Releases: splunk-soar-connectors/carbonblackcloud
Releases · splunk-soar-connectors/carbonblackcloud
2.0.1
2.0.0
- New Features:
- Migration from Alerts v6 to Alerts v7.
- New actions that operate on Carbon Black Cloud objects:
- get cron jobs - Get Cron Jobs in Carbon Black Cloud
- get observations - Get Observations
- Updated action:
- get scheduled task - Get Scheduled Task Created in Carbon Black Cloud
- Decommissioned action:
- get enriched event - Get Enriched Event
- Added two new types of alerts (INTRUSION_DETECTION_SYSTEM and HOST_BASED_FIREWALL) to ingest.
- Breaking Changes:
- Alerts ingest has been changed to Alert API v7. Some fields in the earlier versions have been renamed or removed from the new versions.
- An additional permission is needed to close alerts: Background Tasks - jobs.status - READ).
- The Alert Action get enriched event has been deprecated and will be deactivated July 31, 2024 . The action get observations has been added and can enrich more Alert types.
1.1.1
- Updated an app dependency that had a security issue
1.1.0
- New actions that operate on Carbon Black Cloud objects:
dismiss future alerts- Dismiss all future Carbon Black Cloud alertsget asset info- Get Asset Infoget cleared eventlogs- Get Cleared Event Logsget rdp info- Get RDP Connection Informationget scheduled task- Get Scheduled Task Created in Carbon Black Cloudlist logged users- List Logged In Users from Carbon Black Cloud LiveQuerylist persistence locations- List Windows Persistence Locations
1.0.2
- New actions that operate on Carbon Black Cloud objects:
dismiss future alerts- Dismiss all future Carbon Black Cloud alertsget asset info- Get Asset Infoget cleared eventlogs- Get Cleared Event Logsget rdp info- Get RDP Connection Informationget scheduled task- Get Scheduled Task Created in Carbon Black Cloudlist logged users- List Logged In Users from Carbon Black Cloud LiveQuerylist persistence locations- List Windows Persistence Locations
1.0.1
- Initial Release