..
AS_Alert_Spiderfoot_Scan
Add files via upload
2021-05-04 14:18:22 -07:00
Advanced-SNOW-Teams-Integration
Fixed Azure Deploy Button
2021-04-29 11:35:22 -07:00
Aggregate-SNOW-tickets
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
AutoConnect-ASCSubscriptions
ASC readme update fix (No local links)
2020-10-01 11:42:53 +03:00
AzureFirewall
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
Block-AADUser
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
Block-ExchangeIP
Update readme.md
2020-03-04 18:44:53 +01:00
Block-IPs-on-MDATP-Using-GraphSecurity
Update approval email message to High Importance
2020-04-27 11:03:18 -07:00
Block-OnPremADUser
Readme update
2021-03-10 11:54:07 +03:00
CarbonBlack
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
Change-Incident-Severity
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
CiscoASA
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
CiscoFirepower
remove local doc
2021-05-18 14:59:12 +03:00
Close-Incident-ASCAlert
Merge pull request #506 from swiftsolves-msft/nateswi_playbook
2020-02-27 08:56:52 -05:00
Close-Incident-MCAS
Added Deploy to Azure button, change name of json to reflect it.
2021-02-15 13:52:06 +00:00
Close-SentinelIncident-fromSNOW
commit
2020-09-15 11:40:39 +03:00
Comment-OriginAlertURL
Added Readme file
2020-04-22 15:13:01 -07:00
Comment-RemediationSteps
Create readme.md
2021-02-03 16:53:08 -08:00
Confirm-AADRiskyUser
fixed schema
2020-06-12 14:47:21 +00:00
Create-AzureDevOpsTask
readme for the Create-AzureDevOpsTask playbook
2020-04-15 13:55:04 +02:00
Create-AzureSnapshot
Add entities to identify VM
2020-10-21 20:58:46 +02:00
Create-IBMResilientIncident
initial
2020-02-28 11:48:23 -05:00
CrowdStrike
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
Defender-Intel-Action-RiskIQ-Intel-Article-Ingest
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Dismiss-AADRiskyUser
Fixing Typo in Dismiss-Riskyuser
2020-07-26 09:13:55 -07:00
Dismiss_Upstream_Events
New playbook created to dismiss upstream events.
2020-08-25 14:25:35 +01:00
Edgescan-AzureSentinel-Integration
Delete azuredeploy1.json
2020-12-03 21:09:17 -08:00
Enrich-Sentinel-Incident-HYAS-Insight-Domain-Current-WHOIS
remove en-us in the links
2020-11-27 12:12:48 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-Domain-Historic-WHOIS
remove en-us in the links
2020-11-27 12:14:13 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-Domain-Passive-DNS
remove en-us in the links
2020-11-27 12:14:48 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-Email-Dynamic-DNS
removed typo
2020-11-27 12:31:22 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-Email-Historic-WHOIS
remove en-us in the links
2020-11-27 12:15:46 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IP-Dynamic-DNS
remove en-us in the links
2020-11-27 12:16:16 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IP-Passive-DNS
remove en-us in the links
2020-11-27 12:16:52 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IP-Passive-Hash
remove en-us in the links
2020-11-27 12:17:24 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IP-SSL-Certificate
remove en-us in the links
2020-11-27 12:17:51 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IP-Sinkhole
remove en-us in the links
2020-11-27 12:18:28 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IPv4-Device-Geo
remove en-us in the links
2020-11-27 12:18:53 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-IPv6-Device-Geo
remove en-us in the links
2020-11-27 12:19:16 +05:30
Enrich-Sentinel-Incident-HYAS-Insight-Phone-Number-Historic-WHOIS
remove en-us in the links
2020-11-27 12:19:42 +05:30
Enrich-SentinelIncident-GreyNoise-IP
Update readme.md
2021-03-24 22:33:36 -04:00
Enrich-SentinelIncident-GreyNoiseCommunity-IP
Update readme.md
2021-04-08 09:58:52 -04:00
Enrich-SentinelIncident-MDATPTVM
Update azuredeploy.json
2020-04-14 22:57:47 +03:00
Enrich-SentinelIncident-ReversingLabs-File-Information
Remove docs langauge specifier
2021-03-03 15:54:50 +01:00
Enrich-SentinelIncident-RiskIQ-Host-Passive-DNS
Updated playbooks to account for bug in LogicApps
2020-07-17 17:35:59 -04:00
Enrich-SentinelIncident-RiskIQ-Host-SSL-Certificate
Updated playbooks to account for bug in LogicApps
2020-07-17 17:35:59 -04:00
Enrich-SentinelIncident-RiskIQ-Host-WHOIS
Officially tested the deployment process end-to-end.
2020-06-18 09:59:44 -04:00
Enrich-SentinelIncident-RiskIQ-IP-Passive-DNS
Updated playbooks to account for bug in LogicApps
2020-07-17 17:35:59 -04:00
Enrich-SentinelIncident-RiskIQ-IP-SSL-Certificate
Updated playbooks to account for bug in LogicApps
2020-07-17 17:35:59 -04:00
Enrich-SentinelIncident-RiskIQ-Summary
Officially tested the deployment process end-to-end.
2020-06-18 09:59:44 -04:00
Enrich-SentinelIncident-RiskIQ-Summary-Host
Officially tested the deployment process end-to-end.
2020-06-18 09:59:44 -04:00
Enrich-SentinelIncident-RiskIQ-Summary-IP
Officially tested the deployment process end-to-end.
2020-06-18 09:59:44 -04:00
Export-Incidents-With-Comments
Updated readme. Added link to guide.
2020-08-25 14:25:12 +01:00
Fortinet-FortiGate
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
Get-ASCRecommendations
Initial Playbook ( #537 )
2020-03-26 17:55:13 -07:00
Get-AlertEntitiesEnrichment
Fix custom template deployment (button) links
2021-05-17 15:59:16 +01:00
Get-AlienVault_OTX
Update to correct template input button and major revision to the logic app
2020-11-19 17:34:49 -06:00
Get-CompromisedPasswords
Update azuredeploy.json
2021-02-01 13:34:28 -08:00
Get-GeoFromIPandTagIncident-EmailAlertBasedonGeo
Update azuredeploy.json
2020-12-24 00:59:14 -05:00
Get-GeoFromIpAndTagIncident
fixes #909
2020-07-31 11:05:29 +02:00
Get-IPReputation
Fixed a VT Schema change.
2020-11-11 12:07:41 -05:00
Get-MDATPInvestigationPackage
Fixed ARMTemplate
2020-12-03 21:46:44 -08:00
Get-MDATPVulnerabilities
Fixed readme title
2020-04-30 07:29:35 +08:00
Get-MDEFileActivityWithin30Mins
add deploy to azure and deploy to azure gov buttons
2021-02-28 13:19:23 -05:00
Get-MDEProcessActivityWithin30Mins
new playbook - initial work
2021-03-05 21:42:09 -05:00
Get-MachineData-EDR-SOAR-ActionsOnMachine
Update README.md
2021-01-06 14:26:47 +08:00
Get-MerakiData-ConfigurationChanges
Removed fromTemplateId
2021-05-04 10:34:05 -05:00
Get-MerakiData-OrgSecurityEvents
Removed fromTemplateId
2021-05-04 10:34:10 -05:00
Get-Microsoft-Covid19-Indicators
change image path
2021-03-16 15:54:51 -07:00
Get-O365Data
fixes to addonguid
2020-05-16 00:14:21 +00:00
Get-ProofPointTapEvents
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
Get-Recipients-EmailMessageID-containing-URL
included fixes for arm template where connector name was wrong
2021-03-09 14:43:46 -05:00
Get-SOCActions
Update Get-SOCActions.json
2021-05-11 11:31:48 -06:00
Get-SentinelAlertsEvidence
Update readme.md
2020-06-11 19:36:52 +03:00
Get-TenableVlun
Update azuredeploy.json
2021-04-29 16:57:17 +03:00
Get-VTURLPositivesComment
further apikey fixes
2021-03-09 17:10:27 -05:00
Get-VirusTotalFileInfo
Get-VirusTotalFileInfo
2021-03-17 16:27:10 +00:00
Get-VirusTotalURLAnalyses
fix-resource-name
2021-04-03 15:16:25 +13:00
Guardicore-Import-Assets
updated deploy links
2020-09-28 14:33:26 -07:00
Guardicore-Import-Incidents
updated deploy links
2020-09-28 14:36:56 -07:00
Guardicore-ThreatIntel
Minor fixes for nullable fields from Guardicore ThreatIntel feed
2021-02-02 09:46:42 +11:00
HaveIBeenPwned-Email
Update readme.md
2021-01-26 10:40:02 -05:00
IdentityProtection-EmailResponse
Update readme.md
2020-10-07 17:46:51 -07:00
