Parse Sane-json-reports and export them as pdf files (used internally).
Base
- Details
- Content
- Dependencies
- Version History
The base pack for Cortex XSOAR.
Name | Description |
---|---|
SanePdfReports | |
DeleteIndicatorRelationships | This automation allows to delete a relationship between indicator objects based on the relationship id. |
HighlightWords | Highlight words inside a given text. |
DrawRelatedIncidentsCanvas | Draw incidents and indicators on the canvas to map and visualize their connections. |
CommonServerPowerShell | Common code that will be merged into each PowerShell script/integration when it runs. |
SaneDocReports | Parse Sane-json-reports and export them as docx files (used internally). |
StixParser | Parse STIX files to Cortex XSOAR indicators by clicking the Upload STIX File button. |
DBotSuggestClassifierMapping | Deprecated. No available replacement. Suggests a classifier mapping based on an advanced name matching algorithm. |
DBotShowClusteringModelInfo | Show clustering model information - model summary and incidents in specific cluster. |
SearchIndicatorRelationships | This automation outputs the indicator relationships to context according to the provided query, using the entities, entityTypes, and relationships arguments. All arguments will use the AND operator. For example, using the following arguments entities=8.8.8.8 entities_types=Domain will provide only relationships that the 8.8.8.8 indicator has with indicators of type domain. |
GetIndicatorsByQuery | Gets a list of indicator objects and the associated indicator outputs that match the specified query and filters. The results are returned in a structured data file. |
DBotBuildPhishingClassifier | Create a phishing classifier using machine learning technique, based on email content. |
DBotPreProcessTextData | Pre-process text data for the machine learning text classifier. |
DBotFindSimilarIncidents | Finds past similar incidents based on incident fields' similarity. Includes an option to also display indicators similarity. |
WordTokenizerNLP | Deprecated. Use DBotPreProcessTextData instead. |
DBotTrainClustering | This script helps organizes and groups incidents based on their similarities using clustering algorithms. |
FindSimilarIncidentsByText | Deprecated. Use DBotFindSimilarIncidents instead. This automation runs using the default Limited User role, unless you explicitly
|
CommonServer | Common code that will be merged into each server script when it runs. |
GetMLModelEvaluation | Finds a threshold for ML model, and performs an evaluation based on it. |
DBotFindSimilarIncidentsByIndicators | Finds similar incidents based on indicators' similarity. Indicators' contribution to the final score is based on their scarcity. |
ValidateContent | Runs validation and linting using the Demisto SDK on content items, such as integrations, automations and content packs. This automation script is used as part of the content validation that runs as part of the contribution flow. |
GetIncidentsByQuery | Gets a list of incident objects and the associated incident outputs that This automation runs using the default Limited User role, unless you explicitly change the permissions.
|
DBotPredictPhishingWords | Predict text label using a pre-trained machine learning phishing model, and get the most important words used in the classification decision. |
DBotMLFetchData | Deprecated. No available replacement. Collect telemetry data from the environment. |
CreateIndicatorRelationship | This automation creates a relationship between indicator objects. |
CheckDockerImageAvailable | Check if a docker image is available for performing docker pull. Script simulates the docker pull flow but doesn't actually pull the image. Returns an entry with 'ok' if all is good otherwise will return an error. |
CommonServerPython | Common code that will be merged into each server script when it runs. |
DBotTrainTextClassifierV2 | Train a machine learning text classifier. |
Name | Description |
---|---|
System Health |
Name | Description |
---|---|
CommonServerPowerShell | Common code that will be merged into each PowerShell script/integration when it runs. |
SanePdfReports | Parse Sane-json-reports and export them as pdf files (used internally). |
WordTokenizerNLP | Deprecated. Use DBotPreProcessTextData instead. |
CommonServerPython | Common code that will be merged into each server script when it runs. |
CheckDockerImageAvailable | Check if a docker image is available for performing docker pull. Script simulates the docker pull flow but doesn't actually pull the image. Returns an entry with 'ok' if all is good otherwise will return an error. |
SearchIndicatorRelationships | This automation outputs the indicator relationships to context according to the provided query, using the entities, entityTypes, and relationships arguments. All arguments will use the AND operator. For example, using the following arguments entities=8.8.8.8 entities_types=Domain will provide only relationships that the 8.8.8.8 indicator has with indicators of type domain. |
FindSimilarIncidentsByText | Deprecated. Use DBotFindSimilarIncidents instead. This automation runs using the default Limited User role, unless you explicitly
|
FindSimilarAlertsByText | Deprecated. Use DBotFindSimilarAlerts instead. This automation runs using the default Limited User role, unless you explicitly
|
CommonServer | Common code that will be merged into each server script when it runs. |
DBotBuildPhishingClassifier | Create a phishing classifier using machine learning technique, based on email content. |
GetMLModelEvaluation | Finds a threshold for ML model, and performs an evaluation based on it. |
DeleteIndicatorRelationships | This automation allows to delete a relationship between indicator objects based on the relationship id. |
DBotFindSimilarIncidents | Finds past similar incidents based on incident fields' similarity. Includes an option to also display indicators similarity. |
DBotFindSimilarAlerts | Finds past similar alerts based on alert fields' similarity. Includes an option to also display indicators similarity. |
SaneDocReports | Parse Sane-json-reports and export them as docx files (used internally). |
DBotFindSimilarIncidentsByIndicators | Finds similar incidents based on indicators' similarity. Indicators' contribution to the final score is based on their scarcity. |
DBotFindSimilarAlertsByIndicators | Finds similar alerts based on indicators' similarity. Indicators' contribution to the final score is based on their scarcity. |
GetIncidentsByQuery | Gets a list of incident objects and the associated incident outputs that This automation runs using the default Limited User role, unless you explicitly change the permissions.
|
GetAlertsByQuery | Gets a list of alert objects and the associated alert outputs that This automation runs using the default Limited User role, unless you explicitly change the permissions.
|
HighlightWords | Highlight words inside a given text. |
DBotMLFetchData | Deprecated. No available replacement. Collect telemetry data from the environment. |
CreateIndicatorRelationship | This automation creates a relationship between indicator objects. |
DBotSuggestClassifierMapping | Deprecated. No available replacement. Suggests a classifier mapping based on an advanced name matching algorithm. |
GetIndicatorsByQuery | Gets a list of indicator objects and the associated indicator outputs that match the specified query and filters. The results are returned in a structured data file. |
StixParser | Parse STIX files to Cortex indicators by clicking the Upload STIX File button. |
DBotTrainClustering | This script helps organizes and groups incidents based on their similarities using clustering algorithms. |
DBotPreProcessTextData | Pre-process text data for the machine learning text classifier. |
ValidateContent | Runs validation and linting using the Demisto SDK on content items, such as integrations, automations and content packs. This automation script is used as part of the content validation that runs as part of the contribution flow. |
Pack Name | Pack By |
---|
Pack Name | Pack By |
---|
Pack Name | Pack By |
---|
Scripts
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
- 37950
Download
Scripts
CommonServerPython
- Fixed an issue where the new decorator for debugging purposes failed to retrieve the result file from scripts that timeout.
- Added the Tactic indicator object.
FindSimilarIncidentsByText
- Documentation and metadata improvements.
GetIncidentsByQuery
- Documentation and metadata improvements.
- Updated the Docker image to: demisto/python3:3.11.10.116949.
CreateIndicatorRelationship
- Documentation and metadata improvements.
- Updated the Docker image to: demisto/python3:3.11.10.116949.
- 37760
Download
Scripts
CommonServerPython
- Added the is_integration_instance_running_on_engine function which determines whether the current integration instance
runs on an xsoar engine. - Added the get_engine_base_url function which gets an engine ID and returns its base URL.
- Reverted the logging changes in the Demisto class merthods.
- 37538
Download
Scripts
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.105874.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.105874.
CommonServerPowerShell
- Updated the Docker image to: demisto/powershell:7.4.2.103657.
- 37214
- 37193
Download
Scripts
SearchIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.115186.
GetIndicatorsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.115186.
GetIncidentsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.115186.
HighlightWords
- Updated the Docker image to: demisto/python3:3.11.10.115186.
CheckDockerImageAvailable
- Updated the Docker image to: demisto/python3:3.11.10.115186.
- 37147
- 37137
- 37136
- 37140
- 37138
- 37139
Download
Scripts
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.112949.
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.112949.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.112949.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.112949.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.112949.
- 37162
- 37154
Download
Scripts
GetIncidentsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.113941.
GetIndicatorsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.113941.
CreateIndicatorRelationship
- Updated the Docker image to: demisto/python3:3.11.10.113941.
DBotShowClusteringModelInfo
- Updated the Docker image to: demisto/python3:3.11.10.113941.
CheckDockerImageAvailable
- Updated the Docker image to: demisto/python3:3.11.10.113941.
DeleteIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.113941.
SearchIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.113941.
DBotBuildPhishingClassifier
- Updated the Docker image to: demisto/python3:3.11.10.113941.
HighlightWords
- Updated the Docker image to: demisto/python3:3.11.10.113941.
- 37006
- 36995
- 36994
- 36998
- 36993
- 36992
- 36997
Download
Scripts
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.105874.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.105874.
- 35708
- 35643
Download
Scripts
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.103517.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.103517.
- 35422
Download
Scripts
DBotTrainTextClassifierV2
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotBuildPhishingClassifier
- Changed the Docker image to: demisto/python3:3.11.9.101916.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotPredictPhishingWords
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.101889.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.101889.
- 35081
Download
Scripts
CommonServerPython
- Removed support for the DemistoWrapper class in python2 integrations and scripts. This fixes an issue where the following error was encountered for python2 integrations and scripts:
TypeError: super() argument 1 must be type, not classobj
- 35283
- 35343
Download
Scripts
DBotFindSimilarIncidentsByIndicators
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
DBotFindSimilarIncidents
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
GetIncidentsByQuery
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
- 35176
Download
Scripts
CommonServerPython
Fixed an issue which caused email enrichers to save results in the wrong context key. Email
key was changed to Account.Email
. This change might affect the following integrations which output Email indicators to context:
- Anomali Threat Stream V3
- Cofense Intelligence V2
- Eclectic IQ Intelligence Center V3
- Email Hippo
- IP Quality Score
- MISP V3
- Reversing Labs Titanium Cloud V2
- SEKOIA Intelligence Center
- Threat Zone
- VM Ray
- 34684
- 33924
Download
Scripts
ValidateContent
- Updated the Docker image to: demisto/xsoar-tools:1.0.0.90942.
- 33641
- 33516
- 33519
- 33515
- 33329
- 33314
- 33318
- 33328
- 33357
- 33344
- 33359
- 33458
- 33535
- 33534
- 33537
- 33552
- 33580
- 33553
- 33418
- 33583
- 33555
- 33556
- 33559
- 33560
- 33619
- 33591
- 33602
- 33600
- 33314
- 33318
- 33328
- 33357
- 33344
- 33359
- 33458
Download
Scripts
CommonServerPython
- Added ignore to sleep method to satisfy linters.
GetIncidentsByQuery
- Moved the implementation to GetIncidentsApiModule.
- The includeContext argument is now deprecated due to performance considerations. Rather than using this argument, it is recommended to retrieve the context of the incidents separately, preferably for a limited number of incidents.
- Updated the Docker image to: demisto/python3:3.10.13.87159.
DBotFindSimilarIncidentsByIndicators
- Internal code enhancements for improved performance.
- Updated the Docker image to: demisto/ml:1.0.0.88591.
DBotFindSimilarIncidents
- Internal code enhancements for improved performance.
- Updated the Docker image to: demisto/ml:1.0.0.88591.
- 33028
Download
Scripts
GetIndicatorsByQuery
- Added the
ALL
option to the populateFields in order to get all the populated fields available. - Updated the automation to always use the populateFields - This is a breaking change! Make sure the value of this field is suitable for you.
- Updated the Docker image to: demisto/python3:3.10.13.87159.
- 32879
Download
Scripts
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.1870375.
- 37950
Download
Scripts
CommonServerPython
- Fixed an issue where the new decorator for debugging purposes failed to retrieve the result file from scripts that timeout.
- Added the Tactic indicator object.
FindSimilarIncidentsByText
- Documentation and metadata improvements.
GetIncidentsByQuery
- Documentation and metadata improvements.
- Updated the Docker image to: demisto/python3:3.11.10.116949.
CreateIndicatorRelationship
- Documentation and metadata improvements.
- Updated the Docker image to: demisto/python3:3.11.10.116949.
- 37760
Download
Scripts
CommonServerPython
- Added the is_integration_instance_running_on_engine function which determines whether the current integration instance
runs on an xsoar engine. - Added the get_engine_base_url function which gets an engine ID and returns its base URL.
- Reverted the logging changes in the Demisto class merthods.
- 37538
Download
Scripts
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.105874.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.105874.
CommonServerPowerShell
- Updated the Docker image to: demisto/powershell:7.4.2.103657.
- 37214
- 37193
Download
Scripts
SearchIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.115186.
GetIndicatorsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.115186.
GetIncidentsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.115186.
HighlightWords
- Updated the Docker image to: demisto/python3:3.11.10.115186.
