deft/reports/weekly-24.html
Yann Esposito (Yogsototh) 136c8c4be4
save
2023-08-09 15:00:50 +02:00

774 lines
23 KiB
HTML

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml" lang="" xml:lang="">
<head>
<meta charset="utf-8" />
<meta name="generator" content="pandoc" />
<meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=yes" />
<meta name="dcterms.date" content="2023-06-16" />
<title>Code Weekly Report 24</title>
<style>
html {
line-height: 1.5;
font-family: Georgia, serif;
font-size: 20px;
color: #1a1a1a;
background-color: #fdfdfd;
}
body {
margin: 0 auto;
max-width: 36em;
padding-left: 50px;
padding-right: 50px;
padding-top: 50px;
padding-bottom: 50px;
hyphens: auto;
overflow-wrap: break-word;
text-rendering: optimizeLegibility;
font-kerning: normal;
}
@media (max-width: 600px) {
body {
font-size: 0.9em;
padding: 1em;
}
h1 {
font-size: 1.8em;
}
}
@media print {
body {
background-color: transparent;
color: black;
font-size: 12pt;
}
p, h2, h3 {
orphans: 3;
widows: 3;
}
h2, h3, h4 {
page-break-after: avoid;
}
}
p {
margin: 1em 0;
}
a {
color: #1a1a1a;
}
a:visited {
color: #1a1a1a;
}
img {
max-width: 100%;
}
h1, h2, h3, h4, h5, h6 {
margin-top: 1.4em;
}
h5, h6 {
font-size: 1em;
font-style: italic;
}
h6 {
font-weight: normal;
}
ol, ul {
padding-left: 1.7em;
margin-top: 1em;
}
li > ol, li > ul {
margin-top: 0;
}
blockquote {
margin: 1em 0 1em 1.7em;
padding-left: 1em;
border-left: 2px solid #e6e6e6;
color: #606060;
}
code {
font-family: Menlo, Monaco, 'Lucida Console', Consolas, monospace;
font-size: 85%;
margin: 0;
}
pre {
margin: 1em 0;
overflow: auto;
}
pre code {
padding: 0;
overflow: visible;
overflow-wrap: normal;
}
.sourceCode {
background-color: transparent;
overflow: visible;
}
hr {
background-color: #1a1a1a;
border: none;
height: 1px;
margin: 1em 0;
}
table {
margin: 1em 0;
border-collapse: collapse;
width: 100%;
overflow-x: auto;
display: block;
font-variant-numeric: lining-nums tabular-nums;
}
table caption {
margin-bottom: 0.75em;
}
tbody {
margin-top: 0.5em;
border-top: 1px solid #1a1a1a;
border-bottom: 1px solid #1a1a1a;
}
th {
border-top: 1px solid #1a1a1a;
padding: 0.25em 0.5em 0.25em 0.5em;
}
td {
padding: 0.125em 0.5em 0.25em 0.5em;
}
header {
margin-bottom: 4em;
text-align: center;
}
#TOC li {
list-style: none;
}
#TOC ul {
padding-left: 1.3em;
}
#TOC > ul {
padding-left: 0;
}
#TOC a:not(:hover) {
text-decoration: none;
}
code{white-space: pre-wrap;}
span.smallcaps{font-variant: small-caps;}
span.underline{text-decoration: underline;}
div.column{display: inline-block; vertical-align: top; width: 50%;}
div.hanging-indent{margin-left: 1.5em; text-indent: -1.5em;}
ul.task-list{list-style: none;}
.display.math{display: block; text-align: center; margin: 0.5rem auto;}
</style>
<style>
body { font-family: monospace; font-size: 14px; line-height: 1.5em; max-width: 60em; margin: 0 auto; padding-top: 0; }
h1,h2,h3,h4 { margin: 0.25em 0; }
header { margin-bottom: 0; }
header h1 { border: none; }
h1 { border-top: solid 10px; border-bottom: solid 10px; margin-bottom: 1em; padding: 0.5em 0; width: 100%; text-align: center;}
h2 { border-top: solid; text-align: center; margin-top: 1em; padding-top: 1em; }
h3 { margin-left: 1em; color: #cb4b16; }
h4 { margin-left: 2em; }
u { display: inline-block; margin-left: 2.75em; opacity: 0.3; }
hr { opacity: 0; }