IdentityProtection-TeamsBotResponse
Update readme.md
2020-10-07 17:48:16 -07:00
Incident-Assignment-Shifts
Update readme.md
2021-04-27 16:10:41 +10:00
Incident-Email-Notification
Update azuredeploy.json
2021-05-18 14:25:53 +10:00
Incident-Status-Sync-To-WDATP
Just adding Author name
2021-01-27 07:59:41 +01:00
Ingest-CanaryTokens
txt to yaml
2020-12-07 16:01:14 -05:00
Ingest-Prisma
Update readme.md
2020-10-01 12:27:42 -03:00
Isolate-AzureStorageAccount
Changed concurrency to 1 for the foreach loop setting storageid variable
2020-06-18 09:09:45 -04:00
Isolate-AzureVMtoNSG
added depends on
2020-03-19 10:04:20 -04:00
Isolate-MDATPMachine
Update to use MDATPDeviceID
2020-08-24 08:53:27 -07:00
Move-LogAnalytics-to-Storage
Change date, using old testing date
2020-06-18 14:27:50 -04:00
Notify-ASCAlertAzureResource
Updates to Notify playbook
2020-03-08 15:05:20 -04:00
Okta
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
OktaRawLog
fix connection issue
2020-05-15 16:24:21 +00:00
Open-JIRA-Ticket
Fixes due to connector bug ( #647 )
2020-05-07 10:53:15 -07:00
Open-SNOW-Ticket
open-SNOW
2020-08-14 16:18:39 +03:00
Open-ServiceDeskPlusOnDemand-Ticket
Bug fix. Added dependsOn node.
2020-08-25 14:23:56 +01:00
Open-Zendesk-Ticket
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
PaloAlto-PAN-OS
New connectors+playbooks ( #2118 )
2021-04-26 11:30:21 -07:00
Post-Message-Slack
fix bug
2020-04-07 08:08:58 -04:00
Post-Message-Teams
Fixing ARM Template
2020-07-21 16:35:30 -04:00
Post-Tags-And-Comments-To-Your-IntSights-Account
Update parameters and api routes
2021-01-20 13:07:16 +02:00
Prompt-User
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
RecordedFuture-Block-IPs-and-Domains-on-Microsoft-Defender-for-Endpoint
Add files via upload
2021-05-18 14:08:35 +01:00
RecordedFuture_C2_Malware_Detect
Update RecordedFuture_C2_Malware_Detection_IndicatorProcessor.json
2021-05-05 18:05:27 +01:00
RecordedFuture_COVID19_Related_Domain_Lure_Detect
Update RecordedFuture_COVID19_Related_Domain_Lure_IndicatorProcessor.json
2021-05-05 18:03:37 +01:00
RecordedFuture_Dom_C2_DNS_Name
Update RecordedFuture_Dom_C2_DNS_Name_IndicatorProcessor.json
2021-05-05 18:04:20 +01:00
RecordedFuture_Generic_Detection
Update RecordedFuture_Generic_Detection_IndicatorProcessor.json
2021-05-05 18:04:50 +01:00
RecordedFuture_IOC_Enrichment
Add files via upload
2021-04-26 10:23:23 +01:00
RecordedFuture_IP_ActCommC2C
Update RecordedFuture_IP_ActCommC2C_IndicatorProcessor.json
2021-05-05 18:05:47 +01:00
RecordedFuture_IP_Enrichment
Add files via upload
2020-11-26 12:39:55 +00:00
RecordedFuture_IP_SCF
Update RecordedFuture_IP_SCF_IndicatorProcessor.json
2021-05-05 18:06:13 +01:00
Reset-AADUserPassword
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
Resolve-McasInfrequentCountryAlerts
Update readme.md
2020-09-10 11:40:01 +02:00
Restrict-MDATPAppExectution
Update to use MDATPDeviceID
2020-08-24 08:53:27 -07:00
Restrict-MDATPDomain
Restrict-MDATPDomain ( #652 )
2020-05-07 13:10:06 -07:00
Restrict-MDATPFileHash
Restrict-MDATPFileHash ( #653 )
2020-05-07 13:48:49 -07:00
Restrict-MDATPIPAddress
Update azuredeploy.json
2020-05-13 13:28:43 -04:00
Restrict-MDATPUrl
Update readme.md
2020-09-23 15:05:00 -04:00
Revoke-AADSignInSessions
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
Run-AzureVMPacketCapture
New Playbook - Run-AzureVMPacketCapture
2020-03-18 21:23:03 -04:00
Run-MDATPAntivirus
Bug fix for Run-MDATPAntivirus
2020-08-13 14:28:15 -07:00
Save-NamedLocations
Update Azure Deploy URL
2020-11-21 14:50:42 +01:00
Send-ConnectorHealthStatus
Updated readme
2020-12-14 22:21:31 +03:00
Send-IngestionCostAlert
Updated images
2021-05-07 11:22:38 +03:00
Send-UrlReport
Fixing Playbook Deploy URLs
2020-02-24 10:06:59 -05:00
Sentinel-Incident-Action-RiskIQ-Reputation-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Action-RiskIQ-Reputation-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Action-RiskIQ-Reputation-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-PassiveDns-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-PassiveDns-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-PassiveDns-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Summary-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Summary-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Summary-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Whois-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Whois-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Data-Whois-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Intel-Summary-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Intel-Summary-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Intel-Summary-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Reputation-Summary-All
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Reputation-Summary-Domain
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Incident-Enrich-RiskIQ-Reputation-Summary-IP
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sentinel-Intel-Action-RiskIQ-Intel-Article-Ingest
Updated RiskIQ playbooks.
2021-04-09 08:32:54 -04:00
Sync-IncidentsWithJIRA
Change folder names & add deploy buttons
2021-04-06 17:39:45 +02:00
TritonDetectionAndResponse
Triton Playbook Fixes
2020-12-14 16:04:26 +02:00
Update-BulkIncidents
changes
2020-08-21 12:01:14 -04:00
Update-NamedLocations-TOR
Update azuredeploy.json
2021-01-05 08:27:23 -08:00
Update-Watchlist-With-NamedLocation
Update Readme.md
2021-05-10 09:57:14 +02:00
Watchlist-Add-HostToWatchList
4 new watchlist playbooks
2021-01-27 08:44:01 +02:00
Watchlist-Add-IPToWatchList
4 new watchlist playbooks
2021-01-27 08:44:01 +02:00
Watchlist-Add-URLToWatchList
4 new watchlist playbooks
2021-01-27 08:44:01 +02:00
Watchlist-Add-UserToWatchList
4 new watchlist playbooks
2021-01-27 08:44:01 +02:00
Watchlist-ChangeIncidentSeverityandTitleIFUserVIP
logicapp watchlist update incident
2020-10-27 18:32:13 +02:00
Watchlist-CloseIncidentKnownIPs
Merge pull request #1196 from Azure/lior
2020-10-26 21:47:00 +02:00
Watchlist-InformSubowner-IncidentTrigger
Fix Watchlists-InformSubOwner
2020-11-08 18:43:20 +02:00
Watchlist-SendSQLData-Watchlist
commit
2020-11-19 21:39:35 +02:00
Zscaler-add-Domains-to-URL-Category
Update README.md
2020-09-28 14:29:28 -07:00
ReadMe.md
Update ReadMe.md
2020-10-22 13:47:02 +13:00
logic_app_logo.png
Add files via upload
2020-10-21 16:37:03 +13:00