Skip to content

Releases: mohlcyber/OpenDXL-Phantom

OpenDXL-Phantom-v1.3.2

05 Dec 16:30
6781688
Compare
Choose a tag to compare

MAR Hash lookup allows MD5, SHA1 and SHA256 searches - hunt file
TIE DXL libraries in package included for external reputation option - set reputation
MAR File Hunt output includes more data including filename and path - hunt file
Updated on poll action to new Phantom API's - on poll
TIE Set Reputation allows to set External or Enterprise reputation - set reputation
Subscribe to ATD analysis report and TIE rep changes - all parsers are included - on poll
Improved Error Handling - General

OpenDXL-Phantom-v1.3.1

13 Jun 16:09
9069d94
Compare
Choose a tag to compare

changed the way how the DXL subscriber is generated (code simplification)
DXL subscriber will automatically killed when asset got deleted (after max. 60s)
changed naming convention during asset creation (e.g. both ePO or DXL Broker IP - both supported)

OpenDXL-Phantom-v1.3.0

27 May 12:24
a6b60af
Compare
Choose a tag to compare

changed set reputation action - able now to set reputations based on MD5, SHA1 or SHA256
changed test message required field to optional
now also released standalone version that includes all dependencies

OpenDXL-Phantom-v1.2.9

23 May 13:14
071a5f6
Compare
Choose a tag to compare

Changed readOnly to False for set_reputation action for approval flow

OpenDXL-Phantom-v1.2.8

22 Feb 19:14
622d245
Compare
Choose a tag to compare

added the ability to define custom ePO ports for certificate generation
move test message to required fields

OpenDXL-Phantom-v1.2.7

19 Nov 17:31
b7ce4dc
Compare
Choose a tag to compare

Empty password fix. Get reputation prevalence visualisation fix.

OpenDXL-Phantom-v1.2.6

16 Nov 14:42
43928a3
Compare
Choose a tag to compare

required Libraries (DXL, TIEDXL, MARDXL) will be downloaden via pip instead of embedded in the app.
added new action to get file reputations from McAfee TIE.

OpenDXL-Phantom-v1.2.5

04 Sep 12:04
4e17443
Compare
Choose a tag to compare

OpenDXL libraries updated.
New subscription process.

Data ingest got extracted from the main module and is in the DXL subscriber now.
This provides the capability to ingest data to Phantom directly without any waiting time.

OpenDXL-Phantom-v1.2.4

18 Dec 10:47
Compare
Choose a tag to compare

fix for customer parser upload

OpenDXL-Phantom-v1.2.3

06 Dec 15:43
46919ff
Compare
Choose a tag to compare

test connectivity topic changed
ATD parser priority
TIE value list added
lookup dxl service action added