This commit is contained in:
Avinash Iyer 2021-10-29 15:44:57 -07:00
Родитель 768e6f6806
Коммит 39af9c354f
9 изменённых файлов: 9 добавлений и 9 удалений

Просмотреть файл

@ -1,5 +1,5 @@
id: 999e9f5d-db4a-4b07-a206-29c4e667b7e8
name: TI map Domain entity to Dns Events (Normalized DNS)
name: (Preview) TI map Domain entity to Dns Events (Normalized DNS)
description: |
Identifies a match in DNS events from any Domain IOC from TI
To use this analytics rule, make sure you have deployed the [ASIM normalization parsers](https://aka.ms/AzSentinelDns).

Просмотреть файл

@ -1,5 +1,5 @@
id: 67775878-7f8b-4380-ac54-115e1e828901
name: TI map IP entity to Dns Events (Normalized DNS)
name: (Preview) TI map IP entity to Dns Events (Normalized DNS)
description: |
Identifies a match in DNS events from any IP IOC from TI
To use this analytics rule, make sure you have deployed the [ASIM normalization parsers](https://aka.ms/AzSentinelDns).

Просмотреть файл

@ -1,5 +1,5 @@
id: cca3b4d9-ac39-4109-8b93-65bb284003e6
name: Email entity to AzureActivity
name: TI map Email entity to AzureActivity
description: |
'Identifies a match in AzureActivity table from any Email IOC from TI'
severity: Medium

Просмотреть файл

@ -1,5 +1,5 @@
id: 2fc5d810-c9cc-491a-b564-841427ae0e50
name: Email entity to SecurityEvent
name: TI map Email entity to SecurityEvent
description: |
'Identifies a match in SecurityEvent table from any Email IOC from TI'
severity: Medium

Просмотреть файл

@ -47,5 +47,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.1.0
version: 1.0.0
kind: Scheduled

Просмотреть файл

@ -1,5 +1,5 @@
id: f9949656-473f-4503-bf43-a9d9890f7d08
name: IP entity to AppServiceHTTPLogs
name: TI map IP entity to AppServiceHTTPLogs
description: |
'Identifies a match in AppServiceHTTPLogs from any IP IOC from TI'
severity: Medium

Просмотреть файл

@ -1,5 +1,5 @@
id: 69b7723c-2889-469f-8b55-a2d355ed9c87
name: IP entity to DnsEvents
name: TI map IP entity to DnsEvents
description: |
'Identifies a match in DnsEvents from any IP IOC from TI'
severity: Medium

Просмотреть файл

@ -1,5 +1,5 @@
id: 5e45930c-09b1-4430-b2d1-cc75ada0dc0f
name: IP entity to W3CIISLog
name: TI map IP entity to W3CIISLog
description: |
'Identifies a match in W3CIISLog from any IP IOC from TI'
severity: Medium

Просмотреть файл

@ -1,5 +1,5 @@
id: 106813db-679e-4382-a51b-1bfc463befc3
name: URL entity to PaloAlto data
name: TI map URL entity to PaloAlto data
description: |
'Identifies a match in PaloAlto data from any URL IOC from TI'
severity: Medium