Граф коммитов

1370 Коммитов

Автор SHA1 Сообщение Дата
v-atulyadav 34892ffe41
Merge pull request #7883 from shabaz-github/master
Updating the Analytics Rules and Hunting Queries for Azure Firewall Solution to support Resource Specific logs.
2023-06-13 11:34:05 +05:30
v-dvedak 0c0da96110
Merge pull request #8022 from jszigetvari-nxlog/nxlog-fim-solution-ng
SOLUTION: NXLog FIM (File Integrity Monitoring) (yet again)
2023-06-12 19:00:59 +05:30
v-dvedak 6d6e7dd1b6
Merge pull request #7353 from NCsteven/NetCleanProActive
Initial
2023-06-12 14:00:38 +05:30
mkchiliveri 29e046d5d7 Added validation for KQL query to use Latest TI Data 2023-06-09 16:58:57 +05:30
mkchiliveri 1c58ab217e
Machiliv/solutionidvalidation (#8218)
* Solution ID Validation

* testing

* testing

* testing

* updated the logic

* testing.

* testing

* testing

* testing

* testing

* testing

* testing

* tesing.

* testing

* updated the logic

* testing

* updated error message
2023-06-08 15:30:46 +05:30
mkchiliveri 868efe2185
Solution ID Validation (#8213)
* Solution ID Validation

* testing

* testing

* testing

* updated the logic

* testing.

* testing

* testing

* testing

* testing

* testing

* testing
2023-06-07 20:34:52 +05:30
mkchiliveri 609acffc7c
Machiliv/microsoft sentinel branding (#8170)
* Branding content validation.

* testing.

* updated the code to check if the file content contains the word "Sentinel" without "Microsoft" preceding it

* updated the regex logic

* updated the code to show mutliple errors.

* updated the code find the correct index.

* updated the index value to correct postion.

* testing

* testing.

* testing

* Added skip logic if it contains SentinelOne solution in the file path.

* updated the error message.

* testing

* updated error message.

* reverted testing changes.

* reverted testing changes.

* commented to fix issues.

* commented branding validation for issue fix

* updated the logic to only target the specific attributes.

* removed comments.

* removed comments

* updated correct index

* updated index logic.

* updated index logic.

* updated the error message format.

* updated the error message.

* reverted test changes.

* reverted testing changes.
2023-06-01 13:56:48 +05:30
mkchiliveri 663571edf5
Machiliv/microsoft sentinel branding (#8167)
* Branding content validation.

* testing.

* updated the code to check if the file content contains the word "Sentinel" without "Microsoft" preceding it

* updated the regex logic

* updated the code to show mutliple errors.

* updated the code find the correct index.

* updated the index value to correct postion.

* testing

* testing.

* testing

* Added skip logic if it contains SentinelOne solution in the file path.

* updated the error message.

* testing

* updated error message.

* reverted testing changes.

* reverted testing changes.

* commented to fix issues.

* commented branding validation for issue fix
2023-05-31 14:51:19 +05:30
Janos Szigetvari 46b5ea3a08 SOLUTION: NXLog FIM (File Integrity Monitoring)
This Pull Request should replace
[Replaces PR #5904](https://github.com/Azure/Azure-Sentinel/pull/6264)
related to the issue:
[NXLog FIM Solution v1.0.0 #5904](https://github.com/Azure/Azure-Sentinel/pull/5904)

CHANGES:

- Corrected outdated NXLog documentation URLs
- Handled most of the requests in the open discussion found in the former PR #5904
- Updated Package 1.0.0.zip to 2.0.1.zip
- Added sample log data
- Generated the package with the V2 packaging script
- Addressed all the failing test findings

This work is associated with NXLog's Jira Issue IN-161

Signed-off-by: Janos Szigetvari <janos.szigetvari@nxlog.org>
2023-05-30 12:22:11 +02:00
mkchiliveri f82b4839c1
Branding content validation. (#8120)
* Branding content validation.

* testing.

* updated the code to check if the file content contains the word "Sentinel" without "Microsoft" preceding it

* updated the regex logic

* updated the code to show mutliple errors.

* updated the code find the correct index.

* updated the index value to correct postion.

* testing

* testing.

* testing

* Added skip logic if it contains SentinelOne solution in the file path.

* updated the error message.

* testing

* updated error message.

* reverted testing changes.

* reverted testing changes.
2023-05-30 15:09:34 +05:30
v-dvedak 3fd725414b
Merge pull request #8040 from Azure/SAP-Hunting-queires
Detects high count download from a sensitive SAP Privileged account.
2023-05-29 17:33:32 +05:30
v-dvedak 17d734823b
Merge pull request #8106 from Azure/v-rbajaj/WebShellsThreatProtection
Packaging Web Shells Threat Protection
2023-05-26 15:27:44 +05:30
DixitVedanshi 691994ea05 Update skip validations 2023-05-24 16:36:12 +05:30
DixitVedanshi 209e6a82f3 Merge branch 'master' into v-vdixit/custom-tables-update 2023-05-24 16:05:08 +05:30
Steven Bronkhorst 7f989e8ce8 fixed datetime 2023-05-23 22:52:48 +02:00
v-rbajaj ca6a9f6e61 Packaging Web Shells Threat Protection 2023-05-23 11:29:35 +05:30
v-dvedak a5994fe427
Merge pull request #7716 from Azure/machiliv/DCKQLValidations
Data connector KQL validations
2023-05-19 18:13:47 +05:30
v-dvedak e59a82667e
Merge pull request #8074 from Azure/v-prasadboke-asi
Kusto Services NuGet Package update
2023-05-19 18:07:07 +05:30
mkchiliveri ef98880aae updated the exception handling. 2023-05-19 17:49:41 +05:30
mkchiliveri f7c451694f Fixed issues mentioned in the review comments. 2023-05-19 16:45:40 +05:30
DixitVedanshi 3e1e5de237 Updating skip validations 2023-05-19 16:34:34 +05:30
DixitVedanshi 2603e9b48a Updating skip validations 2023-05-19 16:28:35 +05:30
DixitVedanshi c2c572521c Custom tables update 2023-05-19 16:09:31 +05:30
DixitVedanshi d0437a860b Updating kusto services package file 2023-05-19 15:46:39 +05:30
mkchiliveri 9b02295081 merged with master and added the skip list 2023-05-19 14:52:00 +05:30
mkchiliveri e9abd55cba Merge branch 'master' into machiliv/SolutionSupportObjectValidation 2023-05-18 17:19:20 +05:30
mkchiliveri 54629e44b7 updated exception handling. 2023-05-18 16:03:19 +05:30
mkchiliveri d1b5a35891 testing 2023-05-18 10:25:24 +05:30
PrasadBoke 9f81dc226b asd 2023-05-17 17:35:18 +05:30
Jannie Li 9e96aa6ca6 Add IdentityInfo as a data connector 2023-05-16 10:54:10 -07:00
v-dvedak 838c77bfc0
Merge pull request #7623 from Flared/jct/adding_analytics_rules
Adding more Analytics rules
2023-05-16 12:35:01 +05:30
gitj121 6f79480808 Query for review 2023-05-15 12:34:02 -07:00
Jean-Christophe Taillandier 1483c6e884 Adding more Analytics rules 2023-05-11 09:24:30 -04:00
Steven Bronkhorst 61561aae3a Updated: valid connector IDs 2023-05-08 13:13:41 +02:00
Steven Bronkhorst 1922eab6a0 Fixed broken spaces 2023-05-08 12:09:05 +02:00
Steven Bronkhorst f585ffda9f Fixed CL and analytics rule 2023-05-08 11:30:19 +02:00
v-vdixit 12c6783f74
Update skipvalidations 2023-05-03 12:48:58 +05:30
v-vdixit 356466867d
Merge branch 'master' into v-vdixit/KQL-validation-test-hunting-queries 2023-05-03 11:54:28 +05:30
Steven Bronkhorst 51267ebc16 updated: Netclean_Incidents_CL.json 2023-05-02 12:05:19 +02:00
shabaz-github 261f78d41e
Merge branch 'Azure:master' into master 2023-04-28 12:17:23 +05:30
rahul0216 ffe30be9ca Update SkipValidationsTemplates.json
Removing Template BackupDeletion.yaml
Id "56ebae61-89cf-42d9-99f4-3dff8ba33885" from skip validation file.
2023-04-26 13:04:07 +05:30
shabaz-github 9f5489fdab
Create AZFWThreatIntel.json
Added missing table - AZFWThreatIntel
2023-04-21 00:01:36 +05:30
v-dvedak 82123b4a5a
Merge pull request #7783 from Azure/DNS_Essentials_Various_Changes_PP
Changes before PP
2023-04-20 14:07:37 +05:30
v-dvedak 94e20d1d78
Merge pull request #7853 from sangling/master
Correcting KQL references
2023-04-20 12:43:41 +05:30
Varun Kohli 79c60ecb1d
Merge branch 'master' into DNS_Essentials_Various_Changes_PP 2023-04-20 12:20:08 +05:30
Varun Kohli 260a14862c
DNSEssentials_AddingCustomTable_KQLValidation (#7870)
* DNSEssentials_AddingCustomTable_KQLValidation

* removing DNS queries from skip validation

* re-adding rules in SkipValidation due to error coming. Removing only ConnectionToUnpopularWebsite
2023-04-20 12:06:01 +05:30
vakohl f6a289df3d Remove DNS queries from SkilValidationTemplate file.
Watchlist not being used anymore so removing from skip validation
2023-04-19 18:39:45 +05:30
v-dvedak 5d95b324b8
Merge pull request #7139 from darktrace-com/master
Darktrace for Sentinel 2.1.0
2023-04-19 13:00:53 +05:30
Simon Angling 391fd86ad9
Selling of Validation 2023-04-19 07:15:02 +02:00
v-dvedak a63bd5b273
Merge pull request #7650 from meravcy/CynerioEventSolution
Cynerio Event Solution
2023-04-18 14:31:03 +05:30