diff --git a/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml new file mode 100644 index 0000000..f3a8c00 --- /dev/null +++ b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow-Parameter-Value.xml @@ -0,0 +1,9 @@ + + + + + + + + + diff --git a/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml new file mode 100644 index 0000000..81e7b6f --- /dev/null +++ b/Community Developed/Trellix HX/Alert Groups/Trellix-HX-Alert_Groups-Workflow.xml @@ -0,0 +1,80 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml new file mode 100644 index 0000000..f3a8c00 --- /dev/null +++ b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow-Parameter-Value.xml @@ -0,0 +1,9 @@ + + + + + + + + + diff --git a/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml new file mode 100644 index 0000000..f5c9fe5 --- /dev/null +++ b/Community Developed/Trellix HX/Alerts/Trellix-HX-Alerts-Workflow.xml @@ -0,0 +1,150 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/Community Developed/Trellix HX/LICENSE b/Community Developed/Trellix HX/LICENSE new file mode 100644 index 0000000..15286d7 --- /dev/null +++ b/Community Developed/Trellix HX/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2024 Mohamed Al-Shabrawy + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml new file mode 100644 index 0000000..ac21019 --- /dev/null +++ b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow-Parameter-Value.xml @@ -0,0 +1,7 @@ + + + + + + + diff --git a/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml new file mode 100644 index 0000000..d67517e --- /dev/null +++ b/Community Developed/Trellix HX/Process Tracker/Trellix-HX-ProcessTracker-Workflow.xml @@ -0,0 +1,147 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/Community Developed/Trellix HX/README.md b/Community Developed/Trellix HX/README.md new file mode 100644 index 0000000..2f0be39 --- /dev/null +++ b/Community Developed/Trellix HX/README.md @@ -0,0 +1,18 @@ +# QRadar Workflows for Trellix HX +IBM QRadar Universal Cloud Connector Workflows for reading Trellix/FireEye HX Alerts and Events through REST API + +## Requirements: +User account to access FireEye HX Controller with api_analyst role + +## Workflow information +- Author Name: Mohamed Al-Shabrawy +- Maintainer Name: @M-Shabrawy +- Version: 1.0.5 +- Endpoint Documentation: + - - https://fireeye.dev/ + - - https://fireeye.dev/apis/lighthouse/ + +## Event Types Currently Supported by the workflow: +- Alerts: Collects non-suppressed alerts known to the system. +- Alert Groups: Collects alert_groups. +- Process Tracker: Collects Process Tracker module events.