content icon indicating copy to clipboard operation
content copied to clipboard

Group-IB new integration

Open Kchekh opened this issue 7 months ago • 3 comments

Contributing to Cortex XSOAR Content

Make sure to register your contribution by filling the contribution registration form

The Pull Request will be reviewed only after the contribution registration form is filled.

Status

  • [ ] In Progress
  • [x] Ready
  • [ ] In Hold - (Reason for hold)

Related Issues

fixes: -

Description

Our team is ready to release a new integration with our Digital Risk Protection product

Must have

  • [x] Tests
  • [x] Documentation

Kchekh avatar May 20 '25 04:05 Kchekh

Thank you for your contribution. Your generosity and caring are unrivaled! Make sure to register your contribution by filling the Contribution Registration form, so our content wizard @itssapir will know the proposed changes are ready to be reviewed. For your convenience, here is a link to the contributions SLAs document.

content-bot avatar May 20 '25 04:05 content-bot

Hi @Kchekh, thanks for contributing to the XSOAR marketplace. To receive credit for your generous contribution please follow this link.

content-bot avatar May 20 '25 04:05 content-bot

Hi @Kchekh, Thank you for your contribution.

Please make sure to fill the contribution registration form so we can carry on handling this PR. Thanks!

itssapir avatar May 27 '25 12:05 itssapir

Hello @itssapir and @Benimanela ! We have filled out the Contributor Details form. Kindly reopen this ticket for our further collaboration

Kchekh avatar Aug 12 '25 14:08 Kchekh

@Kchekh any update?

merit-maita avatar Aug 31 '25 06:08 merit-maita

Hi @Kchekh, Thank you for the work on this contribution. The implementation looks good overall.

I have a few comments from a security perspective at this stage:

General

  • Please add a description in the pack_metadata file for clarity and documentation.
  • Run demisto-sdk format on all files to ensure proper formatting and alignment with XSOAR standards.
  • In the README (Step 5), users are instructed to create a new Pre-Process Rule, but it appears this rule already exists. Please clarify or update the instructions as needed.
  • Add additionalinfo for the Violation Section to filter the received Violation parameter in instance settings.

Pre-Process Rule

  • The Pre-Process Rule appears incomplete—no action is defined. Should it be running the GIBDRPIncidentUpdate script? Please review and update as required.

Incident Fields

  • For performance reasons, please mark all custom incident fields as unsearchable: true unless searching is specifically needed.

  • Avoid creating new fields when suitable common fields already exist. For example:

    • Use the standard Occurred field instead of GIB DRP Created.
    • Use the standard Title field instead of GIB DRP Title.
    • Please review all incident fields and reuse existing fields where possible.

Playbook

  • Change the playbook name to: Group-IB Digital Risk Protection - Violation Incident Postprocessing for consistency.
  • The first step should check if the Group-IB integration is enabled to avoid errors.
  • The "done" task is currently set to close the investigation. Please update the task name to clearly indicate this.
  • Please add an end step (Section Header task type) at the end of the playbook for better clarity.

Let me know once you've addressed the above so I can take another look!

Hi @Kchekh,

Thanks for resolving some of the points! Have you had a chance to look at my other comments as well?

Benimanela avatar Sep 04 '25 12:09 Benimanela

@Kchekh unfortunately i have to close the pr for the lack of update, feel free to reopen in case there's some. thanks!

merit-maita avatar Sep 09 '25 07:09 merit-maita

Hello @merit-maita , Thank you very much for your review, I have prepared all the changes. Could we reopen the PR? For the final step, I am waiting for the Docker image update, here https://github.com/demisto/dockerfiles/pull/40577, and it has moved here https://github.com/demisto/dockerfiles/pull/40654 Otherwise, everything is ready

Kchekh avatar Oct 17 '25 12:10 Kchekh

Hello @merit-maita and @Benimanela , The Docker image has been updated and I have added it to the current version. Could you please review the changes made based on your comments?

Kchekh avatar Oct 23 '25 10:10 Kchekh

Hello @merit-maita and @Benimanela , Please advise, should I create a new PR to promote the launch of the new integration and transfer the current changes achieved in this PR to it?

Kchekh avatar Nov 11 '25 13:11 Kchekh

A new PR was made - https://github.com/demisto/content/pull/41990

Kchekh avatar Nov 20 '25 11:11 Kchekh