a { color: #06a;}
ul { margin-left: 3em; }
#TOC ul { margin-left: 0.5em; }
li { clear: both; }
li > a { float: right; }
nav li a { float: none; }
blockquote { opacity: 0.7; }
</style>
<!--[if lt IE 9]>
<script src="//cdnjs.cloudflare.com/ajax/libs/html5shiv/3.7.3/html5shiv-printshiv.min.js"></script>
<![endif]-->
</head>
<body>
<header id="title-block-header">
<h1 class="title">Code Weekly Report 24</h1>
<p class="subtitle">logs goes 2 weeks back</p>
<p class="date">2023-06-16</p>
</header>
<nav id="TOC" role="doc-toc">
<ul>
<li><a href="#iroh">IROH</a>
<ul>
<li><a href="#lead">lead</a>
<ul>
<li><a href="#guillaume-buisson-1">Guillaume Buisson [1]</a>
<ul>
<li><a href="#iroh-1">iroh [1]</a></li>
</ul></li>
</ul></li>
<li><a href="#data">data</a>
<ul>
<li><a href="#mario-aquino-4">Mario Aquino [4]</a>
<ul>
<li><a href="#iroh-4">iroh [4]</a></li>
</ul></li>
<li><a href="#guillaume-erétéo-2">Guillaume Erétéo [2]</a>
<ul>
<li><a href="#iroh-2">iroh [2]</a></li>
</ul></li>
<li><a href="#ambrose-bonnaire-sergeant-1">Ambrose Bonnaire-Sergeant
[1]</a>
<ul>
<li><a href="#ctia-1">ctia [1]</a></li>
</ul></li>
</ul></li>
<li><a href="#integrations">integrations</a>
<ul>
<li><a href="#matthieu-sprunck-2">Matthieu Sprunck [2]</a>
<ul>
<li><a href="#tenzin-config-2">tenzin-config [2]</a></li>
</ul></li>
<li><a href="#kirill-chernyshov-8">Kirill Chernyshov [8]</a>
<ul>
<li><a href="#iroh-3">iroh [3]</a></li>
<li><a href="#tenzin-config-5">tenzin-config [5]</a></li>
</ul></li>
<li><a href="#shafiq-1">Shafiq [1]</a>
<ul>
<li><a href="#iroh-1-1">iroh [1]</a></li>
</ul></li>
</ul></li>
<li><a href="#auth">auth</a>
<ul>
<li><a href="#bartuka-1">bartuka [1]</a>
<ul>
<li><a href="#iroh-1-2">iroh [1]</a></li>
</ul></li>
<li><a href="#yann-esposito-16">Yann Esposito [16]</a>
<ul>
<li><a href="#iroh-4-1">iroh [4]</a></li>
<li><a href="#ring-jwt-middleware-3">ring-jwt-middleware [3]</a></li>
<li><a href="#tenzin-config-9">tenzin-config [9]</a></li>
</ul></li>
<li><a href="#olivier-barbeau-7">Olivier Barbeau [7]</a>
<ul>
<li><a href="#iroh-7">iroh [7]</a></li>
</ul></li>
<li><a href="#yogsototh-3">(Yogsototh) [3]</a>
<ul>
<li><a href="#ring-jwt-middleware-3-1">ring-jwt-middleware [3]</a></li>
</ul></li>
</ul></li>
<li><a href="#iroh-ops">iroh-ops</a>
<ul>
<li><a href="#jerome-schneider-1">Jerome Schneider [1]</a>
<ul>
<li><a href="#tenzin-1">tenzin [1]</a></li>
</ul></li>
<li><a href="#patrick-patat-1">Patrick Patat [1]</a>
<ul>
<li><a href="#iroh-ops-1">iroh-ops [1]</a></li>
</ul></li>
<li><a href="#patrick-patat-1-1">Patrick Patat [1]</a>
<ul>
<li><a href="#iroh-ops-1-1">iroh-ops [1]</a></li>
</ul></li>
</ul></li>
</ul></li>
<li><a href="#other">Other</a>
<ul>
<li><a href="#other-1">Other</a>
<ul>
<li><a href="#robert-levy-2">Robert Levy [2]</a>
<ul>
<li><a href="#iroh-1-3">iroh [1]</a></li>
<li><a href="#tenzin-config-1">tenzin-config [1]</a></li>
</ul></li>
<li><a href="#devin-walters-2">Devin Walters [2]</a>
<ul>
<li><a href="#tenzin-config-2-1">tenzin-config [2]</a></li>
</ul></li>
<li><a href="#mia-3">Mia [3]</a>
<ul>
<li><a href="#iroh-1-4">iroh [1]</a></li>
<li><a href="#iroh-engine-2">iroh-engine [2]</a></li>
</ul></li>
<li><a href="#scott-mcleod-1">Scott McLeod [1]</a>
<ul>
<li><a href="#tenzin-config-1-1">tenzin-config [1]</a></li>
</ul></li>
<li><a href="#krishna-ganugapenta-4">krishna Ganugapenta [4]</a>
