Skip to content

SOCRadar v2.3.0: Add complete integration suite#43732

Open
Radargoger wants to merge 36 commits intodemisto:contrib/Radargoger_socradar-pack-v2.2.2from
Radargoger:socradar-pack-v2.2.2
Open

SOCRadar v2.3.0: Add complete integration suite#43732
Radargoger wants to merge 36 commits intodemisto:contrib/Radargoger_socradar-pack-v2.2.2from
Radargoger:socradar-pack-v2.2.2

Conversation

@Radargoger
Copy link
Copy Markdown
Contributor

@Radargoger Radargoger commented Mar 29, 2026

Contributing to Cortex XSOAR Content

Make sure to register your contribution by filling the contribution registration form

The Pull Request will be reviewed only after the contribution registration form is filled.

Status

  • In Progress
  • Ready
  • In Hold - (Reason for hold)

Related Issues

Description

This PR adds three new integrations to the SOCRadar pack (v2.2.2):

  1. SOCRadar Rapid Reputation - Fast reputation checking for IPs, domains, URLs, and file hashes with bulk support (up to 100 indicators) and automatic rate limiting.

  2. SOCRadar IoC Enrichment - Deep threat intelligence enrichment with signal strength, confidence levels, activity labels, premium feeds, relations, and optional AI insights.

  3. SOCRadar Threat Feed - Collection-based IoC feed integration for automated indicator ingestion using collection UUIDs with incremental feed capability and comprehensive geolocation data.

All integrations follow Cortex XSOAR best practices, include comprehensive documentation, and are production-ready.

Must have

  • Tests - Unit tests included for Threat Feed (14 test cases, all passing)
  • Documentation - Complete README files for all three integrations with commands, examples, and configuration guides

Changes

  • Added Integrations/FeedSOCRadarThreatFeed/ (new)
  • Added Integrations/SOCRadarRapidReputation/ (new)
  • Added Integrations/SOCRadarIoCEnrichment/ (new)
  • Updated pack_metadata.json to version 2.2.2
  • Updated main README.md with all three integrations
  • Added ReleaseNotes/2_2_2.md

Testing

All integrations have been tested with valid SOCRadar API keys:

  • API connectivity verified
  • All commands tested and working
  • DBot score integration validated
  • Error handling confirmed
  • Rate limiting verified (Rapid Reputation)
  • Feed ingestion tested (Threat Feed)

relates: https://jira-dc.paloaltonetworks.com/browse/CIAC-16413

@content-bot content-bot added Partner-Approved Contribution Form Filled Whether contribution form filled or not. Partner Contribution Thank you! Contributions are always welcome! External PR Partner Support Level Indicates that the contribution is for Partner supported pack labels Mar 29, 2026
@content-bot content-bot changed the base branch from master to contrib/Radargoger_socradar-pack-v2.2.2 March 29, 2026 16:27
@content-bot
Copy link
Copy Markdown
Contributor

Thank you for your contribution. Your generosity and caring are unrivaled! Make sure to register your contribution by filling the Contribution Registration form, so our content wizard @kamalq97 will know the proposed changes are ready to be reviewed.
For your convenience, here is a link to the contributions SLAs document.

@content-bot
Copy link
Copy Markdown
Contributor

Hi @Radargoger, thanks for contributing to the XSOAR marketplace. To receive credit for your generous contribution please follow this link.

@content-bot
Copy link
Copy Markdown
Contributor

🤖 AI-Powered Code Review Available

Hi @kamalq97, @MosheEichler, you can leverage AI-powered code review to assist with this PR!

Available Commands:

  • @marketplace-ai-reviewer start review - Initiate a full AI code review
  • @marketplace-ai-reviewer re-review - Incremental review for new commits

@Radargoger Radargoger changed the title SOCRadar v2.2.2: Add complete integration suite SOCRadar v2.3.0: Add complete integration suite Mar 29, 2026
- Fix README.md markdown formatting for pre-commit compliance
- Update pack version from 2.2.2 to 2.3.0
- Rename release notes: 2_2_2.md -> 2_3_0.md
- Add missing sections: SOCRadar Incidents, Incidents v4
- Fix header spacing and consistent formatting
- Correct support email to operation@socradar.io
@kamalq97 kamalq97 removed their request for review March 30, 2026 06:38
@kamalq97 kamalq97 assigned MosheEichler and unassigned kamalq97 Mar 30, 2026
@SOCRadar
Copy link
Copy Markdown
Contributor

approved

@Radargoger
Copy link
Copy Markdown
Contributor Author

Hi @MosheEichler and @kamalq97 ,

I have finalized all the necessary steps for this contribution. The PR is now ready to be reviewed and merged.

Completed Actions:

Pre-commit Checks: All local and CI pre-commit tests are now passing (including ruff, black, mypy, and markdownlint).

Formatting & Linting: Resolved all trailing whitespace, line length, and Python 3.9+ type hint requirements.

Secrets Detection: All dummy data and false positives have been addressed; the secrets_detection check is clear.

Partner Approval: The contribution has been marked as Partner-Approved.

Registration: The Contribution Registration Form has been filled and verified (label is active).

Documentation: Comprehensive READMEs and Release Notes (v2.3.0) are included and follow XSOAR standards.

All integrations (Rapid Reputation, IoC Enrichment, and Threat Feed) are production-ready and fully tested.

the PR is ready for your final review.

Thank you!
Burak
Senior Product Manager
Enterprise API & Integration Team Lead

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Contribution Form Filled Whether contribution form filled or not. Contribution Thank you! Contributions are always welcome! External PR Partner Support Level Indicates that the contribution is for Partner supported pack Partner Partner-Approved TIM Review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants