Skip to content

Commit 454f4b5

Browse files
committed
Solution updated
1 parent 6b2be2f commit 454f4b5

File tree

4 files changed

+733
-27
lines changed

4 files changed

+733
-27
lines changed
Lines changed: 109 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,110 @@
11
{
2-
"Name": "Cyble Vision",
3-
"Author": "Cyble Inc",
4-
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/CybleLogo.svg\" width=\"75px\" height=\"75px\">",
5-
"Description": "This Solution provides Playbooks for Cyble Vision Threat Intelligence ingestion and IOC enrichment, integrating Cyble APIs.\n\n This Solution also includes a CCF Conenctor which enables Alerts ingestion from Cyble Platform to Microsoft Sentinel Workspace.",
6-
"Data Connectors": [
7-
"Solutions/Cyble Vision/Data Connectors/CybleVisionAlerts_CCF/CybleVisionAlerts_DataConnectorDefinition.json"
8-
],
9-
"Playbooks": [
10-
"Solutions/Cyble Vision/Playbooks/IoC-Enrichment/azuredeploy.json",
11-
"Solutions/Cyble Vision/Playbooks/TI-Ingest/azuredeploy.json"
12-
],
13-
"BasePath": "C:\\GitHub\\Azure-Sentinel",
14-
"Version": "3.0.1",
15-
"Metadata": "SolutionMetadata.json",
16-
"TemplateSpec": true,
17-
"Is1PConnector": false
18-
}
2+
"Name": "Cyble Vision",
3+
"Author": "Cyble Inc",
4+
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/CybleLogo.svg\" width=\"75px\" height=\"75px\">",
5+
"Description": "This Solution provides Playbooks for Cyble Vision Threat Intelligence ingestion and IOC enrichment, integrating Cyble APIs.\n\n This Solution also includes a CCF Conenctor which enables Alerts ingestion from Cyble Platform to Microsoft Sentinel Workspace.",
6+
"Data Connectors": [
7+
"Solutions/Cyble Vision/Data Connectors/CybleVisionAlerts_CCF/CybleVisionAlerts_DataConnectorDefinition.json"
8+
],
9+
"Analytic Rules": [
10+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Assets.yaml",
11+
"Solutions/Cyble Vision/Analytic Rules/Alerts_BitBucket.yaml",
12+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Cloud_Storage.yaml",
13+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Compromised_Endpoints_Cookies.yaml",
14+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Compromised_Files.yaml",
15+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Cyber_Crime_Forum.yaml",
16+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Darkweb_Data_Breaches.yaml",
17+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Darkweb_Marketplace.yaml",
18+
"Solutions/Cyble Vision/Analytic Rules/Alerts_darkweb_ransomware_rule.yaml",
19+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Defacement_Content.yaml",
20+
"Solutions/Cyble Vision/Analytic Rules/Alerts_defacement_keyword_rule.yaml",
21+
"Solutions/Cyble Vision/Analytic Rules/Alerts_defacement_url_rule.yaml",
22+
"Solutions/Cyble Vision/Analytic Rules/Alerts_discord_rule.yaml",
23+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Docker.yaml",
24+
"Solutions/Cyble Vision/Analytic Rules/Alerts_domain_expiry_rule.yaml",
25+
"Solutions/Cyble Vision/Analytic Rules/Alerts_domain_watchlist_rule.yaml",
26+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Flash_Report_Alerts.yaml",
27+
"Solutions/Cyble Vision/Analytic Rules/Alerts_github.yaml",
28+
"Solutions/Cyble Vision/Analytic Rules/Alerts_hacktivism.yaml",
29+
"Solutions/Cyble Vision/Analytic Rules/Alerts_i2p_rule.yaml",
30+
"Solutions/Cyble Vision/Analytic Rules/Alerts_IOC'S.yaml",
31+
"Solutions/Cyble Vision/Analytic Rules/Alerts_ip_risk_score_rule.yaml",
32+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Leaked_Credentials.yaml",
33+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Malicious_ads.yaml",
34+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Mobile_Apps.yaml",
35+
"Solutions/Cyble Vision/Analytic Rules/Alerts_new_vulnerability_rule.yaml",
36+
"Solutions/Cyble Vision/Analytic Rules/Alerts_News_Feed.yaml",
37+
"Solutions/Cyble Vision/Analytic Rules/Alerts_osint_rule.yaml",
38+
"Solutions/Cyble Vision/Analytic Rules/Alerts_ot_ics_rule.yaml",
39+
"Solutions/Cyble Vision/Analytic Rules/Alerts_pastebin_rule.yaml",
40+
"Solutions/Cyble Vision/Analytic Rules/Alerts_phishing_rule.yaml",
41+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Physical_Threats.yaml",
