Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
99 commits
Select commit Hold shift + click to select a range
04d6d21
- Update to Fix a playbook pointing at the old Foundation - Error Han…
scottbrumley Jan 16, 2026
dd26b97
- Update to Fix CrowdStrike Layout pointing at incorrect scripts.
scottbrumley Jan 16, 2026
1580986
- Bump Versions
scottbrumley Jan 16, 2026
fd2f82b
- Normalization needed for Layout
scottbrumley Jan 16, 2026
5e5c76a
- Playbook was in the wrong place
scottbrumley Jan 16, 2026
98c130b
Merge pull request #417 from Palo-Cortex/fix/unified-error-handler
scottbrumley Jan 16, 2026
0c90a1a
- Update to soc-packs-release-v2.yml to use the demisto-sdk zip-file …
scottbrumley Jan 20, 2026
8adecbc
Merge pull request #419 from Palo-Cortex/fix/ci-release-using-demisto…
scottbrumley Jan 20, 2026
59e0254
- Testing new package format with demisto-sdk
scottbrumley Jan 20, 2026
dd6f11f
- Bump packing
scottbrumley Jan 20, 2026
73489b9
Merge pull request #422 from Palo-Cortex/test/new-ci-demisto-zip
scottbrumley Jan 20, 2026
6bf7b94
- Issue when a package is not created assuming all should be.
scottbrumley Jan 20, 2026
099d2cc
Merge pull request #423 from Palo-Cortex/test/new-ci-demisto-zip
scottbrumley Jan 20, 2026
f2cbade
Merge branch 'main' into develop
scottbrumley Jan 20, 2026
14f5a92
- Added Deprecation language to Package
scottbrumley Jan 20, 2026
299db81
Merge pull request #425 from Palo-Cortex/test/ci-demisto-sdk
scottbrumley Jan 20, 2026
952f81e
Merge branch 'main' into develop
scottbrumley Jan 20, 2026
d460a6e
- Using package to test demist-sdk zip-file in CI.
scottbrumley Jan 20, 2026
569e4ce
Merge pull request #427 from Palo-Cortex/fix/ci-release-demisto-zip
scottbrumley Jan 20, 2026
edd6a18
- Text bump
scottbrumley Jan 20, 2026
ed715b3
Merge pull request #429 from Palo-Cortex/fix/ci-release-demisto-zip
scottbrumley Jan 20, 2026
20cf235
Merge branch 'main' into develop
scottbrumley Jan 20, 2026
7674561
- Testing Trend Micro with Bootloader
scottbrumley Jan 20, 2026
b07e6a1
Merge pull request #431 from Palo-Cortex/test/ci-demisto-zip
scottbrumley Jan 20, 2026
6e0dd9a
- Created a bootloader script and integration for managing SOC Framew…
scottbrumley Jan 22, 2026
49140ec
- bump soc-framework-manager version
scottbrumley Jan 22, 2026
d3a2587
- Fix Validation errors fromVerison and Name / ID match
scottbrumley Jan 22, 2026
1f9c355
Merge pull request #434 from Palo-Cortex/feature/soc-framework-pack-m…
scottbrumley Jan 22, 2026
04aa751
- Bump version on Trend and soc-optimization to test zip build.
scottbrumley Jan 22, 2026
8ff2103
Merge branch 'main' into develop
scottbrumley Jan 22, 2026
e8fccd3
- Install of Custom Packs
scottbrumley Jan 22, 2026
df906f4
Merge pull request #439 from Palo-Cortex/feat/soc-framework-bootloader
scottbrumley Jan 22, 2026
c50af70
- Attempting to install the market place Unit 42 package
scottbrumley Jan 23, 2026
3091ab0
Merge pull request #441 from Palo-Cortex/feat/soc-opt-unit-42-integra…
scottbrumley Jan 23, 2026
7c0983a
- Update to soc-optimization Unit 42 Integration Pack ID and Name
scottbrumley Jan 23, 2026
8a90c3b
Merge pull request #443 from Palo-Cortex/feat/soc-opt-unit-42-integra…
scottbrumley Jan 23, 2026
f1e40df
Merge branch 'main' into develop
scottbrumley Jan 23, 2026
597f3bb
- Update brand to create instance
scottbrumley Jan 23, 2026
a97c705
Merge pull request #445 from Palo-Cortex/feat/soc-opt-unit-42-integra…
scottbrumley Jan 23, 2026
882a766
- Fixing Integration Instance Name
scottbrumley Jan 23, 2026
0a42253
Merge pull request #451 from Palo-Cortex/fix/soc-opt-integration-unit-42
scottbrumley Jan 23, 2026
469d393
- Adding function to deal with long validation times
scottbrumley Jan 23, 2026
53c59db
- Fixed SOCFWPackManager.yml file
scottbrumley Jan 23, 2026
56f4b8b
Merge pull request #453 from Palo-Cortex/feat/soc-pack-manager
scottbrumley Jan 23, 2026
b5a4f80
- Updated Documentation for the SOCFWPackManager
scottbrumley Jan 26, 2026
752f64d
- Bump version
scottbrumley Jan 26, 2026
06f73a4
Merge pull request #455 from Palo-Cortex/docs/soc-pack-manager
scottbrumley Jan 26, 2026
444d8c0
Merge branch 'main' into develop
scottbrumley Jan 26, 2026
a5f209a
- Fix to import requests line. Indentation was mugged.
scottbrumley Jan 26, 2026
53e2da6
Merge pull request #457 from Palo-Cortex/docs/soc-pack-manager
scottbrumley Jan 26, 2026
3c291a2
Merge branch 'main' into develop
scottbrumley Jan 26, 2026
7f71909
- Fix multiple lines. Indentation was mugged.
scottbrumley Jan 26, 2026
81a56b7
Merge pull request #459 from Palo-Cortex/docs/soc-pack-manager
scottbrumley Jan 26, 2026
301322c
Merge branch 'main' into develop
scottbrumley Jan 26, 2026
c30d8e9
- fix_errors.py was the culprit. It was broken. Trying again
scottbrumley Jan 26, 2026
61bc7c6
Merge pull request #461 from Palo-Cortex/docs/soc-pack-manager
scottbrumley Jan 26, 2026
fbfa7a3
Merge branch 'main' into develop
scottbrumley Jan 26, 2026
fcc72c5
- fix_errors.py was the culprit. It was broken. Trying again
scottbrumley Jan 26, 2026
33636ed
Merge branch 'develop' into fix/soc-pack-manager
scottbrumley Jan 26, 2026
578db92
Merge pull request #463 from Palo-Cortex/fix/soc-pack-manager
scottbrumley Jan 26, 2026
c53bd35
Merge branch 'main' into develop
scottbrumley Jan 26, 2026
a070ab7
- Testing prepare-content with PoV companion
scottbrumley Jan 26, 2026
3e736d1
Merge pull request #465 from Palo-Cortex/test/pov-companion
scottbrumley Jan 26, 2026
9f3df5f
- Testing prepare-content with PoV companion
scottbrumley Jan 27, 2026
dd9eb43
Merge pull request #467 from Palo-Cortex/test/pov-companion
scottbrumley Jan 27, 2026
1f85532
Merge branch 'main' into develop
scottbrumley Jan 27, 2026
6ac3464
- Testing prepare-content with PoV companion
scottbrumley Jan 27, 2026
aeec712
Merge pull request #469 from Palo-Cortex/test/pov-companion
scottbrumley Jan 27, 2026
c32e29a
- Fixed Jobs configuration and Integrations
scottbrumley Jan 28, 2026
da707a3
Merge pull request #471 from Palo-Cortex/fix/soc-manager-configure
scottbrumley Jan 28, 2026
1c8ebfe
Merge branch 'main' into develop
scottbrumley Jan 28, 2026
d131b1b
- Created New SOC Common Playbooks V3
scottbrumley Jan 29, 2026
6e76ef1
- Made soc-common-playbooks non visible
scottbrumley Jan 29, 2026
07caa5a
Merge pull request #473 from Palo-Cortex/fix/soc-opt-unified
scottbrumley Jan 29, 2026
33527cb
- Playbook Fixes
scottbrumley Jan 29, 2026
ba07beb
- Playbook Fixes for Trend
scottbrumley Jan 29, 2026
334c225
- Playbook Fixes for Common Playbooks Unified
scottbrumley Jan 29, 2026
63e0762
- Fix Validation
scottbrumley Jan 29, 2026
0ecbf3c
Merge pull request #474 from Palo-Cortex/fix/soc-opt-unified
scottbrumley Jan 29, 2026
e13590c
- Fix Dedup playbook missing
scottbrumley Jan 29, 2026
78f4f65
- Playbook Validation Fix
scottbrumley Jan 29, 2026
69e691a
Merge pull request #475 from Palo-Cortex/fix/soc-opt-unified
scottbrumley Jan 29, 2026
93cd644
- Fixed inputs and Error Handling issues
scottbrumley Jan 30, 2026
38b23d8
Merge pull request #476 from Palo-Cortex/fix/soc-opt-unified
scottbrumley Jan 30, 2026
422959e
- Update Unified
scottbrumley Jan 30, 2026
c16713d
Merge pull request #478 from Palo-Cortex/update/update-zip-package
scottbrumley Jan 30, 2026
5c9e5f5
Merge branch 'main' into develop
scottbrumley Jan 30, 2026
319c0e3
- Clean Up xsoar_config.json files. Move all dependencies to soc-opt…
scottbrumley Jan 30, 2026
799b5b6
- Updated soc-common-playbooks-unified zipfile link in soc-optimizati…
scottbrumley Jan 30, 2026
1498d01
Merge pull request #480 from Palo-Cortex/update/update-zip-package
scottbrumley Jan 30, 2026
3222d55
Merge branch 'main' into develop
scottbrumley Jan 30, 2026
1b26114
- Bump Version
scottbrumley Jan 30, 2026
f226eab
Merge pull request #482 from Palo-Cortex/update/update-zip-package
scottbrumley Jan 30, 2026
bb4ae16
Merge branch 'main' into develop
scottbrumley Jan 30, 2026
54a1793
- Bump Version
scottbrumley Jan 30, 2026
57b1487
Merge pull request #484 from Palo-Cortex/fix/soc-opt-unified
scottbrumley Jan 30, 2026
fee6851
Merge branch 'main' into develop
scottbrumley Jan 30, 2026
6fd1b6f
- Bump Version
scottbrumley Jan 30, 2026
d63fd74
Merge pull request #486 from Palo-Cortex/update/soc-crowdstrike-zip
scottbrumley Jan 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Packs/soc-crowdstrike-falcon/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"id": "soc-crowdstrike-falcon",
"description": "This contains the content for XSIAM CrowdStrike Falcon. This includes layouts, playbooks and incident fields",
"support": "xsoar",
"currentVersion": "1.0.36",
"currentVersion": "1.0.37",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
2 changes: 1 addition & 1 deletion Packs/soc-crowdstrike-falcon/xsoar_config.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"custom_packs": [
{
"id": "soc-crowdstrike-falcon.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-crowdstrike-falcon-v1.0.36/soc-crowdstrike-falcon-v1.0.36.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-crowdstrike-falcon-v1.0.37/soc-crowdstrike-falcon-v1.0.37.zip",
"system": "yes"
}
],
Expand Down
12 changes: 6 additions & 6 deletions Packs/soc-optimization-unified/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,13 +11,13 @@ This repository outlines a scalable SOC optimization approach tailored for Palo
---

## 1. Enable Auto Triage
1. Read 👉 [Auto-Triage Usage](../../Documentation/Auto_Triage.md) To Understand How it Closes Cases
1. Read 👉 [Auto-Triage Usage](https://github.com/Palo-Cortex/soc-optimization/blob/main/Documentation/Documentation/Auto_Triage.md) To Understand How it Closes Cases
2. Investigation & Response → Automation → Jobs
3. Check Auto Triage
4. Click Enable Button


![Auto_Triage_Enable.png](../../docs/soc-optimization/Auto_Triage_Enable.png)
![Auto_Triage_Enable.png](https://github.com/Palo-Cortex/soc-optimization/tree/main/images/Auto_Triage_Enable.png)
---

## 2. Configure Automation Rules
Expand All @@ -26,7 +26,7 @@ This repository outlines a scalable SOC optimization approach tailored for Palo

👉 [Learn more about Entry Point playbooks](https://github.com/Palo-Cortex/soc-optimization/blob/main/Documentation/EntryPoints.md)

![Default_Automation_Rules.png](../../docs/soc-optimization/Default_Automation_Rules.png)
![Default_Automation_Rules.png](https://github.com/Palo-Cortex/soc-optimization/tree/main/images/Default_Automation_Rules.png)
- **EP_IR_NIST(800-61)** is the *Incident Response Catch-All*.
- You can create more specific rules above this (e.g., Phishing based on MITRE Technique T1566).

