This commit is contained in:
Diana Damenova 2023-12-15 15:35:08 -05:00
Родитель 8279ca7d08
Коммит f740f7ca1e
6 изменённых файлов: 16 добавлений и 2 удалений

Просмотреть файл

@ -80,6 +80,8 @@ query: |
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: UserPrincipalName
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix

Просмотреть файл

@ -144,12 +144,16 @@ query: |
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: UserName
- identifier: Name
columnName: AccountName
- identifier: NTDomain
columnName: AccountNTDomain
- entityType: Host
fieldMappings:
- identifier: FullName
columnName: Computer
- identifier: HostName
columnName: HostName
- identifier: NTDomain

Просмотреть файл

@ -80,6 +80,8 @@ query: |
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: UserPrincipalName
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix

Просмотреть файл

@ -69,6 +69,8 @@ query: |
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: Initiatedby
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix

Просмотреть файл

@ -97,6 +97,8 @@ entityMappings:
columnName: FileHashCustomEntity
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: InitiatingProcessAccountName
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix
@ -107,6 +109,8 @@ entityMappings:
columnName: ProcessCustomEntity
- entityType: Host
fieldMappings:
- identifier: FullName
columnName: DeviceName
- identifier: HostName
columnName: HostName
- identifier: NTDomain

Просмотреть файл

@ -54,12 +54,12 @@ query: |
| where StartTime between (UEBAWindowStart .. UEBAWindowEnd)
| project StartTime, EndTime, Subscription, VirtualMachineName, Caller, CallerIpAddress, UEBAEventTime, UEBAActionType, UEBASourceIPLocation, UEBAActivityInsights, UEBAUsersInsights
| extend AccountName = tostring(split(Caller, "@")[0]), AccountUPNSuffix = tostring(split(Caller, "@")[1])
| extend timestamp = StartTime, AccountCustomEntity=Caller
| extend timestamp = StartTime
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: AccountCustomEntity
columnName: Caller
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix