Граф коммитов

3570 Коммитов

Автор SHA1 Сообщение Дата
v-atulyadav 5bc1fd2e6d
Update AVSpringShell.yaml 2024-10-07 15:14:14 +05:30
Dwaine Ridderhof 98f0fa0fb7
Correct URL 2024-10-07 10:40:09 +02:00
v-rusraut abe3346766 Update RDP_Nesting.yaml 2024-09-27 14:25:14 +05:30
Sentinel 6d43d593f4 Update RDP_Nesting.yaml 2024-08-28 16:30:39 +05:30
v-atulyadav 3862745808
Merge pull request #10873 from Azure/ashwin/rule-deprecation-july24
Deprecating duplicate rule with same logic
2024-07-29 17:51:33 +05:30
PrasadBoke 51983a7b5d Update ExplicitMFADeny.yaml 2024-07-29 16:59:21 +05:30
Ashwin Patil c0fd1083b6
Merge pull request #10253 from Azure/Entity-Work-April-5
Entity Work April 5 part 1
2024-07-24 17:37:26 -07:00
rahul0216 bbf656b0cb Update imProcess_SolarWinds_SUNBURST_Process-IOCs.yaml 2024-07-16 02:03:46 +05:30
rahul0216 69a2d6cc84 Added TTP wherver missing 2024-07-15 10:28:38 +05:30
v-sabiraj 64b5d72978 Update imAuthSigninsMultipleCountries.yaml 2024-06-28 12:42:06 +05:30
v-sabiraj e59b0ca09a Modified the query just to get user details 2024-06-28 12:15:31 +05:30
v-shukore 01d0f10102 version updated 2024-06-25 11:47:01 +05:30
v-atulyadav bb60e2e081
Merge pull request #10660 from pemontto/new-analytic-newlines
🐛 Remove preceding newlines in queries
2024-06-19 16:47:14 +05:30
pemontto 4b2fca6710
🐛 Remove preceding newlines in queries 2024-06-14 14:23:17 +01:00
Tiago Duarte a75b3744f1
Update AnomalousSingleFactorSignin.yaml
Removed unknown field CrossTenantAccessType
2024-06-14 12:48:42 +01:00
Tiago Duarte 430bb357ca
Update and rename AnomolousSingleFactorSignin.yaml to AnomalousSingleFactorSignin.yaml
Cleaned the code with needed fields, added more fields and extra entities. Also, the name was corrected to Anomalous instead of Anomolous, which is miswritten.
2024-06-14 12:30:51 +01:00
v-shukore 979d54bff5 Merge branch 'master' into Entity-Work-April-5 2024-06-13 16:54:56 +05:30
pemontto 74b0dd1993
🐛 Entity references wrong UPN column 2024-06-11 20:17:31 +01:00
pemontto 9a37033814
🐛 Fix DGA alert name override placeholder 2024-06-06 12:26:27 +01:00
hannah.oneill@cybercx.com.au cbb05d9204 Update versions 2024-05-10 12:36:09 +10:00
hannah.oneill@cybercx.com.au 87223204d0 Reviewed descriptions 2024-05-10 11:24:45 +10:00
Manuel Melendez f913cb89e0 Entity Work April 22
Required items, please complete

   Change(s):
   - Split Account and Host fullnames and removed custom entities

   Reason for Change(s):
   - Need for entity work

   Version Updated:
   - Yes

   Testing Completed:
   - Yes

   Checked that the validations are passing and have addressed any issues that are present:
   -No
2024-04-22 10:34:53 -07:00
Manuel Melendez e96d1f65dc Updating version of these files as checking failed for them 2024-04-22 09:53:18 -07:00
Manuel Melendez 10aae7ba6f Merge branch 'master' of https://github.com/Azure/Azure-Sentinel into Entity-Work-April-5 2024-04-22 09:48:21 -07:00
Manuel Melendez c015a5f148 Fixed Typo 2024-04-16 15:16:42 -07:00
Manuel Melendez c50964aaf0 Entity Work April 16
Required items, please complete

   Change(s):
   - Removing custom entity mappings
   - splitting host and account

   Reason for Change(s):
   - Required for entity work

   Version Updated:
   - yes

   Testing Completed:
   - yes

   Checked that the validations are passing and have addressed any issues that are present:
   - No
2024-04-16 15:01:28 -07:00
Tiago Duarte b0c133d599
Updated version that was missing
Forgot to update the version, thought it wasn't needed for such a small change.
2024-04-11 14:33:43 +01:00
Tiago Duarte 46fc992d31
Fixed IP entity
There was a typo SouceIPMax instead of SourceIPMax
2024-04-11 10:42:05 +01:00
Manuel Melendez f94b1cb862 Rerunning checks 2024-04-10 20:18:44 -07:00
Shain 544a7282de
Merge pull request #10255 from Azure/Entity-Work-April-5-pt2
Entity-Work-April-5-pt2
2024-04-08 11:26:33 -07:00
Manuel Melendez 5b1e18b737 Removed timestamp 2024-04-08 09:29:13 -07:00
Manuel Melendez e5ab0a7d8a Removed timestamp 2024-04-08 09:25:50 -07:00
Manuel Melendez 24370686d6 Fixed another typo 2024-04-05 13:04:47 -07:00
Manuel Melendez 7a592e67dc Entity-Work-April-5-pt2
Required items, please complete