Expand All @@ -39,13 +39,13 @@ This repository outlines a scalable SOC optimization approach tailored for Palo
- `Severity >= Medium`
- `Has MITRE Tactic`

![Starring_NIST_IR.png](../../docs/soc-optimization/Starring_NIST_IR.png)
![Starring_NIST_IR.png](https://github.com/Palo-Cortex/soc-optimization/tree/main/images/Starring_NIST_IR.png)

## 4. XSIAM SOC Value Metric Dashboard
** Real-time metrics from PoV into production **
1. Dashboards & Reports → Dashboard → XSIAM SOC Value Metrics
2. Select 7 Days (More realistic for SOC reporting)
![Value_Metrics.png](../../docs/soc-optimization/Value_Metrics.png)
![Value_Metrics.png](https://github.com/Palo-Cortex/soc-optimization/tree/main/images/Value_Metrics.png)

*Tips:*
- Alerts must fire playbooks and playbook tasks must run before this dash works.
Expand All @@ -61,7 +61,7 @@ This repository outlines a scalable SOC optimization approach tailored for Palo
- Incidents that are not marked with a star are automatically triaged using `JOB_-_Triage_Incidents.yml`.
- Ensures that high-volume, low-risk alerts are handled without manual intervention.

👉 [Auto-Triage Usage](../../docs/soc-optimization/Auto_Triage.md) — Automatically closes non-priority incidents to reduce alert fatigue.
👉 [Auto-Triage Usage](https://github.com/Palo-Cortex/soc-optimization/tree/main/images/Auto_Triage.md) — Automatically closes non-priority incidents to reduce alert fatigue.

### 2. **Modular Playbooking with the `Upon Trigger`**
- The `Upon Trigger` playbook is the engine of modular decision-making.
Expand Down
2 changes: 1 addition & 1 deletion Packs/soc-optimization-unified/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"id": "soc-optimization-unified",
"description": "This contents the content used to leverage processes that the Palo SOC uses including: Playbooks, integrations, layouts, etc.",
"support": "xsoar",
"currentVersion": "3.0.20",
"currentVersion": "3.0.21",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
4 changes: 2 additions & 2 deletions Packs/soc-optimization-unified/xsoar_config.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,12 +8,12 @@
"custom_packs": [
{
"id": "soc-optimization-unified.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-optimization-unified-v3.0.20/soc-optimization-unified-v3.0.20.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-optimization-unified-v3.0.21/soc-optimization-unified-v3.0.21.zip",
"system": "yes"
},
{
"id": "soc-common-playbooks-unified.zip",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-common-playbooks-unified-v2.7.53/soc-common-playbooks-unified-v2.7.5",
"url": "https://github.com/Palo-Cortex/secops-framework/releases/download/soc-common-playbooks-unified-v2.7.53/soc-common-playbooks-unified-v2.7.53.zip",
"system": "yes"
}
],
Expand Down
4 changes: 2 additions & 2 deletions pack_catalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
{
"id": "soc-crowdstrike-falcon",
"display_name": "SOC CrowdStrike Falcon Integration Enhancement for Cortex XSIAM",
"version": "1.0.36",
"version": "1.0.37",
"path": "Packs/soc-crowdstrike-falcon",
"visible": true,
"xsoar_config": "https://raw.githubusercontent.com/Palo-Cortex/secops-framework/refs/heads/main/Packs/soc-crowdstrike-falcon/xsoar_config.json"
Expand Down Expand Up @@ -59,7 +59,7 @@
{
"id": "soc-optimization-unified",
"display_name": "SOC Framework Unified",
"version": "3.0.20",
"version": "3.0.21",
"path": "Packs/soc-optimization-unified",
"visible": true,
"xsoar_config": "https://raw.githubusercontent.com/Palo-Cortex/secops-framework/refs/heads/main/Packs/soc-optimization-unified/xsoar_config.json"
Expand Down