Hello,
We currently utilize the Windows Defender ATP v 3.6.0 app in our Splunk SOAR Cloud instance. I've discovered that the 'run query' action utilizes an outdated advancedqueries api endpoint that does not expose all of the tables available in Advanced Hunting.
I'd like to update the 'run query' action to use the advancedhunting api endpoint that has the proper tables exposed. I'm familiar with the code and where this needs to be updated, but not on how to create a custom version of this app.
What is the proper way to customize the app and install it in our SOAR cloud?
... View more