   Change(s):
   - Deleted custom entites
  - Split host into hostname and dnsdoman
  - split account into name and upn suffix

   Reason for Change(s):
   - See guidance below

   Version Updated:
   - Required only for Detections/Analytic Rule templates
   - See guidance below

   Testing Completed:
   - See guidance below

   Checked that the validations are passing and have addressed any issues that are present:
   - See guidance below

# Guidance <- remove section before submitting
-----------------------------------------------------------------------------------------------------------
## Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:

Thank you for your contribution to the Microsoft Sentinel Github repo.

> Details of the code changes in your submitted PR.  Providing descriptions for pull requests ensures there is context to changes being made and greatly enhances the code review process.  Providing associated Issues that this resolves also easily connects the reason.

   Change(s):
   - Updated syntax for XYZ.yaml

   Reason for Change(s):
   - New schema used for XYZ.yaml
   - Resolves ISSUE #1234

   Version updated:
   - Yes
   - Detections/Analytic Rule templates are required to have the version updated

> The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly.  If your submission requires a custom parser or function, it must be submitted with the PR.

   Testing Completed:
   - Yes/No/Need Help

_Note: If updating a detection, you must update the version field._

> Before the submission has been made, please look at running the KQL and Yaml Validation Checks locally.
> https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally

   Checked that the validations are passing and have addressed any issues that are present:
   - Yes/No/Need Help

   _Note: Let us know if you have tried fixing the validation error and need help._

> References:
> - [Guidance for Detection checks](https://github.com/Azure/Azure-Sentinel#pull-request-detection-template-structure-validation-check)
> - [General contribution guidance](https://github.com/Azure/Azure-Sentinel/wiki#what-can-you-contribute-and-how-can-you-create-contributions)
> - [PR validation troubleshooting](https://github.com/Azure/Azure-Sentinel#pull-request)

-----------------------------------------------------------------------------------------------------------
2024-04-05 13:01:51 -07:00
Manuel Melendez 19b09f01b0 Fixed typo 2024-04-05 12:24:34 -07:00
Manuel Melendez 97f4ff6809 Entity Work April 5 part 1
Required items, please complete

   Change(s):
   - Deleted Custom Entity mappings
   - Split hostname and domain
   - Split name and UPN suffix

   Reason for Change(s):
   - Needed to add full mappings

   Version Updated:
   - yes

   Testing Completed:
   - yes

   Checked that the validations are passing and have addressed any issues that are present:
   - no
2024-04-05 12:05:38 -07:00
Shain 62267e05d8
Update ServicePrincipalAssignedPrivilegedRole.yaml 2024-02-27 06:56:33 -08:00
Shain 2886c4430d
Merge pull request #10050 from Azure/shainw-Dev-0228-entitymapFix
Update imFileEvent_Dev-0228FilePathHashesNovember2021(ASIMVersion).yaml
2024-02-26 12:00:31 -08:00
Shain 9c3216a6f1
Update imFileEvent_Dev-0228FilePathHashesNovember2021(ASIMVersion).yaml 2024-02-26 11:20:46 -08:00
Shain f660c73bef
Update imProcess_AdFind_Usage.yaml 2024-02-26 08:07:10 -08:00
Shain 94cfcb8028
Update Accountcreatedfromnon-approvedsources.yaml 2024-01-25 07:47:15 -08:00
Shain 44469351a8 version 2024-01-22 08:30:26 -08:00
Shain 922d1b59c6 Fixing customer reported bugs 2024-01-22 08:26:03 -08:00
Shain 9d2a99a0ec
Merge pull request #9706 from Azure/EntityWorkJan3
EntityWorkJan3 - Manny
2024-01-09 09:12:31 -08:00
Manuel Melendez dd422c4ca8 One more fix 2024-01-09 08:51:01 -08:00
Murali Krishna Dev Uppugunduri db7eeabea7 Merge branch 'master' into users/v-muuppugundu/MultipleRDPIssues 2024-01-08 12:57:30 +05:30
v-atulyadav 623de5bf61
Merge pull request #9730 from tduarte14/master
Changed runtime to every 2h instead of 1d for 2 rules
2024-01-08 11:05:48 +05:30
v-atulyadav 3286a7a962 version updated 2024-01-08 10:37:35 +05:30
Tiago Duarte 02a8bddf62
Added missing version number update
Added missing version number update
2024-01-06 11:46:17 +00:00
Tiago Duarte 1f65ac1374
Fixed wrong account parsing in AuditLog block
Fixed wrong account parsing in AuditLog block
2024-01-06 11:39:49 +00:00