Skip to content

feat: Add SIEM correlation scenario execution with context injection …#69

Merged
natesmalley merged 1 commit intonatesmalley:mainfrom
jmorascalyr:apollo-changes
Feb 19, 2026
Merged

feat: Add SIEM correlation scenario execution with context injection …#69
natesmalley merged 1 commit intonatesmalley:mainfrom
jmorascalyr:apollo-changes

Conversation

@jmorascalyr
Copy link
Collaborator

…and parser improvements

  • Added start_correlation_scenario() and _execute_correlation_scenario() methods to ScenarioService for executing scenarios with SIEM context passed via environment variable
  • Updated Proofpoint event generator to handle overrides for phishScore-based threat type determination and added click-related fields (clickIP, clickTime, threatURL) for parser detection
  • Rewrote Proofpoint parser from complex multi

…and parser improvements

- Added start_correlation_scenario() and _execute_correlation_scenario() methods to ScenarioService for executing scenarios with SIEM context passed via environment variable
- Updated Proofpoint event generator to handle overrides for phishScore-based threat type determination and added click-related fields (clickIP, clickTime, threatURL) for parser detection
- Rewrote Proofpoint parser from complex multi
@natesmalley natesmalley merged commit cace214 into natesmalley:main Feb 19, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants