This commit is contained in:
v-dvedak 2024-02-14 15:16:51 +05:30
Родитель b431777e77
Коммит d4d725e50c
21 изменённых файлов: 21 добавлений и 21 удалений

Просмотреть файл

@ -1,4 +1,4 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------------|
| 3.0.0 | 31-07-2023 | Updated prerequisites for AbuseIPDB-BlacklistIpToThreatIntelligence playbook |
| | | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| | | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -2,6 +2,6 @@
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.2 | 07-02-0024 | Updated solution description |
| 3.0.1 | 02-01-2024 | Tagged for dependent solutions for deployment |
| 3.0.0 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|---------------------------------------------------------------------------|
| 3.0.0 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -2,5 +2,5 @@
|-------------|--------------------------------|---------------------------------------------------------------------------|
| 3.0.2 | 07-02-2024 | Tagged for dependent solutions for deployment |
| 3.0.1 | 23-01-2024 | Added subTechniques in Template |
| 3.0.0 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,7 +1,7 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.1 | 23-01-2024 | Added subTechniques in Template |
| 3.0.0 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| | | Optimized the **Analytic Rule** query logic to achieve expected results |

Просмотреть файл

@ -2,5 +2,5 @@
|-------------|--------------------------------|------------------------------------------------------------------------------------------|
| 3.0.3 | 17-01-2024 | Updated Azure Firewall **Data Connector** to support resource specific logs. |
| 3.0.2 | 15-12-2023 | Updated query in **Analytical Rule** (Port Scan) |
| 3.0.1 | 21-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.1 | 21-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.0 | 20-07-2023 | Updated **Workbook** template to remove unused variables. |

Просмотреть файл

@ -1,4 +1,4 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.1 | 27-11-2023 | Added new Entity Mappings to **Analytic Rules** |
| 3.0.0 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,3 +1,3 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.0 | 28-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID & MS 365 Defender to MS Defender XDR |
| 3.0.0 | 28-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID & MS 365 Defender to MS Defender XDR |

Просмотреть файл

@ -2,4 +2,4 @@
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.2 | 09-02-2024 | Tagged for dependent solutions for deployment |
| 3.0.1 | 16-01-2024 | Sub-techniques added for **Analytical Rules** |
| 3.0.0 | 07-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 07-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.0 | 07-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 07-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,6 +1,6 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|-----------------------------------------------------------------------------------------|
| 3.0.3 | 07-11-2023 |Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.3 | 07-11-2023 |Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.2 | 10-08-2023 |Added the missing userAssignedIdentities field for UserAssigned type in the **Playbooks**|
| 3.0.1 | 21-07-2023 |Updated the description in the solution |
| 3.0.0 | 11-07-2023 |Updated the title, logo and the description in the solution |

Просмотреть файл

@ -1,3 +1,3 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|------------------------------------------------------------------------------|
| 3.0.1 | 28-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID & MS 365 Defender to MS Defender XDR |
| 3.0.1 | 28-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID & MS 365 Defender to MS Defender XDR |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.0 | 07-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 07-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|--------------------------------------------------------------------------|
| 3.0.1 | 01-12-2024 | Added **Playbooks** for enhanced solution workflows. |
| 3.0.0 | 11-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 11-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -4,7 +4,7 @@
| 3.0.10 | 26-12-2023 | 1 **Analytic Rule** Modified by adding "GroupMembership" instead of "Admin" condition for better extraction of admin accounts from the identity infotable. |
| 3.0.9 | 28-11-2023 | 2 **Analytic Rules** Modified by Adding Entity Mapping to (GuestAccountsAddedinAADGroupsOtherThanTheOnesSpecified.yaml) and Changed timerange of (SigninPasswordSpray.yaml) from 3d to 1d. |
| 3.0.8 | 21-11-2023 | 1 **Analytic Rules** Fixed issue that was causing multiple triggers for the same event. |
| 3.0.7 | 06-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.7 | 06-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.6 | 30-10-2023 | 1 **Data Connector** added back in the solution. |
| 3.0.5 | 19-10-2023 | 1 **Analytic Rules** updated in the solution (PIMElevationRequestRejected). |
| 3.0.4 | 16-10-2023 | 1 **Analytic Rules** got added in the solution (SuspiciousSignInFollowedByMFAModification), modified workbook query to fix duplicate locations for the query. |

Просмотреть файл

@ -1,6 +1,6 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|--------------------------------------------------------------------------|
| 3.0.4 | 07-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.4 | 07-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.3 | 10-10-2023 | Updated **Workbook** template to replace the datatype InformationProtectionLogs_CL to MicrosoftPurviewInformationProtection |
| 3.0.2 | 04-10-2023 | Updated **Workbook** template to fix Signinlogs datatype |
| 3.0.1 | 20-09-2023 | Updated **Workbook** template to fix the invaild json issue |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|---------------------------------------------------------------------------|
| 3.0.1 | 10-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.1 | 10-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
| 3.0.0 | 06-07-2023 | Updating **Analytic rule** query for KQL failure |

Просмотреть файл

@ -1,4 +1,4 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|--------------------------------------------------------------------------|
| 3.0.0 | 11-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 11-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,4 +1,4 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|-----------------------|
| 3.0.0 | 11-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 11-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -1,5 +1,5 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|----------------------------------------------------------------------------|
| 3.0.0 | 07-11-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 07-11-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |

Просмотреть файл

@ -2,6 +2,6 @@
|-------------|--------------------------------|--------------------------------------------------------------------------------------------|
| 3.0.2 | 23-01-2024 | Added Sub-Technique in Template |
| 3.0.1 | 13-12-2023 | Updated query in **Analytical Rule** (AD user enabled and password not set within 48 hours)|
| 3.0.0 | 26-12-2023 | Changes for rebranding from Azure Active Directory to Microsoft Entra ID |
| 3.0.0 | 26-12-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |