Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ability to execute active response on any element of TheHive #609

Closed
To-om opened this issue Jun 12, 2018 · 3 comments
Closed

Ability to execute active response on any element of TheHive #609

To-om opened this issue Jun 12, 2018 · 3 comments

Comments

@To-om
Copy link
Contributor

To-om commented Jun 12, 2018

Request Type

Feature Request

Description

The aim of this feature request is to add the ability to execute action (send an email, create a request on a ticketing system, ...) from any element of TheHive (case, task, alert, ...).
Similarly to analyzers, theses action are executed on Cortex but they don't generate report.

@To-om To-om added this to the 3.1.0 (Cerana 1) milestone Jun 12, 2018
@To-om To-om self-assigned this Jun 12, 2018
To-om added a commit that referenced this issue Jun 12, 2018
@saadkadhi
Copy link
Contributor

@To-om Well hopefully while a report is not warranted, a success/failure/manual check needed status is a requirement :)

@To-om
Copy link
Contributor Author

To-om commented Jun 12, 2018

Actions haven't a report (so no need report templates) but they have a status, of course.

@saadkadhi saadkadhi modified the milestone: 3.1.0 (Cerana 1) Jun 13, 2018
@crackytsi
Copy link

Actually I was a little surprised that all Topics were removed from the milestones and even the milestones that introduce e.g. migration to GraphDB disappeared.
I think your decision to implement this feature is really good and I support it, hopefully this does not mean that all the other teams are no longer planned.

A few comments from operation side:
I currently use custom-fields that "autorest" with webooks e.g. to implement functions like "Export all cases as CSV file" or to have reports.
So for me, it would be very helpfull
a) If also in Dashboards there would be a "active-respose" e.g. to implemente a generate a PDF from dashboar function can be implemented
b) If the result/status could also be a HTML supporting field. e.g. to offer an option to download a case/CSV Export of all cases etc.
c) Being able to understand what user executes an active response, e.g. to send the user a email with requested data.

Of course this is only my very limited view based on my usecases, but maybe they help/inspire you ;)
Best wishes, + Thanks for all your doing!!! Chris

To-om added a commit that referenced this issue Jul 6, 2018
To-om added a commit that referenced this issue Jul 9, 2018
To-om added a commit that referenced this issue Jul 11, 2018
To-om added a commit that referenced this issue Jul 11, 2018
nadouani added a commit that referenced this issue Jul 12, 2018
nadouani added a commit that referenced this issue Jul 13, 2018
nadouani added a commit that referenced this issue Jul 19, 2018
nadouani added a commit that referenced this issue Jul 23, 2018
To-om added a commit that referenced this issue Jul 26, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants