GithubHelp home page GithubHelp logo

hartl3y94 / content-1 Goto Github PK

View Code? Open in Web Editor NEW

This project forked from demisto/content

0.0 0.0 0.0 552 MB

Demisto is now Cortex XSOAR. Automate and orchestrate your Security Operations with Cortex XSOAR's ever-growing Content Repository. Pull Requests are always welcome and highly appreciated!

Home Page: https://xsoar.pan.dev/

License: MIT License

Shell 0.23% JavaScript 3.41% Python 93.93% PowerShell 0.93% HTML 0.45% Dockerfile 0.01% YARA 0.01% Rich Text Format 1.04%

content-1's Introduction

Content logo

CircleCI Language grade: Python Open in Visual Studio Code

Open in Remote - Containers

If you already have VS Code and Docker installed, you can click the badge above or here to get started. Clicking these links causes VS Code to automatically install the Remote - Containers extension (if needed), clone the source code into a container volume, and spin up a development container for use.

Cortex XSOAR Platform - Content Repository

Demisto is now Cortex XSOAR.

This repo contains content provided by Demisto to automate and orchestrate your Security Operations. Here we will share our ever-growing list of playbooks, automation scripts, report templates and other useful content.

We security folks love to tinker, keep enhancing and sharpening our toolset and we decided to open up everything and make it a collaborative process for the entire security community. We want to create useful knowledge and build flexible, customizable tools, sharing them with each other as we go along.

We invite you to use the playbooks and scripts, modify them to suit your needs and see what works for you, get involved in the community discussion and of course remember to give back and contribute so that others can enjoy and learn from your hard work and build upon it to enhance it even further.

Documentation

If you wish to develop and contribute Content, make sure to check our Content Developer Portal at: https://xsoar.pan.dev/

Contributing

Contributions are welcome and appreciated. For instructions about adding/modifying content please see our Content Contribution Guide.

Playbooks

The Cortex XSOAR Platform includes a visual playbook editor - you can add and modify tasks, create control flow according to answers returned by your queries, and automate everything with your existing security tools, services and products. You can also export your work to a file in the COPS format, and import playbooks shared by your peers who have done the same.

We will be releasing more and more playbooks for interesting scenarios, so stay tuned. If you are working on an interesting playbook of your own, feel free to send us a Pull Request and let's build it together.

The spec for our open playbook format, COPS, can be found here.

Scripts

These scripts written in Python or Javascript perform Security Operations tasks. The scripts are built to run inside the Cortex XSOAR Platform - they can query or send commands to a long list of existing security products, and react based on the output.

You can take your logic and the way you want to work and write your own scripts, allowing for maximum flexibility. The services and products you use can be online Cloud-based or on-premises setups, and we have tools to support more complex topologies such as when the product's subnet is firewalled off.

Integrations

Integrations written in Javascript or Python enable the Cortex XSOAR Platform to orchestrate security and IT products. Each integration provides capabilities in the form of commands and each command usually reflects a product capability (API) and returns both a human readable and computer readable response.

Docker

We use docker to run python scripts and integrations in a controlled environment. You can configure an existing docker image from the Cortex XSOAR Docker Hub Organization or create a new docker image to suite your needs. More information about how to use Docker is available here.

Reports

Cortex XSOAR Platform support flexible reports written in JSON. All of our standard reports calculating various incident statistics and metrics are stored in this repo.


Enjoy and feel free to reach out to us on the DFIR Community Slack channel.

content-1's People

Contributors

adi88d avatar amshamah419 avatar avidan-h avatar bakatzir avatar barchen1 avatar content-bot avatar dantavori avatar deanarbel avatar dorsha avatar glicht avatar guydemi avatar idovandijk avatar ikademisto avatar itay4 avatar jochman avatar kirbles19 avatar liorblob avatar liorkol avatar meirwah avatar orenzohar avatar orlichter1 avatar reutshal avatar ronykoz avatar roysagi avatar shahafbenyakir avatar shaniacht1 avatar shellyber avatar slavikm avatar teizenman avatar yaakovi avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.