Граф коммитов

96 Коммитов

Автор SHA1 Сообщение Дата
Eli Forbes 1f51a84abc Move Image Content 2021-03-05 12:10:42 -08:00
vu-socprime e324b88139
Merge branch 'master' into oracle_db_audit_data_conn 2021-03-05 10:37:07 +02:00
vu-socprime 5f54a93ca9
Merge branch 'master' into mcafeeepo_data_conn 2021-03-04 11:05:31 +02:00
v-jayakal 1c9d02195f
Merge pull request #1812 from adirDev/CognniDataConnector
Add Cognni data connector,  including:
2021-03-01 15:19:09 -08:00
v-jayakal 52ff0bdb21
Merge pull request #1797 from socprime/box_data_conn
Box Data Connector
2021-02-25 10:45:28 -08:00
Vitalii Uslystyi 5d3f4bf5ee box data conn - updated logo 2021-02-23 11:25:40 +02:00
Vitalii Uslystyi b3ed1e31fe oracle db audit - added logo 2021-02-23 10:02:41 +02:00
Vitalii Uslystyi a975ce48cb McAfeeePO - added logo 2021-02-23 10:01:04 +02:00
v-jayakal 20f012c15c
Merge pull request #1679 from socprime/JiraAuditConnector
Jira audit connector
2021-02-22 22:47:40 -08:00
Alex Verbniak bb0e918004 JiraAudit:icon fix 2021-02-22 16:47:57 +02:00
adirDev 55c20048ce Change logo id to GUID 2021-02-22 14:48:53 +02:00
adirDev 8ae317a365 Fix automation errors:
* Fix data connector schema
* Fix logo
* Fix workbook and workbookMetadata
* Removed all detection yaml files
2021-02-22 14:42:41 +02:00
adirDev cfe0559e46 Add Cognni data connector including:
* The data connector json file
* Cognni logo
* Cognni sample data
* Detection queries
* Cognni workbook with preview images
2021-02-22 10:43:16 +02:00
Eli Forbes 5f1640ff5c Fix Cisco Logo to be renderable 2021-02-17 16:29:43 -08:00
Vitalii Uslystyi 7ee7b39718 box data conn - added box logo 2021-02-15 15:03:34 +02:00
Alex Verbniak 6a73e8d8f0 JiraAudit: Icon changes 2021-02-09 10:18:46 +02:00
v-jayakal 6d6a55475d
Merge pull request #1689 from agaridata/012921-customer-fixes
012921 customer fixes
2021-02-05 11:46:32 +05:30
Usman Din 26b67a6f75 Updated Agari Logo
- removed all styling tags
2021-02-03 11:24:57 -05:00
Usman Din cb4cd4e662 Removed style tag from logo
Removed style tag from logo
2021-02-02 12:42:33 -05:00
v-jayakal c6806df548
Merge pull request #1608 from Azure/feature/v-admahe/ForcePointCloud
onboard Forcepoint Cloud Security Gateway
2021-02-02 23:01:31 +05:30
Usman Din 017fa6211d Updated Logo
New Logo file
2021-02-01 10:15:36 -05:00
Usman Din c101170c9d Logo and Boolean Fix
-added boolean parser fix
-updated logo
-updated zip
2021-01-29 16:10:20 -05:00
Usman Din 8c0f4b5afb Revert "Boolean fix and logo change"
This reverts commit 3d2174527b.
2021-01-29 16:05:53 -05:00
Usman Din 3d2174527b Boolean fix and logo change
added boolean parser
updated logo
updated zip
2021-01-29 16:03:28 -05:00
Alex Verbniak f150b64f35 JiraAudit: vendor logo 2021-01-28 16:48:16 +02:00
v-jayakal c68dfab32b
Merge pull request #1446 from cyberpion-yotam/cyberpion-sl-connector
Cyberpion sl connector
2021-01-21 10:47:11 +05:30
v-admahe 3f87f4e07d Changes for ForcepointCloudSecurity 2021-01-20 13:15:01 +05:30
Roi Vaknin fc57db99a7
Morphiesc DataConnector (#1435)
* Morphiesc DataConnector

- Morphisec Data connector configuration
- Morphisec parser function
- Morphisec logo
- Morphisec events sample as csv

* Updated files

- changed logo into smaller file without xmlns
- changed id
- fixed links to parser
- added IsPreview
- Fixed -O for python