42+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Postman.yaml",
43+
"Solutions/Cyble Vision/Analytic Rules/Alerts_product_vulnerability_rule.yaml",
44+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Social_Media_Monitoring.yaml",
45+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Stealer_Logs.yaml",
46+
"Solutions/Cyble Vision/Analytic Rules/Alerts_subdomains_rule.yaml",
47+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Suspicious_Domain.yaml",
48+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Telegram_Mentions.yaml",
49+
"Solutions/Cyble Vision/Analytic Rules/Alerts_TOR_Links.yaml",
50+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Vulnerability.yaml",
51+
"Solutions/Cyble Vision/Analytic Rules/Alerts_Web_Applications.yaml"
52+
],
53+
"Parsers": [
54+
"Solutions/Cyble Vision/Parser/Alerts_advisory.yaml",
55+
"Solutions/Cyble Vision/Parser/Alerts_assets.yaml",
56+
"Solutions/Cyble Vision/Parser/Alerts_bit_bucket.yaml",
57+
"Solutions/Cyble Vision/Parser/Alerts_cloud_storage.yaml",
58+
"Solutions/Cyble Vision/Parser/Alerts_compromised_endpoints_cookies.yaml",
59+
"Solutions/Cyble Vision/Parser/Alerts_compromised_files.yaml",
60+
"Solutions/Cyble Vision/Parser/Alerts_cyber_crime_forums.yaml",
61+
"Solutions/Cyble Vision/Parser/Alerts_darkweb_data_breaches.yaml",
62+
"Solutions/Cyble Vision/Parser/Alerts_darkweb_marketplaces.yaml",
63+
"Solutions/Cyble Vision/Parser/Alerts_darkweb_ransomware.yaml",
64+
"Solutions/Cyble Vision/Parser/Alerts_defacement_content.yaml",
65+
"Solutions/Cyble Vision/Parser/Alerts_defacement_keyword.yaml",
66+
"Solutions/Cyble Vision/Parser/Alerts_defacement_url.yaml",
67+
"Solutions/Cyble Vision/Parser/Alerts_discord.yaml",
68+
"Solutions/Cyble Vision/Parser/Alerts_docker.yaml",
69+
"Solutions/Cyble Vision/Parser/Alerts_domain_expiry.yaml",
70+
"Solutions/Cyble Vision/Parser/Alerts_domain_watchlist.yaml",
71+
"Solutions/Cyble Vision/Parser/Alerts_flash_report.yaml",
72+
"Solutions/Cyble Vision/Parser/Alerts_github_tor_links.yaml",
73+
"Solutions/Cyble Vision/Parser/Alerts_github.yaml",
74+
"Solutions/Cyble Vision/Parser/Alerts_hacktivism.yaml",
75+
"Solutions/Cyble Vision/Parser/Alerts_i2p.yaml",
76+
"Solutions/Cyble Vision/Parser/Alerts_iocs.yaml",
77+
"Solutions/Cyble Vision/Parser/Alerts_ip_risk_score.yaml",
78+
"Solutions/Cyble Vision/Parser/Alerts_leaked_credentials.yaml",
79+
"Solutions/Cyble Vision/Parser/Alerts_malicious_ads.yaml",
80+
"Solutions/Cyble Vision/Parser/Alerts_mobile_apps.yaml",
81+
"Solutions/Cyble Vision/Parser/Alerts_new_vulnerability.yaml",
82+
"Solutions/Cyble Vision/Parser/Alerts_news_feed.yaml",
83+
"Solutions/Cyble Vision/Parser/Alerts_osint.yaml",
84+
"Solutions/Cyble Vision/Parser/Alerts_ot_ics.yaml",
85+
"Solutions/Cyble Vision/Parser/Alerts_pastebin.yaml",
86+
"Solutions/Cyble Vision/Parser/Alerts_phishing.yaml",
87+
"Solutions/Cyble Vision/Parser/Alerts_physical_threats.yaml",
88+
"Solutions/Cyble Vision/Parser/Alerts_postman.yaml",
89+
"Solutions/Cyble Vision/Parser/Alerts_product_vulnerability.yaml",
90+
"Solutions/Cyble Vision/Parser/Alerts_ransomware_updates.yaml",
91+
"Solutions/Cyble Vision/Parser/Alerts_social_media_monitoring.yaml",
92+
"Solutions/Cyble Vision/Parser/Alerts_ssl_expiry.yaml",
93+
"Solutions/Cyble Vision/Parser/Alerts_stealer_logs.yaml",
94+
"Solutions/Cyble Vision/Parser/Alerts_subdomains.yaml",
95+
"Solutions/Cyble Vision/Parser/Alerts_suspicious_domains.yaml",
96+
"Solutions/Cyble Vision/Parser/Alerts_telegram_mentions.yaml",
97+
"Solutions/Cyble Vision/Parser/Alerts_vulnerability.yaml",
98+
"Solutions/Cyble Vision/Parser/Alerts_web_applications.yaml"
99+
],
100+
"Playbooks": [
101+
"Solutions/Cyble Vision/Playbooks/IoC-Enrichment/azuredeploy.json",
102+
"Solutions/Cyble Vision/Playbooks/TI-Ingest/azuredeploy.json",
103+
"Solutions/Cyble Vision/Playbooks/CybleVisionAlert_Status_Update/azuredeploy.json"
104+
],
105+
"BasePath": "C:\\GitHub\\Azure-Sentinel",
106+
"Version": "3.0.1",
107+
"Metadata": "SolutionMetadata.json",
108+
"TemplateSpec": true,
109+
"Is1PConnector": false
110+
}
55.1 KB
Binary file not shown.

0 commit comments

Comments
 (0)