changes
This commit is contained in:
Родитель
407c87bfea
Коммит
f63fc0ed91
|
@ -35,5 +35,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -37,5 +37,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -36,5 +36,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -39,5 +39,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -36,5 +36,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -69,5 +69,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -36,5 +36,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -37,5 +37,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "DCShadow"
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "DCSync"
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Golden Ticket"
|
||||
|
||||
version: 1.0.0
|
|
@ -26,5 +26,4 @@ query: |
|
|||
| where MessageType == 2
|
||||
| lookup kind=leftouter SeverityTable on Severity
|
||||
| order by Level
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "OS Credential Dumping: LSASS Memory"
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Password Guessing"
|
||||
|
||||
version: 1.0.0
|
|
@ -18,5 +18,4 @@ relevantTechniques:
|
|||
query: |
|
||||
afad_parser
|
||||
| where MessageType == 2 and Codename == "Password Spraying"
|
||||
|
||||
version: 1.0.0
|
|
@ -57,5 +57,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -55,5 +55,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -73,5 +73,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -68,5 +68,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -52,5 +52,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -60,5 +60,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -42,5 +42,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -45,5 +45,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -46,5 +46,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -51,5 +51,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -19,5 +19,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -19,5 +19,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -33,5 +33,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -38,5 +38,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -39,5 +39,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -58,5 +58,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -41,5 +41,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -56,5 +56,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: DeletingIP
|
||||
|
||||
version: 1.0.0
|
|
@ -39,5 +39,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -40,5 +40,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -52,5 +52,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -56,5 +56,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -73,5 +73,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -43,5 +43,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: URLCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -69,5 +69,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -34,5 +34,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -79,5 +79,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -121,5 +121,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: DomainName
|
||||
columnName: Name
|
||||
|
||||
version: 1.0.0
|
|
@ -63,5 +63,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -58,5 +58,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -82,5 +82,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -32,5 +32,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -50,5 +50,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -49,5 +49,4 @@ entityMappings:
|
|||
columnName: FileHashType
|
||||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -45,5 +45,4 @@ entityMappings:
|
|||
columnName: MD5
|
||||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -48,5 +48,4 @@ entityMappings:
|
|||
columnName: MD5
|
||||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -49,5 +49,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -40,5 +40,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -40,5 +40,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -33,5 +33,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -36,5 +36,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: URLCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -32,5 +32,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -35,5 +35,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -13,5 +13,4 @@ query: |
|
|||
GitHubRepo
|
||||
| where Action == "vulnerabilityAlert"
|
||||
| project TimeGenerated, DismmisedAt, Reason, vulnerableManifestFilename, Description, Link, PublishedAt, Severity, Summary
|
||||
|
||||
version: 1.0.0
|
|
@ -43,5 +43,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -27,5 +27,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -36,5 +36,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -31,5 +31,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -30,5 +30,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: AccountCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -64,5 +64,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -77,5 +77,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -75,5 +75,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -51,5 +51,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -50,5 +50,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -89,5 +89,4 @@ entityMappings:
|
|||
columnName: HashAlgorithm
|
||||
- identifier: Value
|
||||
columnName: FileHashCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -125,5 +125,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -89,5 +89,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -152,5 +152,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -171,5 +171,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -81,5 +81,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -70,5 +70,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -95,5 +95,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -102,5 +102,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -53,5 +53,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -70,5 +70,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -143,5 +143,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -95,5 +95,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -47,5 +47,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -95,5 +95,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -52,5 +52,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -88,5 +88,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -101,5 +101,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: DomainName
|
||||
columnName: DNSName
|
||||
|
||||
version: 1.0.0
|
|
@ -52,5 +52,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: URLCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -81,5 +81,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -107,5 +107,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -53,5 +53,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -71,5 +71,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -33,5 +33,4 @@ query: |
|
|||
| where authAttempts > 500
|
||||
| extend timestamp = firstAttempt
|
||||
| sort by uniqueAccounts
|
||||
|
||||
version: 1.0.0
|
|
@ -35,5 +35,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -40,5 +40,4 @@ entityMappings:
|
|||
|
||||
|
||||
|
||||
|
||||
version: 1.0.0
|
|
@ -82,5 +82,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: FullName
|
||||
columnName: HostCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -54,5 +54,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -98,5 +98,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: DomainName
|
||||
columnName: DNSName
|
||||
|
||||
version: 1.0.0
|
|
@ -81,5 +81,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
|
@ -114,5 +114,4 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
|
||||
version: 1.0.0
|
Некоторые файлы не были показаны из-за слишком большого количества измененных файлов Показать больше
Загрузка…
Ссылка в новой задаче