* Update logo file

* Fixed logo

Added xmlns and remove title

Co-authored-by: Roi <roi@morphisec.com>
2021-01-05 18:13:12 -08:00
Yotam Rosenmann 29922b4c16 Merge branch 'master' into cyberpion-sl-connector 2020-12-24 12:34:52 +02:00
Shain adf08b9bf9
Merge pull request #1368 from AlsidOfficial/AFAD-connector
New Alsid for AD connector, workbooks and analytics templates
2020-12-14 14:45:52 -08:00
Julien CLEMENT cc68bc5874 Fix logos to fit guidelines
Signed-off-by: Julien CLEMENT <julien.clement@epita.fr>
2020-12-14 09:36:50 +01:00
SunRift 413fca0b8a
Darktrace connector (#1359)
* Darktrace Connector info

initial 3 required files for connector PR

* Update Darktrace.json

added KQL query

* Update Darktrace.svg

removed xlink

* Update Darktrace.svg

Changed logo fill as requested

* Darktrace Connector workbook added

Added relevant files required for the darktrace workbook, which contains a variety of KQL queries.

* Updated Connector Description

Updated description to be more specific as per change request.

* Update WorkbooksMetadata.json

spaces added

* Removing additional Character

Removing additional Character at the beginning of the file in Darktrace workbook json

Co-authored-by: v-jayakal <v-jayakal@microsoft.com>
2020-12-11 17:56:52 -08:00
Yotam Rosenmann e5d762782f Merge branch 'master' into cyberpion-sl-connector 2020-12-11 11:40:04 +02:00
Yotam Rosenmann 87d4529039 Created Cyberpion connector 2020-12-11 11:14:00 +02:00
SOC Prime cace382aa5
Apache HTTP Server Data Connector (#1373)
* added ApacheHTTPServer Data Connector

* added description to apache parser

* added apache logo

* apache data connector - changed connector id

Co-authored-by: Sergiy Prystaiko <sp@socprime.com>
Co-authored-by: Vitalii Uslystyi <vu@socprime.com>
2020-12-08 17:32:56 -08:00
ecosystempo 067b6d796b
WatchGuardFirebox Connector update (#1365)
* Update WatchGuardFirebox syslog

Update WatchGuardFirebox syslog

* Delete Connector_syslog_WatchGuardFirebox.json

* Update WatchGuardFirebox syslog

Update WatchGuardFirebox syslog

* Updte WatchGuard logo

Updte WatchGuard logo

* Add files via upload

* Delete WatchGuard_logo_Color.svg

* Add files via upload

* Add WatchGuardFirebox.json file

* Delete Connector_syslog_WatchGuardFirebox.json

* Delete WatchGuardFirebox.txt

* Delete WatchGuard_Logo-SVG_Format.svg

* Delete WatchGuardFirebox_syslog_data.csv

* Update WatchGuardFirebox Connector json file

* Update Connector_syslog_WatchGuardFirebox.json

* Update Connector_syslog_WatchGuardFirebox.json

* Add WatchGuard Firebox Parsers file

* Add WatchGuard Logo file

* Delete WatchGuard_Logo-SVG_Format.svg

wrong place

* Add WatchGuard Logo file

* Update WatchGuardFirebox syslog data

* test

* Delete new 1.txt

* Update Connector_syslog_WatchGuardFirebox.json

1.modify SampleQueries, DataType and connectivityCriterias query to WatchGuardFirebox
2.Legend value remove WatchGuard
3.use https://aka.ms/sentinel-watchguardfirebox-parser as Kusto Function link.

* Update WatchGuardFirebox.txt

update USAGE step

* Update WatchGuard_Logo-SVG_Format.svg

remove id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"  in line 2

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Update WatchGuard_Logo-SVG_Format.svg

* Delete WatchGuard_Logo-SVG_Format.svg

Delete and update new one

* Add new  WatchGuard_Logo-SVG_Format.svg file

* Update WatchGuard_Logo-SVG_Format.svg

I remove xmlns:xlink, keep id="Layer_1".
logo properties didn't have GUIDs so i'm not sure id="Layer_1" should be keep or modify or delete

* Update WatchGuard_Logo-SVG_Format.svg
2020-12-04 11:35:27 -08:00
SOC Prime 33796f287c
Akamai Security Events Data Connector (#1375)
* added Akamai Security Events Data Connector

* added akamai logo

* updated akamai data connector template

Co-authored-by: Sergiy Prystaiko <sp@socprime.com>
2020-12-04 11:18:30 -08:00
tijuc b47d6af0fd
Adding SonicWall CEF connector for Azure Sentinel (#1397)
Azure Sentinel CEF connecotr for SonicWall Firewall
2020-12-03 15:02:45 -08:00
Julien CLEMENT ec8eb1a990 Merge branch 'master' into AFAD-connector 2020-12-03 10:35:04 +01:00
John Kirch 6463056031
NXLog LinuxAudit data connector: Initial Commit (#1280)
* NXLog LinuxAudit data connector: Initial Commit
  1. Connector UX: NXLogLinuxAudit.json
  2. Sample Data:  NXLogLinuxAudit_CL.json
  3. Logo:         NXLog.svg

* 1. Connector UX: `NXLogDnsLogs.json`
2. Sample Data:  `NXLogDNS_Logs_CL.json`
3. Logo:         `NXLog.svg`

* Resolved the following issues in Pull Request 1280:
  1. Changed the filename of the Data Samples for this collector to match the table name.
  2. Added 7 additional JSON records having the "comm" field with various values:
     "sshd","whoami","sudo","systemd-hostnam","accounts-daemon","usermod","polkit-agent-he"

* Resolve conversation in Pull Request 1298 regarding the "en-us" locale in the ETW Documentation URL

* Attempt to resolve DocumentsLinkValidation failures in Pull Request 1298:
Renamed "Sample Data/Custom/NXLogDNS_Logs_CL.json" to match the table name:
        "Sample Data/Custom/DNS_Logs_CL.json"

Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
2020-12-01 23:44:20 -08:00
SOC Prime 88c3fc89b6
G workspace reports connector (#1320)
* GWorkspace: add table schemas

* GWorkspace: add parser

* GWorkspace: add deploy template

* GWorkspace: add pickle_string script

* GWorkspace: add connector template

* GWorkspace: add connector archive

* GWorkspace: add connector files

* GWorkspace: fixes in script.

* GWorkspace: update archive.

* Gworkspace: fixing json file

* GWorkspace: add logo

* GWorkspace: Connector template fixes

* GWorkspace: added data samples

* GWorkspace: added new logo

* GWorkspace: Add sampleQueries

* GWorkspace: Script and Archive updated

Co-authored-by: Alex Verbniak <ov@socprime.com>
2020-11-25 14:00:19 -08:00
Andrey Nikolaev bec77bef2b
Thycotic update logos (#1358)
* Changed Logo and new preview for workbook

* Add newline and fixed scheme
2020-11-25 13:51:51 -08:00
skhademcis 1586b8a749
Cisco firepower e streamer cef (#1239)
* Initial 4.0 build of enCore eStreamer client for Sentinel

* updated setup instructions

* Relocated CiscoFirepowerConnector location

* Updated sample queries, cleaned up documentation, and removed ids and title from svg logo

* Abbreviated links using markup

* modified svg ids and removed title

* Update cisco-logo-72px.svg

Removed invalid version attribute and modified guids

* Update cisco-logo-72px.svg

Removed xml namespace definition and credit to png generation software

Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
2020-11-24 17:45:50 -08:00
Julien CLEMENT 814380bd8a Add alsid logo
Signed-off-by: Julien CLEMENT <julien.clement@epita.fr>
2020-11-24 14:55:48 +01:00
Usman Din 58cff9dbdc
PFI25 - Agari data connector fixes (#1315)
* PFI-25: Agari Data Connector

 - Added support for fetching /revoking bearer tokens for Agari Phishing Defense (APD)
 - Added support for fetching /revoking bearer tokens for Agari Phishing Response (APR)
 - Added support for fetching /revoking bearer tokens for Agari Brand Protection (BP)
 - Added support Microsoft Security Graph via OAuth
 - Added support for fetching Policy Hits and Threat Categories for APD into Sentinel Log Analytics
 - Added support for Brand Protection alert logs to Sentinel Log Analytics.
 - Added support for Brand Protection Threat Feeds to feed URL data to the Security Graph
 - Added support for Phishing Response IoCs to be fed to the Security Graph API
 - Added error checking on API responses
 - Added support for pagination of API responses
 - Added instructions for fetching the Agari Client ID / Secret
 - Added instructions about the Security Graph API
 - Added instructions for manual deployment

* PFI-25: Agari Data Connector (continued - fixes)