CheckDockerImageAvailable
- Updated the Docker image to: demisto/python3:3.11.10.115186.
- 37147
- 37137
- 37136
- 37140
- 37138
- 37139
Download
Scripts
GetIncidentsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.113941.
GetIndicatorsByQuery
- Updated the Docker image to: demisto/python3:3.11.10.113941.
CreateIndicatorRelationship
- Updated the Docker image to: demisto/python3:3.11.10.113941.
CheckDockerImageAvailable
- Updated the Docker image to: demisto/python3:3.11.10.113941.
DeleteIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.113941.
SearchIndicatorRelationships
- Updated the Docker image to: demisto/python3:3.11.10.113941.
DBotBuildPhishingClassifier
- Updated the Docker image to: demisto/python3:3.11.10.113941.
HighlightWords
- Updated the Docker image to: demisto/python3:3.11.10.113941.
- 37006
- 36995
- 36994
- 36998
- 36993
- 36992
- 36997
Download
Scripts
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.105874.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.105874.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.105874.
- 35643
- 35708
Download
Scripts
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.103517.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.103517.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.103517.
- 35422
Download
Scripts
DBotBuildPhishingClassifier
- Changed the Docker image to: demisto/python3:3.11.9.101916.
DBotPreProcessTextData
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotFindSimilarIncidents
- Updated the Docker image to: demisto/ml:1.0.0.101889.
GetMLModelEvaluation
- Updated the Docker image to: demisto/ml:1.0.0.101889.
DBotFindSimilarIncidentsByIndicators
- Updated the Docker image to: demisto/ml:1.0.0.101889.
- 35081
Download
Scripts
CommonServerPython
- Removed support for the DemistoWrapper class in python2 integrations and scripts. This fixes an issue where the following error was encountered for python2 integrations and scripts:
TypeError: super() argument 1 must be type, not classobj
- 35343
- 35283
Download
Scripts
DBotFindSimilarIncidentsByIndicators
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
DBotFindSimilarIncidents
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
GetIncidentsByQuery
- Fixed an issue where the populateFields argument didn't accept a pipe (|) as a separator.
- 35176
Download
Scripts
CommonServerPython
Fixed an issue which caused email enrichers to save results in the wrong context key. Email
key was changed to Account.Email
. This change might affect the following integrations which output Email indicators to context:
- Anomali Threat Stream V3
- Cofense Intelligence V2
- Eclectic IQ Intelligence Center V3
- Email Hippo
- IP Quality Score
- MISP V3
- Reversing Labs Titanium Cloud V2
- SEKOIA Intelligence Center
- Threat Zone
- VM Ray
- 33924
- 34684
Download
Scripts
ValidateContent
- Updated the Docker image to: demisto/xsoar-tools:1.0.0.90942.
- 33641
- 33516
- 33519
- 33515
- 33329
- 33314
- 33318
- 33328
- 33357
- 33344
- 33359
- 33458
- 33535
- 33534
- 33537
- 33552
- 33580
- 33553
- 33418
- 33583
- 33555
- 33556
- 33559
- 33560
- 33619
- 33591
- 33602
- 33600
- 33314
- 33318
- 33328
- 33357
- 33344
- 33359
- 33458
Download
Scripts
CommonServerPython
- Added ignore to sleep method to satisfy linters.
GetIncidentsByQuery
- Moved the implementation to GetIncidentsApiModule.
- The includeContext argument is now deprecated due to performance considerations. Rather than using this argument, it is recommended to retrieve the context of the incidents separately, preferably for a limited number of incidents.
- Updated the Docker image to: demisto/python3:3.10.13.87159.
DBotFindSimilarIncidentsByIndicators
- Internal code enhancements for improved performance.
- Updated the Docker image to: demisto/ml:1.0.0.88591.
DBotFindSimilarIncidents
- Internal code enhancements for improved performance.
- Updated the Docker image to: demisto/ml:1.0.0.88591.
- 33028
Download
Scripts
GetIndicatorsByQuery
- Added the
ALL
option to the populateFields in order to get all the populated fields available. - Updated the automation to always use the populateFields - This is a breaking change! Make sure the value of this field is suitable for you.
- Updated the Docker image to: demisto/python3:3.10.13.87159.
- 32879
Download
PUBLISHER
data:image/s3,"s3://crabby-images/cdaeb/cdaeb6108b9d10f4b2a563cfa6cce90a75e31b12" alt="Cortex"
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Cortex | |
Created | August 2, 2020 | |
Last Release | February 10, 2025 |