usablitiy enahcment - made dropdown option

* Sample Data Example Additon

* Added missing CL from customer data type dependancy.

* Addressed PR Comments, Added logging, Added API Key Failure Error

* Fixed commit issues

* Fixing Requested Change

* variable rename as requested

* fixed Workbook issue

* Added 3 new queries to Workbook

* Updated Sample Images

* updated URL for API Key instructions

* Updated ARM URL, removed subscription ID's

Co-authored-by: Eric Shulze <ericsh@us-ericsh-mac.us.trendnet.org>
Co-authored-by: ericsh <eric_shulze@trendmicro.com>
2020-12-09 18:57:49 -08:00
chicduong 20dcde2a79 cisco meraki parser 2020-12-09 14:53:54 -08:00
Shain c55ebd5179
Merge pull request #1388 from chicduong/acn_cd_sepparser01
ACN_CD_SymantecEndpointProtection_Parser01
2020-12-09 12:13:43 -08:00
Shain 6f58976e95
Merge pull request #1386 from chicduong/acn_cd_arubaclearpassparser01
ACN_CD_ArubaClearPass_Parser01
2020-12-09 12:12:36 -08:00
Shain 6769ed5234
Merge pull request #1410 from chicduong/acn_cd_cylanceparser01
ACN_CD_CylancePROTECT_Parser01
2020-12-09 12:10:28 -08:00
Julien CLEMENT 88f7fbd3c8 Renamed sample file to match table name
Signed-off-by: Julien CLEMENT <julien.clement@epita.fr>
2020-12-09 10:28:33 +01:00
SOC Prime cace382aa5
Apache HTTP Server Data Connector (#1373)
* added ApacheHTTPServer Data Connector

* added description to apache parser

* added apache logo

* apache data connector - changed connector id

Co-authored-by: Sergiy Prystaiko <sp@socprime.com>
Co-authored-by: Vitalii Uslystyi <vu@socprime.com>
2020-12-08 17:32:56 -08:00
Praneet 8644628b81
Sophos cloud optix (#1391)
* Sophos Cloud Optix Rest API Data Connector Initial Commit

* Removing the stale description line

* Fixing the DocumentsLinkValidation error with locale (en-us) specified in the url

* Fixing the DocumentsLinkValidation error with locale (en-us) specified in some sample data

* Updating to remove 'customs' permissions as Sophos Cloud Optix doesn't need it

* Updating the query to show top 5 environments
2020-12-08 08:27:37 -08:00
Julien CLEMENT a12cba04e0 Changed sample data from csv to json
Signed-off-by: Julien CLEMENT <julien.clement@epita.fr>
2020-12-07 15:36:02 +01:00
chicduong b156974d98 qualys KB parser 2020-12-04 22:56:36 -08:00
chicduong 77963bc816
ACN_CD_SymantecDLP_Parser01 (#1364)
* symantec parser and sample data

* updated parser
2020-12-04 16:46:08 -08:00
chicduong c044cb2fdb cylancePROTECT parser 2020-12-04 14:31:56 -08:00
ecosystempo 067b6d796b
WatchGuardFirebox Connector update (#1365)
* Update WatchGuardFirebox syslog

Update WatchGuardFirebox syslog

* Delete Connector_syslog_WatchGuardFirebox.json

* Update WatchGuardFirebox syslog

Update WatchGuardFirebox syslog

* Updte WatchGuard logo

Updte WatchGuard logo

* Add files via upload

* Delete WatchGuard_logo_Color.svg

* Add files via upload

* Add WatchGuardFirebox.json file

* Delete Connector_syslog_WatchGuardFirebox.json

* Delete WatchGuardFirebox.txt

* Delete WatchGuard_Logo-SVG_Format.svg

* Delete WatchGuardFirebox_syslog_data.csv

* Update WatchGuardFirebox Connector json file

* Update Connector_syslog_WatchGuardFirebox.json

* Update Connector_syslog_WatchGuardFirebox.json

* Add WatchGuard Firebox Parsers file

* Add WatchGuard Logo file

* Delete WatchGuard_Logo-SVG_Format.svg

wrong place

* Add WatchGuard Logo file

* Update WatchGuardFirebox syslog data

* test

* Delete new 1.txt

* Update Connector_syslog_WatchGuardFirebox.json

1.modify SampleQueries, DataType and connectivityCriterias query to WatchGuardFirebox
2.Legend value remove WatchGuard
3.use https://aka.ms/sentinel-watchguardfirebox-parser as Kusto Function link.

* Update WatchGuardFirebox.txt

update USAGE step

* Update WatchGuard_Logo-SVG_Format.svg

remove id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"  in line 2

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Delete WatchGuard_Logo-SVG_Format.svg

Delete and update new one

* Add new  WatchGuard_Logo-SVG_Format.svg file

* Update WatchGuard_Logo-SVG_Format.svg

I remove xmlns:xlink, keep id="Layer_1".
logo properties didn't have GUIDs so i'm not sure id="Layer_1" should be keep or modify or delete

* Update WatchGuard_Logo-SVG_Format.svg
2020-12-04 11:35:27 -08:00
SOC Prime 33796f287c
Akamai Security Events Data Connector (#1375)
* added Akamai Security Events Data Connector

* added akamai logo

* updated akamai data connector template

Co-authored-by: Sergiy Prystaiko <sp@socprime.com>
2020-12-04 11:18:30 -08:00
SOC Prime 7c3d0c8de6
Cisco ISE Data Connector (#1374)
* added Cisco ISE Data Connector

* added description to Cisco ISE parser

* updated cisco ise data connector template

Co-authored-by: Sergiy Prystaiko <sp@socprime.com>
2020-12-04 11:14:52 -08:00
tijuc b47d6af0fd
Adding SonicWall CEF connector for Azure Sentinel (#1397)
Azure Sentinel CEF connecotr for SonicWall Firewall
2020-12-03 15:02:45 -08:00
Julien CLEMENT ec8eb1a990 Merge branch 'master' into AFAD-connector 2020-12-03 10:35:04 +01:00
John Kirch 6463056031
NXLog LinuxAudit data connector: Initial Commit (#1280)
* NXLog LinuxAudit data connector: Initial Commit
  1. Connector UX: NXLogLinuxAudit.json
  2. Sample Data:  NXLogLinuxAudit_CL.json
  3. Logo:         NXLog.svg

* 1. Connector UX: `NXLogDnsLogs.json`
2. Sample Data:  `NXLogDNS_Logs_CL.json`
3. Logo:         `NXLog.svg`

* Resolved the following issues in Pull Request 1280:
  1. Changed the filename of the Data Samples for this collector to match the table name.
  2. Added 7 additional JSON records having the "comm" field with various values:
     "sshd","whoami","sudo","systemd-hostnam","accounts-daemon","usermod","polkit-agent-he"

* Resolve conversation in Pull Request 1298 regarding the "en-us" locale in the ETW Documentation URL

* Attempt to resolve DocumentsLinkValidation failures in Pull Request 1298:
Renamed "Sample Data/Custom/NXLogDNS_Logs_CL.json" to match the table name:
        "Sample Data/Custom/DNS_Logs_CL.json"

Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
2020-12-01 23:44:20 -08:00
chicduong 71b2d303da sample data updates 2020-12-01 16:34:52 -08:00
chicduong 55601c30d0 SEP Parser 2020-12-01 16:20:16 -08:00
chicduong 71748b470a Aruba ClearPass parser 2020-12-01 12:31:28 -08:00
SOC Prime 88c3fc89b6
G workspace reports connector (#1320)
* GWorkspace: add table schemas

* GWorkspace: add parser

* GWorkspace: add deploy template

* GWorkspace: add pickle_string script

* GWorkspace: add connector template

* GWorkspace: add connector archive

* GWorkspace: add connector files

* GWorkspace: fixes in script.

* GWorkspace: update archive.

* Gworkspace: fixing json file

* GWorkspace: add logo

* GWorkspace: Connector template fixes

* GWorkspace: added data samples

* GWorkspace: added new logo

* GWorkspace: Add sampleQueries

* GWorkspace: Script and Archive updated

Co-authored-by: Alex Verbniak <ov@socprime.com>
2020-11-25 14:00:19 -08:00
Julien CLEMENT cb57b910c3 Add sample data
Signed-off-by: Julien CLEMENT <julien.clement@epita.fr>
2020-11-25 10:53:41 +01:00
skhademcis 1586b8a749
Cisco firepower e streamer cef (#1239)
* Initial 4.0 build of enCore eStreamer client for Sentinel

* updated setup instructions

* Relocated CiscoFirepowerConnector location

* Updated sample queries, cleaned up documentation, and removed ids and title from svg logo

* Abbreviated links using markup

* modified svg ids and removed title

* Update cisco-logo-72px.svg

Removed invalid version attribute and modified guids

* Update cisco-logo-72px.svg

Removed xml namespace definition and credit to png generation software

Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
2020-11-24 17:45:50 -08:00
chicduong d104b3816b
ACN_CD_Netskope_DataConnector01 (#1313)
* Netskope Connector

* revisions

* revisions 2

* updated filename
2020-11-24 14:29:06 -08:00
Usman Din 58cff9dbdc
PFI25 - Agari data connector fixes (#1315)
* PFI-25: Agari Data Connector

 - Added support for fetching /revoking bearer tokens for Agari Phishing Defense (APD)
 - Added support for fetching /revoking bearer tokens for Agari Phishing Response (APR)
 - Added support for fetching /revoking bearer tokens for Agari Brand Protection (BP)
 - Added support Microsoft Security Graph via OAuth
 - Added support for fetching Policy Hits and Threat Categories for APD into Sentinel Log Analytics
 - Added support for Brand Protection alert logs to Sentinel Log Analytics.
 - Added support for Brand Protection Threat Feeds to feed URL data to the Security Graph
 - Added support for Phishing Response IoCs to be fed to the Security Graph API
 - Added error checking on API responses
 - Added support for pagination of API responses
 - Added instructions for fetching the Agari Client ID / Secret
 - Added instructions about the Security Graph API
 - Added instructions for manual deployment

* PFI-25: Agari Data Connector (continued - fixes)

 - fixed typo in token gen if statement
 - fixed header variable in APD call
 - added x-header to API call to identify Sentinel
 - added if statements for APD push to Sentinel to verify if there is data to push
 - removed en-us from URLs
 - added BP logs to deployment template
 - added log samples - raw is data from the API call, formatted is what is used to push to Sentinel
 - added approprtiate files to the zip archive
 - functionapp.json--
 - removed Preview from the title
 - added preview to the availability section
 --deploy.json--
 - removed "description" tag from the boolean variables
 - fixed typos in the descriptions
 - fixed alignment of paramaters
 - added new resources to capture function, resource groups, subscriptionid for writing to the evironment variables
 - added 3 new variables for LastLogtTime per product
 --run.ps1 changes--
 - added new variables to take read environment variables
 - added new function SetLastLogTime. This function stamps the new startdate to be used on the next run of the script. This was done to satisfy the case where if the script failed to run there would be no gap in the logs vs relying on the timer function
 - added UserAgent Strings
 - moved startdate into if statements per product to read the latest time in the respective variables
 - added varaiables to be populated if the API call was successfule, used in the function above to signal a new startdate should be populated
 - call the function last as it resets the current app session
 --zip file--
 - created new zip with updated app
 - added version of powershell progamatically to the UA String
 - per product UA strings
 - Set the the first run start-date once
 - moved to per product startdate variables
 - modified queries to use per-product startdates
 - Update agari.zip

* Update Agari_API_FunctionApp.json

-Updated instructions for additonal steps around permissions to make both the automated and manual deployments have the correct permissions.
-added BP logs to the query section

* Updated additonal instructions and samples

Cleaned up the instructions further
added samples in json format
removed old zip samples

* Updated role type

Changed text to Contirbutor vs owner

* Update azuredeploy_Agari_API_FunctionApp.json

Updated as per guidance from @nazang

* Update azuredeploy_Agari_API_FunctionApp.json

- Added the ?raw=true to the link.

* Update Agari_API_FunctionApp.json

@nazang I'll need a shortened link for the FunctionAPP.json as well

* Links and Logo Update

- added short links to json files
- added Agari logo
2020-11-23 10:39:25 -08:00
SOC Prime 533e0983f8
Proofpoint POD Connector (#1293)
* proofpoint pod - initial commit

* ProofpointPOD: Delete "Preview" and change Umbrella to Proofpoint

* ProofpointPOD: delete empty lines from parser

* ProofpointPOD: add proxies.json file

* ProofpointPOD: script fixes

* ProofpointPOD: add well-known CA library certifi

Co-authored-by: Alex Verbniak <ov@socprime.com>
2020-11-20 17:30:04 -08:00
chicduong d7c49479b9
ACN_CD_JuniperSRX_DataConnector01 (#1324)
* juniper srx connector

* revisions
2020-11-20 16:40:07 -08:00
cbiguet 0b3c43deb1
Adding Onapsis Connector and Workbook (#1303)
* Adding Onapsis Connector and Workbook

* Applying proposed changes

Co-authored-by: Constantin Biguet <ext_cbiguet@onapsis.com>
Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
Co-authored-by: Nan Zang <nazang@microsoft.com>
2020-11-19 20:24:52 -08:00
chicduong 61e4b32bb9
ACN_CD_VMwareESXi_DataConnector01 (#1309)
* VMware ESXi connector

* revisions
2020-11-17 15:22:51 -08:00
SOC Prime e4d2a7a670
Salesforce Service Cloud Connector (#1292)
* saleforce sc connector - initial commit

* salesforce sc - added python file

* salesforce sc - updated zip file

* salesforce sc - updated connector template

* salesforce sc - added logo

* Salesforce SC: delete Preview

* Salesforce SC: change chunksize

* Salesforce SC: add proxies.json

* Salesforce SC: add handling of nextRecordsUrl

* Salesforce SC: update zip file

Co-authored-by: Alex Verbniak <ov@socprime.com>
2020-11-16 19:31:20 -08:00
Andrey Nikolaev b17aebb52d
Thycotic (#1144)
* Add new data connector

* Add example source data for ThycoticCEF dataconnector.
Add logo for dataconnector.

* Add workbook for Thycotic.

* Add workbook for Thycotic Secret Server.

* Add preview for Thycotic workbook

* Fix bug

* Add Thycotic dashboard and preview images and logo.

* Fix name dataconnector

* Add newline to json file

* Change workbook name in template

* Back file

* Add to Dashboard new block for event 'Login Failure'

* Change TemplateId

* Change link to base documentation for Secret Server

* Change link to documentation for configure Secret Server Syslog

* Changed data connector for Thycotic Secret Server

* Change Workbook , query add params

* Change format logo

* Add change to meta file

* Modify

* Update Logo for Dashboard, Dataconnector and Workbook

* Modify meta file

* Reset changes

* Reset Meta data

* Change meta file

* Change Logo for Thycotic

* Review image and changes Logo

Co-authored-by: unknown <andy@andy-nb.softwarium.net>
2020-11-13 15:15:49 -08:00
chicduong 37d8d8164f
ACN_CD_CiscoUCS_Connector01 (#1281)
* cisco ucs connector

* revisions

* update parser links
2020-11-13 15:03:22 -08:00
SOC Prime a90ff862f6
Cisco umbrella connector (#1261)
* added table schemas

* added function app

* added parser

* added logo

* added azuredeploy arm template

* updated links in azuredeploy arm template

* added connector template

* added sample data

* updated links to github in templates

* improved logging in function app

* updated connector template

* cisco umbrella: updated links

* cisco umbrella: removed logo to avoid duplication

* cisco umbrella connector - changed AWSSecretAccesKey variable name

* cisco umbrella connector - removed CiscoUmbrella.md file

* cisco umbrella connector - updated connector template

* cisco umbrella connector - updated connector template

* cisco umbrella - renamed parser func and updated connector template

* cisco umbrella - updated sample queries in connector template

* cisco umbrella - added proxies.json file

Co-authored-by: Vitalii Uslystyi <vu@socprime.com>
2020-11-13 07:16:25 -08:00
Aymen Ibrahim 3d059a315b
Added missing fields in Better MTD sample data 2020-11-12 16:29:19 +03:00
chicduong 6ab2bfe4d0
Squid Proxy Connector (#1231)
Co-authored-by: Preeti Krishna <preetikr@microsoft.com>
2020-11-10 17:08:31 -08:00
Aymen Ibrahim a1d3fc7ee0
Merged with upstream 2020-11-04 20:17:33 +03:00
ahatekar dda6a5f1dd Indicator publish: 11/2/2020 9:11:19 PM 2020-11-02 13:11:21 -08:00
ahatekar 21b958c0e9 Indicator publish: 11/2/2020 9:11:16 PM 2020-11-02 13:11:18 -08:00
Aymen Ibrahim e95ec341a2
Added json sample BETTER MTD data 2020-10-28 11:35:36 +03:00
ahatekar 5d57cd0885 Indicator publish: 10/27/2020 5:28:14 PM 2020-10-27 10:28:14 -07:00
ahatekar b6bbe97c1d Indicator publish: 10/27/2020 5:28:11 PM 2020-10-27 10:28:12 -07:00