 - fixed typo in token gen if statement
 - fixed header variable in APD call
 - added x-header to API call to identify Sentinel
 - added if statements for APD push to Sentinel to verify if there is data to push
 - removed en-us from URLs
 - added BP logs to deployment template
 - added log samples - raw is data from the API call, formatted is what is used to push to Sentinel
 - added approprtiate files to the zip archive
 - functionapp.json--
 - removed Preview from the title
 - added preview to the availability section
 --deploy.json--
 - removed "description" tag from the boolean variables
 - fixed typos in the descriptions
 - fixed alignment of paramaters
 - added new resources to capture function, resource groups, subscriptionid for writing to the evironment variables
 - added 3 new variables for LastLogtTime per product
 --run.ps1 changes--
 - added new variables to take read environment variables
 - added new function SetLastLogTime. This function stamps the new startdate to be used on the next run of the script. This was done to satisfy the case where if the script failed to run there would be no gap in the logs vs relying on the timer function
 - added UserAgent Strings
 - moved startdate into if statements per product to read the latest time in the respective variables
 - added varaiables to be populated if the API call was successfule, used in the function above to signal a new startdate should be populated
 - call the function last as it resets the current app session
 --zip file--
 - created new zip with updated app
 - added version of powershell progamatically to the UA String
 - per product UA strings
 - Set the the first run start-date once
 - moved to per product startdate variables
 - modified queries to use per-product startdates
 - Update agari.zip

* Update Agari_API_FunctionApp.json

-Updated instructions for additonal steps around permissions to make both the automated and manual deployments have the correct permissions.
-added BP logs to the query section

* Updated additonal instructions and samples

Cleaned up the instructions further
added samples in json format
removed old zip samples

* Updated role type

Changed text to Contirbutor vs owner

* Update azuredeploy_Agari_API_FunctionApp.json

Updated as per guidance from @nazang

* Update azuredeploy_Agari_API_FunctionApp.json

- Added the ?raw=true to the link.

* Update Agari_API_FunctionApp.json

@nazang I'll need a shortened link for the FunctionAPP.json as well

* Links and Logo Update

- added short links to json files
- added Agari logo
2020-11-23 10:39:25 -08:00
cbiguet 0b3c43deb1
Adding Onapsis Connector and Workbook (#1303)
* Adding Onapsis Connector and Workbook

* Applying proposed changes

Co-authored-by: Constantin Biguet <ext_cbiguet@onapsis.com>
Co-authored-by: Shain <45466083+shainw@users.noreply.github.com>
Co-authored-by: Nan Zang <nazang@microsoft.com>
2020-11-19 20:24:52 -08:00
SOC Prime e4d2a7a670
Salesforce Service Cloud Connector (#1292)
* saleforce sc connector - initial commit

* salesforce sc - added python file

* salesforce sc - updated zip file

* salesforce sc - updated connector template

* salesforce sc - added logo

* Salesforce SC: delete Preview

* Salesforce SC: change chunksize

* Salesforce SC: add proxies.json

* Salesforce SC: add handling of nextRecordsUrl

* Salesforce SC: update zip file

Co-authored-by: Alex Verbniak <ov@socprime.com>
2020-11-16 19:31:20 -08:00
Mike 9ad5ea9a2d
Updated Trend Micro logo for the data connectors (#1321)
* Create Trend_Micro_Logo.svg

* Update Trend_Micro_Logo.svg
2020-11-16 18:26:48 -08:00
Andrey Nikolaev b17aebb52d
Thycotic (#1144)
* Add new data connector

* Add example source data for ThycoticCEF dataconnector.
Add logo for dataconnector.

* Add workbook for Thycotic.

* Add workbook for Thycotic Secret Server.

* Add preview for Thycotic workbook

* Fix bug

* Add Thycotic dashboard and preview images and logo.

* Fix name dataconnector

* Add newline to json file

* Change workbook name in template

* Back file

* Add to Dashboard new block for event 'Login Failure'

* Change TemplateId

* Change link to base documentation for Secret Server

* Change link to documentation for configure Secret Server Syslog

* Changed data connector for Thycotic Secret Server

* Change Workbook , query add params

* Change format logo

* Add change to meta file

* Modify

* Update Logo for Dashboard, Dataconnector and Workbook

* Modify meta file

* Reset changes

* Reset Meta data

* Change meta file

* Change Logo for Thycotic

* Review image and changes Logo

Co-authored-by: unknown <andy@andy-nb.softwarium.net>
2020-11-13 15:15:49 -08:00
Aymen Ibrahim 50a7593ca2
Added BETTER MTD logo 2020-10-13 23:00:47 +04:00