mirror of
https://github.com/valitydev/Cortex-Analyzers.git
synced 2024-11-06 17:15:21 +00:00
.. | ||
PaloAltoNGFW_unblock_domain.json | ||
README.md | ||
Unblock_domain.py |
Block external IP address for Palo Alto NGFW
Response module for block external IP address for Palo Alto NGFW
Installation
need install:
- pan-os-python
- thehive4py
ToDo
to work, you need to create Address_Group in PaloAltoNGFW and create security polites and name them in "name_internal_Address_Group_for_domain" and "name_external_Address_Group_for_domain"
principle of operation:
- the value is selected from the alert the hive.
- if ioc added in Address_Groups, script deleted ioc
- if ioc in AddressObject, script deleted ioc