Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new workflow for Trellix HX #273

Open
wants to merge 59 commits into
base: master
Choose a base branch
from
Open

Conversation

M-Shabrawy
Copy link

@M-Shabrawy M-Shabrawy commented Dec 22, 2024

Workflow to pull alerts and events from Trellix HX solution and related modules through REST API, which provides more details from the normal CEF formatted SYSLOG alert notifications.

Signed-off-by: Mohamed Al-Shabrawy <@M-Shabrawy>

M-Shabrawy and others added 30 commits February 10, 2022 00:44
correcting Offset to offset (caused infinite loop)
…l to Community Developed/FireEye HX/FireEye-HX-Alert_Groups-Workflow-Parameter-Value.xml

Move to new folder structure
…eveloped/FireEye HX/FireEye-HX-Alert_Groups-Workflow.xml

Move to new folder structure
…ommunity Developed/FireEye HX/FireEye-HX-Alerts-Workflow-Parameter-Value.xml

Move to new folder structure
…ed/FireEye HX/FireEye-HX-Alerts-Workflow.xml

Move to new folder structure
Adding Insecure parameter to all Endpoint calls to control allowUntrustedServerCertificate
Added ignore_selfsigned_certificate parameter
Update version
Update version information
Indentation and adding allowUntrustedServerCertificate control
Added ignore_selfsigned_certificate parameter
M-Shabrawy and others added 29 commits February 3, 2023 17:56
Update brand name to Trellix
…-Workflow.xml

- Updated file name to reflect brand name change.
- Remove the use of Bypass SSL, as it's now part of DSM configuration.
- Update variable names
Removed Ignore Self-Signed Certificate parameter
…l to FireEye-Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml

Updated to use the new brand name and removed ignore self-signed certificate
…s-Workflow.xml

Updated to reflect new brand name
Removed ignore self-signed certificate, and update variable naming style
Updated bookmark update section
Changing FE to Trellix and added logging
Added Process Tracker workflow information
Update workflow logic to count for non-linear Event IDs
…low.xml to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml

Reorganization
…low-Parameter-Value.xml to Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml

Reorganization
…to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml

Reorganization
…meter-Value.xml to Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml

Reorganization
…w.xml to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml

Reorganization
…-Workflow-Parameter-Value.xml to Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml

Reorganization
Updated descriptions
- minor bugs
Signed-off-by: Mohamed Al-Shabrawy <@M-Shabrawy>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant