First Release
- Tested against Check Point Gaia version R80.10
- Support for OPSEC LEA-based remote firewall log collection
- Support for SSLCA and Clear authentication modes
First release. Support following query commands and threat intelligence feeds.
* misp-attributes
* misp-events
Works on Logpresso Sonar 4.0.2306.0 or above.
Fixed a bug where the ncloud-monthly-costs-by-contract command would fail due to an null defaultAmount value.
First release
* jira-audit-logs command
First release
* Version: Quadminers Network Blackbox 3.3.6 or above
* Parser: support session, meta, packet rule, content file, CPU, NIC log types
* Query Commands
* nbb-content: Get content body.
* nbb-contents: Get contents.
* nbb-custom-alerts: Get custom alerts.
* nbb-custom-rules: Get custom rules.
* nbb-download-file: Download content file.
* nbb-download-pcap: Download PCAP file.
* nbb-packets: Get packets for specified session.
* nbb-sessions: Get sessions.
* nbb-suricata-alerts: Get suricata alerts.
* nbb-suricata-rules: Get suricata rules.
First release. Supports the following extended commands:
- ngfcti-ip-addresses
- ngfcti-files
- ngfcti-urls
- ngfcti-domains
New command:
* abuseipdb-check-ip-batch
Changes
* Added idle timeout option for BLUEMAX NGF session.
* Added expiration period option for BLUEMAX blacklist registration.
* Fixed concurrency error when executing multiple BLUEMAX NGF commands at the same time.
First release. Support following commands:
* google-workspace-users
* google-workspace-domains
* google-workspace-drive-logs
* google-workspace-meet-logs
* google-workspace-oauth-logs
First release. Support following commands:
* notion-users
* notion-pages
* notion-blocks
* notion-blocks-batch
Added missing output fields:
* Added missing output fields to bluemax-ngf-add-blacklist-rule command.
* Added profile field to output of bluemax-ngf-blacklist-rules command.
* Added profile field to output of bluemax-ngf-system-time command.
* Added profile field to output of bluemax-ngf-system-info command.
First release. Support following commands:
* docx-words
* docx-words-batch
* file-type
* file-type-batch
* pptx-words
* pptx-words-batch
Changes
* Supports blacklist object instead of IP group object for IP blacklist synchronization.
* Supports IP block exception configuration to prevent human error.
* Supports also following commands:
* bluemax-ngf-accounts
* bluemax-ngf-blacklist-rules
* bluemax-ngf-add-blacklist-rule
* bluemax-ngf-remove-blacklist-rule
* bluemax-ngf-session-logs
* bluemax-ngf-system-info
* bluemax-ngf-system-status
* bluemax-ngf-system-time
First release. Support following commands:
* ncloud-access-control-group-rules: Get rule list of access control groups from Naver Cloud.
* ncloud-access-control-groups: Get ACG list from Naver Cloud.
* ncloud-activities: Get cloud activity logs from Naver Cloud.
* ncloud-monthly-costs-by-contract: Get monthly costs by contract from Naver Cloud.
* ncloud-monthly-costs-by-product: Get monthly costs by product from Naver Cloud.
* ncloud-network-acls: Get network ACLs from Naver Cloud.
* ncloud-regions: Get regions from Naver Cloud.
* ncloud-servers: Get server instances from Naver Cloud.
* ncloud-sub-accounts: Get sub accounts from Naver Cloud.
* ncloud-subnets: Get subnets from Naver Cloud.
* ncloud-vpcs: Get VPCs from Naver Cloud.
* ncloud-zones: Get zones from Naver Cloud.
Slack app now supports channel, username, and icon_emoji settings for connect profile.
First release. Support following commands:
* mws-file-summary-report
* mws-file-static-report
* mws-ip-summary-report
* mws-domain-summary-report
First release. Support following commands:
* bluemax-ngf-add-host-object
* bluemax-ngf-add-host-to-group
* bluemax-ngf-address-group-members
* bluemax-ngf-address-groups
* bluemax-ngf-firewall-rules
* bluemax-ngf-host-objects
* bluemax-ngf-remove-host-from-group
* bluemax-ngf-remove-host-object
Fixed an error of two commands due to invalid REST API endpoint:
* abuseipdb-check-ip
* abuseipdb-report-ip
Fixed app start failure caused by kotlin dependency.
First release. Support following query commands:
* criminal-ip-asset-asn-stats
* criminal-ip-asset-country-stats
* criminal-ip-asset-favicon-stats
* criminal-ip-asset-port-stats
* criminal-ip-asset-product-stats
* criminal-ip-asset-search
* criminal-ip-asset-service-stats
* criminal-ip-get-ip-summary
* criminal-ip-get-vpn-reports
* criminal-ip-get-vpn-summary
* criminal-ip-status