add Scheduled kind to all exisitng templates (solutions + detections)
This commit is contained in:
Родитель
fb86d04235
Коммит
afe1ba6969
|
@ -43,4 +43,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -37,4 +37,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -38,4 +38,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -50,4 +50,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -40,4 +40,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.2.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -35,4 +35,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.2.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -66,4 +66,4 @@ customDetails:
|
|||
DnsQuery: DnsQuery
|
||||
QueryType: QueryType
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -35,4 +35,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.2.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -49,4 +49,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -75,4 +75,4 @@ customDetails:
|
|||
SubType: SubType
|
||||
DnsQuery: DnsQuery
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -46,4 +46,4 @@ entityMappings:
|
|||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -53,4 +53,4 @@ entityMappings:
|
|||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -37,4 +37,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -51,4 +51,4 @@ entityMappings:
|
|||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -39,4 +39,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -39,4 +39,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -36,4 +36,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -38,4 +38,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -37,4 +37,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -40,4 +40,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -37,4 +37,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -70,4 +70,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -37,4 +37,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -38,4 +38,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "DCShadow"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "DCSync"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Golden Ticket"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -27,4 +27,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -27,4 +27,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "OS Credential Dumping: LSASS Memory"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Password Guessing"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -19,4 +19,4 @@ query: |
|
|||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Password Spraying"
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ query: |
|
|||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -58,4 +58,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -67,4 +67,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -56,4 +56,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -55,4 +55,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -71,4 +71,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -71,4 +71,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -58,4 +58,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -78,4 +78,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -69,4 +69,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -58,4 +58,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: TargetUserPrincipalName
|
||||
version: 1.0.1
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -40,4 +40,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -41,4 +41,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -46,4 +46,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -61,4 +61,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -43,4 +43,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -46,4 +46,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -42,4 +42,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: UserIP
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -47,4 +47,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -51,4 +51,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.1.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -20,4 +20,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -20,4 +20,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -46,4 +46,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -31,4 +31,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -28,4 +28,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -55,4 +55,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -34,4 +34,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -43,4 +43,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -39,4 +39,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -40,4 +40,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -59,4 +59,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -42,4 +42,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -57,4 +57,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: DeletingIP
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -39,4 +39,4 @@ query: |
|
|||
strcat('https://dev.azure.com/', OrganizationName, '/', ProjectName, '/_release?_a=releases&view=mine&definitionId=', DefId))
|
||||
| extend timestamp = StartTime
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -45,4 +45,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -62,4 +62,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -40,4 +40,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -41,4 +41,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -58,4 +58,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.1
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -57,4 +57,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -79,4 +79,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.1
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -44,4 +44,4 @@ entityMappings:
|
|||
- identifier: Url
|
||||
columnName: URLCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -34,4 +34,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -41,4 +41,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -32,4 +32,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -32,4 +32,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -80,4 +80,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -33,4 +33,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -38,4 +38,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -51,4 +51,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -36,4 +36,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -33,4 +33,4 @@ entityMappings:
|
|||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
|
@ -29,4 +29,4 @@ entityMappings:
|
|||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
version: 1.0.0
|
||||
kind: scheduled
|
||||
kind: Scheduled
|
Некоторые файлы не были показаны из-за слишком большого количества измененных файлов Показать больше
Загрузка…
Ссылка в новой задаче