<ul>
<li><a href="#tenzin-4">tenzin [4]</a></li>
</ul></li>
<li><a href="#milehrer-2">milehrer [2]</a>
<ul>
<li><a href="#iroh-engine-2-1">iroh-engine [2]</a></li>
</ul></li>
<li><a href="#martin-bruchanov-2">Martin Bruchanov [2]</a>
<ul>
<li><a href="#tenzin-2">tenzin [2]</a></li>
</ul></li>
<li><a href="#kirill-chernyshov-1">Kirill Chernyshov [1]</a>
<ul>
<li><a href="#tenzin-config-1-2">tenzin-config [1]</a></li>
</ul></li>
<li><a href="#john-jardine-2">John Jardine [2]</a>
<ul>
<li><a href="#tenzin-2-1">tenzin [2]</a></li>
</ul></li>
<li><a href="#sofiia-mykytiuk-9">Sofiia Mykytiuk [9]</a>
<ul>
<li><a href="#tenzin-9">tenzin [9]</a></li>
</ul></li>
<li><a href="#muhammad-xdr-ops-4">muhammad-xdr-ops [4]</a>
<ul>
<li><a href="#tenzin-4-1">tenzin [4]</a></li>
</ul></li>
<li><a href="#dmytro-budko-5">Dmytro Budko [5]</a>
<ul>
<li><a href="#tenzin-5">tenzin [5]</a></li>
</ul></li>
<li><a href="#scott-mcleod-1-1">Scott McLeod [1]</a>
<ul>
<li><a href="#iroh-1-5">iroh [1]</a></li>
</ul></li>
<li><a href="#rekha-gupta-2">Rekha Gupta [2]</a>
<ul>
<li><a href="#tenzin-config-2-2">tenzin-config [2]</a></li>
</ul></li>
<li><a href="#jerome-schneider-1-1">Jerome Schneider [1]</a>
<ul>
<li><a href="#tenzin-1-1">tenzin [1]</a></li>
</ul></li>
<li><a href="#yurii-ivanisenko-2">Yurii Ivanisenko [2]</a>
<ul>
<li><a href="#tenzin-2-2">tenzin [2]</a></li>
</ul></li>
<li><a href="#gayan-jayasundara-2">Gayan Jayasundara [2]</a>
<ul>
<li><a href="#tenzin-2-3">tenzin [2]</a></li>
</ul></li>
</ul></li>
</ul></li>
</ul>
</nav>
<h1 id="iroh">IROH</h1>
<h2 id="lead">lead</h2>
<h3 id="guillaume-buisson-1">Guillaume Buisson [1]</h3>
<h4 id="iroh-1">iroh [1]</h4>
<ul>
<li>Initial XDR Incident Manager Response 1.1 Draft Spec <a
href="https://github.com/advthreat/iroh/pull/7847">#7847</a></li>
</ul>
<h2 id="data">data</h2>
<h3 id="mario-aquino-4">Mario Aquino [4]</h3>
<h4 id="iroh-4">iroh [4]</h4>
<ul>
<li>Fix flaky test <a
href="https://github.com/advthreat/iroh/pull/7971">#7971</a></li>
<li>Partition and batch threat hunt observables <a
href="https://github.com/advthreat/iroh/pull/7958">#7958</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Establish a task timeout option for async work <a
href="https://github.com/advthreat/iroh/pull/7948">#7948</a></li>
<li>Issue 7823/incident summary mapping <a
href="https://github.com/advthreat/iroh/pull/7907">#7907</a></li>
</ul>
</blockquote>
<h3 id="guillaume-erétéo-2">Guillaume Erétéo [2]</h3>
<h4 id="iroh-2">iroh [2]</h4>
<ul>
<li>Update risk-score.md <a
href="https://github.com/advthreat/iroh/pull/7974">#7974</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>adding org mode for calculating data volume <a
href="https://github.com/advthreat/iroh/pull/7941">#7941</a></li>
</ul>
</blockquote>
<h3 id="ambrose-bonnaire-sergeant-1">Ambrose Bonnaire-Sergeant [1]</h3>
<h4 id="ctia-1">ctia [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Disable /metric/average route for irrelevant entities <a
href="https://github.com/advthreat/ctia/pull/1372">#1372</a></li>
</ul>
</blockquote>
<h2 id="integrations">integrations</h2>
<h3 id="matthieu-sprunck-2">Matthieu Sprunck [2]</h3>
<h4 id="tenzin-config-2">tenzin-config [2]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Share the same module configurations in iroh and iroh-async in PROD
<a
href="https://github.com/advthreat/tenzin-config/pull/905">#905</a></li>
<li>Disable HTTP Proxy in IROH proxy (PROD)<a
href="https://github.com/advthreat/tenzin-config/pull/903">#903</a></li>
</ul>
</blockquote>
<h3 id="kirill-chernyshov-8">Kirill Chernyshov [8]</h3>
<h4 id="iroh-3">iroh [3]</h4>
<ul>
<li>Remove try/catch for better error handling <a
href="https://github.com/advthreat/iroh/pull/7980">#7980</a></li>
<li>Fix NullPointerException <a
href="https://github.com/advthreat/iroh/pull/7961">#7961</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Use event id for the key of kafka record <a
href="https://github.com/advthreat/iroh/pull/7923">#7923</a></li>
</ul>
</blockquote>
<h4 id="tenzin-config-5">tenzin-config [5]</h4>
<ul>
<li>Enable KafkaServices on INT <a
href="https://github.com/advthreat/tenzin-config/pull/921">#921</a></li>
<li>Disable KafkaServices once again <a
href="https://github.com/advthreat/tenzin-config/pull/918">#918</a></li>
<li>Enable Kafka related services on INT <a
href="https://github.com/advthreat/tenzin-config/pull/916">#916</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Temporary disable services <a
href="https://github.com/advthreat/tenzin-config/pull/914">#914</a></li>
<li>Set SSL kafka security protocol on INT <a
href="https://github.com/advthreat/tenzin-config/pull/912">#912</a></li>
</ul>
</blockquote>
<h3 id="shafiq-1">Shafiq [1]</h3>
<h4 id="iroh-1-1">iroh [1]</h4>
<ul>
<li>Creating iroh-events datastream should succeed even if it exists
already <a
href="https://github.com/advthreat/iroh/pull/7959">#7959</a></li>
</ul>
<h2 id="auth">auth</h2>
<h3 id="bartuka-1">bartuka [1]</h3>
<h4 id="iroh-1-2">iroh [1]</h4>
<ul>
<li>[IROH Auth] RBAC JWT Revocation on <code>role</code> change <a
href="https://github.com/advthreat/iroh/pull/7875">#7875</a></li>
</ul>
<h3 id="yann-esposito-16">Yann Esposito [16]</h3>
<h4 id="iroh-4-1">iroh [4]</h4>
<ul>
<li>Upgrade SX to XDR org via provisioning <a
href="https://github.com/advthreat/iroh/pull/7981">#7981</a></li>
<li>feature-flag scopes are considered as special <a
href="https://github.com/advthreat/iroh/pull/7985">#7985</a></li>
<li>fix local dev environment to be able to start locally without docker
<a href="https://github.com/advthreat/iroh/pull/7944">#7944</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Use org to display the roles as expected <a
href="https://github.com/advthreat/iroh/pull/7952">#7952</a></li>
</ul>
</blockquote>
<h4 id="ring-jwt-middleware-3">ring-jwt-middleware [3]</h4>
<ul>
<li>Version 1.1.4-SNAPSHOT</li>
<li>Version 1.1.3</li>
<li>Support external error via is-revoked-fn</li>
</ul>
<h4 id="tenzin-config-9">tenzin-config [9]</h4>
<ul>
<li>Enable XDR roles in PROD <a
href="https://github.com/advthreat/tenzin-config/pull/919">#919</a></li>
<li>factorize PROD <a
href="https://github.com/advthreat/tenzin-config/pull/917">#917</a></li>
<li>Add role-web-service config everywhere <a
href="https://github.com/advthreat/tenzin-config/pull/911">#911</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Canonicalize the configs (#913) <a
href="https://github.com/advthreat/tenzin-config/pull/915">#915</a></li>
<li>Canonicalize the configs <a
href="https://github.com/advthreat/tenzin-config/pull/913">#913</a></li>
<li>Add missing role-web-service everywhere <a
