OctoMation Orchestration & Automation

repository·main·Indexed 19 days ago

https://github.com/flagify-com/octomation

A community-edition Orchestration & Automation (O&A) platform by HoneyGuide SOAR. It provides a low-code/no-code visual playbook editor to automate complex workflows in cybersecurity, IT operations, and network management. Key features include visual playbook orchestration, integration with 450+ products via HTTP/HTTPS, SSH, Telnet, and RESTful APIs, data ingestion via Kafka and Syslog, and an open SDK for custom application development.

Tokens
3.1K
Snippets
2
Records
10
Agent score
68%

What's inside OctoMation

  1. Overview of OctoMation Orchestration & Automation

    main

    OctoMation (Octopus Orchestration & Automation) is a community free version of the HoneyGuide SOAR product. It is a low-code/no-code orchestration and automation platform designed to automate workflows across network security, IT operations, and service management.

    Key Capabilities:

    • Visual Playbook Orchestration: Use a visual canvas to drag and drop nodes including actions, rules, approvals, polling, virtual nodes, and collection nodes. Supports advanced logic like loops, nested playbooks, and functions.
    • Extensive Connectivity: Supports integration with 450+ mainstream products (security, network, IT, and SaaS) via protocols like HTTP/HTTPS, SSH, Telnet, and RESTful APIs.
    • Data Ingestion: Receives upstream information via Kafka, Syslog, and other methods to trigger automated workflows.
    • Extensibility: Provides an open SDK and visual development tools for users to build custom application integrations.
  2. Compare OctoMation Community and HoneyGuide Commercial Editions

    main

    OctoMation offers two primary versions: the OctoMation Community Edition and the HoneyGuide Commercial Edition.

    OctoMation Community Edition

    • Event Management: Receives events via API, Syslog, and Kafka. Supports log parsing using CSV, Key/Value, delimiters, JSON, CEF, and Regular Expressions. Includes general field mapping and security event type binding.
    • Applications: Includes an application security capability management interface, an online IDE/debugging tool for APP development, template language rendering, and support for Java/Python. Access to open-source community applications.
    • Playbooks (剧本): Features visual playbook orchestration with support for actions, rules, sub-playbooks, approval, virtual, and collection nodes. Supports advanced functions like loops, functions, and delays, as well as playbook import/export and community playbooks.
    • Collaborative War Room (协同作战室): Creates independent war rooms for each event. Supports multi-user collaboration (text, images, files), adding personnel, executing playbooks/actions via menus, and visualizing execution status. Supports bookmarking playbooks/actions and marking security evidence.
    • Advanced Features: Includes basic collection functions, custom general field management, containerized deployment, and orchestration automation APIs.
    • Support & Licensing: 5x8 community support, 2 online users, 1-year renewable license, and non-commercial use only.

    HoneyGuide Commercial Edition

    • Enhanced Event Management: Adds custom event deduplication rules, event lifecycle cards, event element graphs, and an event knowledge base.
    • Enhanced Applications: 450+ integrated mainstream product capabilities and custom development for private security capabilities.
    • Enhanced Playbooks: Adds playbook permission management (user/role), AI-recommended nodes during orchestration, built-in AssetWise asset management, and 100+ playbook best practices.
    • Enhanced War Room: Adds natural language interaction via security action bots and knowledge base Q&A bots, OCR for chat images, context-aware playbook/action recommendations, command prompt execution, and advanced chat features (read receipts, quotes, withdrawals, group announcements, search, and focus mode).
    • Enhanced Advanced Features: AI enhancement, million-level IP list collections, enhanced security features, distributed deployment, high availability, and domestic innovation (信创) support.
    • Additional Modules: Lego-style visual dashboards, visual workflow tickets, security protection special modules, security monitoring modules, and command/war modules.
    • Support & Customization: Professional SOAR original support, consulting, and delivery teams; 7x24 technical support via phone; SSO integration, and custom feature/capability adaptation.
    • Licensing: Flexible, on-demand customization.
  3. Quickstart Guides for OctoMation

    main

    For new users, the following guides are recommended to get started:

    • Create your first Playbook: Learn how to build automated workflows.
    • First Event Ingestion: Learn how to bring external events into OctoMation.
    • First App Development: Learn how to develop custom application integrations using the SDK.
    https://github.com/flagify-com/OctoMation/wiki/%E6%88%91%E7%9A%84%E7%AC%AC%E4%B8%80%E4%B8%AAOctoMation-Playbook
    https://github.com/flagify-com/OctoMation/wiki/%E6%88%91%E7%9A%84%E7%AC%AC%E4%B8%80%E4%B8%AAOctoMation-%E4%BA%8B%E4%BB%B6%E6%8E%A5%E5%85%A5
    https://github.com/flagify-com/OctoMation/wiki/%E6%88%91%E7%9A%84%E7%AC%AC%E4%B8%80%E4%B8%AAOctoMation-%E5%BA%94%E7%94%A8APP%E5%BC%80%E5%8F%91
  4. Import Community Playbooks and Apps

    main

    After installation, you can create your own assets or import pre-built community packages:

    • Application Capability Packages (APP): Import existing application integrations.
    • Scenario Playbook Packages: Import pre-configured playbooks for specific use cases.

    Refer to the specific documentation for AppPackages.md and PlaybookPackages.md for details on how to import these files.

  5. Install and upload application APPs to OctoMation

    main

    To extend OctoMation's capabilities, you can upload application APPs.

    1. Download the required APP installation package.
    2. Access the OctoMation application management interface at https://<OCTOMATION_SERVER>/apps.
    3. Click 【上传应用】 (Upload App).

    Note: After uploading, some APPs may require configuration of resource parameters such as IP, Port, Account, Password, or API KEY.

    https://<OCTOMATION_SERVER>/apps
  6. Activate OctoMation Community Free Version

    main

    To use the community free version, you must import a free authorization License.

    1. Apply for License: Visit the OctoMation Community Free License Application page or scan the QR code provided in the documentation.
    2. Import License: Once you receive the authorization file, log in to the OctoMation system and import it.

    Tip: It is recommended to add octomation_support@wuzhi-ai.com to your email server's whitelist to ensure you receive the license file.

  7. Import and configure OctoMation Playbook Packages

    main

    To use a new playbook package in OctoMation, follow these steps:

    1. Download: Download the desired .conf playbook file from the repository.
    2. Upload: Access the OctoMation playbook management interface at https://<OCTOMATION_SERVER>/playbook_list and click the 【导入】 (Import) button to upload the file.
    3. Configure: After uploading, you must manually edit the playbook content once. Update the relevant applications and parameters to match your local environment settings.
    4. Run: Once configured, the playbook is ready for execution.
  8. Reference list of Network Tool APPs

    main

    The following network tools are available for download and integration into OctoMation. Most require specific API credentials or configuration parameters after installation.

    Application NameVendorManual/DocsDownload Link
    IPdatabase IPinfoIPinfoAPI DocsDownload
    微步在线V3 (Threatbook)微步在线API DocsDownload
    消息通知-钉钉 (DingTalk)钉钉API DocsDownload
    Kafka ClientKafkaN/ADownload
    HTTP Client雾帜智能N/ADownload
    SSH Client雾帜智能N/ADownload
    RSS Client雾帜智能N/ADownload
    Toolbox雾帜智能N/ADownload
    Scamalytics Threat IntelScamalyticsN/ADownload
    X军刀 (xKnife)雾帜智能N/ADownload
    AppDemo雾帜智能N/ADownload
    VirusTotal Threat IntelvirustotalAPI DocsDownload
    alienVault Threat IntelalienVaultAPI DocsDownload
    GitHub AssistantGitHubAPI DocsDownload
    Aliyun WAF阿里云API DocsDownload
    EMAIL Tool雾帜智能N/ADownload
    企业微信 (WeCom)雾帜智能API DocsDownload
  9. Available OctoMation Playbook Packages

    main

    The following playbooks are available for download and use within OctoMation:

    Playbook NameDescriptionContributorDownload Link
    IP地址信息增强Queries IP address geographic information through multiple channels.J0hnFFFFPlaybook IP_Enrich.conf
    RSS新闻收集器Collects latest information via RSS. (Recommended RSS URL: https://www.4hou.com/feed)J0hnFFFFPlaybook RSS新闻收集器
    网页安全监测Checks for illegal keywords on websites and detects large-scale web page changes.J0hnFFFFPlaybook 网页安全监测
    cve漏洞订阅Subscribes to CVE vulnerability updates.wzygmPlaybook cve漏洞订阅
    自动封禁-阶梯封禁Automated tiered banning. Connect to events to perform automatic banning/disposal for security incidents.wzygmPlaybook 自动封禁-阶梯封禁