href="https://github.com/advthreat/tenzin-config/pull/910">#910</a></li>
<li>Gen configs git pre-commit hook <a
href="https://github.com/advthreat/tenzin-config/pull/908">#908</a></li>
<li>Factorisation iroh/iroh-async confs <a
href="https://github.com/advthreat/tenzin-config/pull/904">#904</a></li>
<li>Tree config structures to prevent config duplication. <a
href="https://github.com/advthreat/tenzin-config/pull/901">#901</a></li>
</ul>
</blockquote>
<h3 id="olivier-barbeau-7">Olivier Barbeau [7]</h3>
<h4 id="iroh-7">iroh [7]</h4>
<ul>
<li>Upgrade Babashka <a
href="https://github.com/advthreat/iroh/pull/7967">#7967</a></li>
<li>add missing exclusions for uberjar <a
href="https://github.com/advthreat/iroh/pull/7963">#7963</a></li>
<li>fix bug when Org has no entitlement <a
href="https://github.com/advthreat/iroh/pull/7956">#7956</a></li>
<li>[IROH configuration]: Generate service diagram <a
href="https://github.com/advthreat/iroh/pull/7872">#7872</a></li>
<li>GH pages updates <a
href="https://github.com/advthreat/iroh/pull/7960">#7960</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>fix alias arguments <a
href="https://github.com/advthreat/iroh/pull/7954">#7954</a></li>
<li>Issue 7930 GitHub pages styling <a
href="https://github.com/advthreat/iroh/pull/7932">#7932</a></li>
</ul>
</blockquote>
<h3 id="yogsototh-3">(Yogsototh) [3]</h3>
<h4 id="ring-jwt-middleware-3-1">ring-jwt-middleware [3]</h4>
<ul>
<li>Version 1.1.4-SNAPSHOT</li>
<li>Version 1.1.3</li>
<li>Support external error via is-revoked-fn</li>
</ul>
<h2 id="iroh-ops">iroh-ops</h2>
<h3 id="jerome-schneider-1">Jerome Schneider [1]</h3>
<h4 id="tenzin-1">tenzin [1]</h4>
<ul>
<li>Kafka Connect: fixed cluster conf and use our own cacerts file</li>
</ul>
<h3 id="patrick-patat-1">Patrick Patat [1]</h3>
<h4 id="iroh-ops-1">iroh-ops [1]</h4>
<ul>
<li>Merge pull request #75 from advthreat/squid</li>
</ul>
<h3 id="patrick-patat-1-1">Patrick Patat [1]</h3>
<h4 id="iroh-ops-1-1">iroh-ops [1]</h4>
<ul>
<li>add squid server for vector in public subnet</li>
</ul>
<h1 id="other">Other</h1>
<h2 id="other-1">Other</h2>
<h3 id="robert-levy-2">Robert Levy [2]</h3>
<h4 id="iroh-1-3">iroh [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>user and team mean time tiles <a
href="https://github.com/advthreat/iroh/pull/7873">#7873</a></li>
</ul>
</blockquote>
<h4 id="tenzin-config-1">tenzin-config [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>add migration for iroh issue #7819 to TEST and PROD environments <a
href="https://github.com/advthreat/tenzin-config/pull/902">#902</a></li>
</ul>
</blockquote>
<h3 id="devin-walters-2">Devin Walters [2]</h3>
<h4 id="tenzin-config-2-1">tenzin-config [2]</h4>
<ul>
<li>Add config.edn for other conure-distributor environments <a
href="https://github.com/advthreat/tenzin-config/pull/920">#920</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Reduce conure-distributor worker count <a
href="https://github.com/advthreat/tenzin-config/pull/906">#906</a></li>
</ul>
</blockquote>
<h3 id="mia-3">Mia [3]</h3>
<h4 id="iroh-1-4">iroh [1]</h4>
<ul>
<li>Snapshot for risk score <a
href="https://github.com/advthreat/iroh/pull/7964">#7964</a></li>
</ul>
<h4 id="iroh-engine-2">iroh-engine [2]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Merge pull request #1394 from advthreat/v0.15.6-rc</li>
<li>Merge pull request #1393 from advthreat/save-asset-snapshot</li>
</ul>
</blockquote>
<h3 id="scott-mcleod-1">Scott McLeod [1]</h3>
<h4 id="tenzin-config-1-1">tenzin-config [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Config changes supporting IROH PR #7934 <a
href="https://github.com/advthreat/tenzin-config/pull/899">#899</a></li>
</ul>
</blockquote>
<h3 id="krishna-ganugapenta-4">krishna Ganugapenta [4]</h3>
<h4 id="tenzin-4">tenzin [4]</h4>
<ul>
<li>COnure-distributor PROD ASG modules fix <a
href="https://github.com/advthreat/tenzin/pull/3062">#3062</a></li>
<li>ops<sub>vpncidr</sub> removal from TEST and other backup regions as
ops vpn not present there <a
href="https://github.com/advthreat/tenzin/pull/3061">#3061</a></li>
<li>Conure-distributor setup config for TEST/PROD <a
href="https://github.com/advthreat/tenzin/pull/3049">#3049</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Conure<sub>distributor</sub> terraform modules config updates <a
href="https://github.com/advthreat/tenzin/pull/3027">#3027</a></li>
</ul>
</blockquote>
<h3 id="milehrer-2">milehrer [2]</h3>
<h4 id="iroh-engine-2-1">iroh-engine [2]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>prepare for v0.15.6</li>
<li>Remove sightings from asset enrichment response, save snapshot
instead</li>
</ul>
</blockquote>
<h3 id="martin-bruchanov-2">Martin Bruchanov [2]</h3>
<h4 id="tenzin-2">tenzin [2]</h4>
<ul>
<li>Clean-up of the old ES5 deployment code <a
href="https://github.com/advthreat/tenzin/pull/3053">#3053</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Fix for consul registration of ops-openvpn service <a
href="https://github.com/advthreat/tenzin/pull/2968">#2968</a></li>
</ul>
</blockquote>
<h3 id="kirill-chernyshov-1">Kirill Chernyshov [1]</h3>
<h4 id="tenzin-config-1-2">tenzin-config [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>IROH Events migration to Elasticsearch <a
href="https://github.com/advthreat/tenzin-config/pull/909">#909</a></li>
</ul>
</blockquote>
<h3 id="john-jardine-2">John Jardine [2]</h3>
<h4 id="tenzin-2-1">tenzin [2]</h4>
<ul>
<li>Add endpoint generation procedure and update endpoints. <a
href="https://github.com/advthreat/tenzin/pull/3058">#3058</a></li>
<li>SXOPS-792: QA complaining of long queue times for incidents
enrichment <a
href="https://github.com/advthreat/tenzin/pull/3054">#3054</a></li>
</ul>
<h3 id="sofiia-mykytiuk-9">Sofiia Mykytiuk [9]</h3>
<h4 id="tenzin-9">tenzin [9]</h4>
<ul>
<li>Update ASG for ES metrics in NAM and EU <a
href="https://github.com/advthreat/tenzin/pull/3063">#3063</a></li>
<li>Update vpnator list <a
href="https://github.com/advthreat/tenzin/pull/3050">#3050</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Remove CSIRT<sub>Investigator</sub> role <a
href="https://github.com/advthreat/tenzin/pull/3045">#3045</a></li>
<li>Policy to allow access to DynamoDB items for ROAdmin <a
href="https://github.com/advthreat/tenzin/pull/3043">#3043</a></li>
<li>Remove jbusboom ssh configs <a
href="https://github.com/advthreat/tenzin/pull/3042">#3042</a></li>
<li>Dmarc record for STAGE <a
href="https://github.com/advthreat/tenzin/pull/3040">#3040</a></li>
<li>Remove ssh access for Michael Simonson <a
href="https://github.com/advthreat/tenzin/pull/3035">#3035</a></li>
<li>Update OPS vpnator list <a
href="https://github.com/advthreat/tenzin/pull/3034">#3034</a></li>
<li>Consul fix for ops vpn <a
href="https://github.com/advthreat/tenzin/pull/3032">#3032</a></li>
</ul>
</blockquote>
<h3 id="muhammad-xdr-ops-4">muhammad-xdr-ops [4]</h3>
<h4 id="tenzin-4-1">tenzin [4]</h4>
<ul>
<li>SXOPS-805 - adding CNAMEs for secure-client-forms MFE <a
href="https://github.com/advthreat/tenzin/pull/3065">#3065</a></li>
<li>enabled trendmicro and defender in all prod regions <a
href="https://github.com/advthreat/tenzin/pull/3055">#3055</a></li>
<li>SXOPS-763 - updating integrations version <a
href="https://github.com/advthreat/tenzin/pull/3052">#3052</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>SXOPS-702 removing INT access to PROD S3 bucket <a
href="https://github.com/advthreat/tenzin/pull/3024">#3024</a></li>
</ul>
</blockquote>
<h3 id="dmytro-budko-5">Dmytro Budko [5]</h3>
<h4 id="tenzin-5">tenzin [5]</h4>
<ul>
<li>SXOPS-191 Terraform: Bring INT and Test into sync with AWS <a
href="https://github.com/advthreat/tenzin/pull/3056">#3056</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>SXOPS-766 [PROD] Fix 'docs' related Terraform Delta <a
href="https://github.com/advthreat/tenzin/pull/3046">#3046</a></li>
<li>SXOPS-636 Docs XDR Deployment, Publish and Host <a
href="https://github.com/advthreat/tenzin/pull/3048">#3048</a></li>
<li>SXOPS-636 Docs XDR Deployment, Publish and Host <a
href="https://github.com/advthreat/tenzin/pull/3041">#3041</a></li>
<li>SXOPS-636 Docs XDR Deployment, Publish and Host <a
href="https://github.com/advthreat/tenzin/pull/3016">#3016</a></li>
</ul>
</blockquote>
<h3 id="scott-mcleod-1-1">Scott McLeod [1]</h3>
<h4 id="iroh-1-5">iroh [1]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>Use filter-map-search directly from CRUDStoreService <a
href="https://github.com/advthreat/iroh/pull/7934">#7934</a></li>
</ul>
</blockquote>
<h3 id="rekha-gupta-2">Rekha Gupta [2]</h3>
<h4 id="tenzin-config-2-2">tenzin-config [2]</h4>
<ul>
<li>fix: to port 4008 because ribbon uses 4007 <a
href="https://github.com/advthreat/tenzin-config/pull/925">#925</a></li>
<li>feat: port for new client management MFE <a
href="https://github.com/advthreat/tenzin-config/pull/924">#924</a></li>
</ul>
<h3 id="jerome-schneider-1-1">Jerome Schneider [1]</h3>
<h4 id="tenzin-1-1">tenzin [1]</h4>
<ul>
<li>SXOPS 801: Kafka connect open port 8083 and use static port in Nomad
<a href="https://github.com/advthreat/tenzin/pull/3059">#3059</a></li>
</ul>
<h3 id="yurii-ivanisenko-2">Yurii Ivanisenko [2]</h3>
<h4 id="tenzin-2-2">tenzin [2]</h4>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>connected self-hosted runner <a
href="https://github.com/advthreat/tenzin/pull/3038">#3038</a></li>
<li>added wokeignore file <a
href="https://github.com/advthreat/tenzin/pull/3036">#3036</a></li>
</ul>
</blockquote>
<h3 id="gayan-jayasundara-2">Gayan Jayasundara [2]</h3>
<h4 id="tenzin-2-3">tenzin [2]</h4>
<ul>
<li>Add Adam as codeowner to Tenzin repo <a
href="https://github.com/advthreat/tenzin/pull/3060">#3060</a></li>
</ul>
<blockquote>
<p><u>&gt;1w</u></p>
<ul>
<li>SXOPS-472 &amp; SXOPS-498 - Enable sentinelone and crowdstrike in
Production for v1.122 Release <a
href="https://github.com/advthreat/tenzin/pull/3031">#3031</a></li>
</ul>
</blockquote>
</body>
</html>