Граф коммитов

613 Коммитов

Автор SHA1 Сообщение Дата
Ofer Shezaf 5400c23507 Change EventOriginalId to EventOriginalType 2021-07-29 17:45:04 +03:00
caroline-sacumen 437b89a85c
Merge branch 'master' into Illusive 2021-07-28 12:25:45 +05:30
Yaron 294fe33f20
Adding new Authentication Alert (#2746)
* renaming M365Defender to comply conventions
2021-07-27 18:46:56 +03:00
Itai Yankelevsky 6d43761537 wip 2021-07-27 12:47:02 +03:00
Itai Yankelevsky b81bf23b6b Add playbook template metdata validations 2021-07-27 12:44:23 +03:00
v-jayakal d67e832e1c
Merge pull request #2583 from socprime/ImpervaCloudWAF
ImpervaWAF: dataconnector, parser, samples
2021-07-26 21:40:12 -07:00
v-jayakal 13d2df0ebc
Merge pull request #2576 from IronNetCybersecurity/IronNet-IronDefense-Solution
IronNet IronDefense Solution Initial Version
2021-07-26 10:59:28 -07:00
Cameron Dahr b41ec122f7 Updated Sonrai Security Solution 2021-07-26 12:08:19 -03:00
Cameron Dahr 45cbcc9dfe Updated Sonrai Security Solution 2021-07-26 10:34:10 -03:00
v-jayakal 490c4b694b
Merge pull request #2415 from Azure/v-rucdu/EventConnectorTemplate
Add Event connector template and updated tests
2021-07-25 14:32:59 -07:00
v-maudan 5a5b90ffa8 Updated latest custom table schema 2021-07-23 17:30:16 +05:30
v-maudan 9e2b30408e Fixed PR validation issues 2021-07-23 16:44:31 +05:30
Caroline Palha c7af1be05d Initial Commit for Illusive Playbooks 2021-07-22 17:45:06 +05:30
Vitalii Uslystyi bbe50dfa89 gcp iam - add connector id to ValidConnectorIds.json to pass tests 2021-07-19 16:31:31 +03:00
Vitalii Uslystyi bf5cddccb0 gcp iam - update fields mapping for kql tests 2021-07-19 15:21:11 +03:00
Vitalii Uslystyi bfc9fd9467 gcp iam - add mapping for parser to pass kql validation tests in rules 2021-07-19 15:16:54 +03:00
Amit Bergman e0549275b1
Update ValidConnectorIds.json 2021-07-19 08:25:08 +03:00
Yaron cc6d578e27
Dns Version 0.1.1 (#2683)
* Updating to match documentation

* improving OSSEM compatibility

* updating ARM templates

* update alerts to use V011. infoblox json syntax

* updating imDns Custom table
2021-07-15 21:06:55 +03:00
v-jayakal 8ba61bd0ff
Merge pull request #2586 from socprime/cisco_duo_connector
Cisco Duo Data Connector
2021-07-14 21:56:41 -07:00
Shain a0d23ac88f
Merge pull request #2638 from andedevsecops/githubfunctionsecretscanning
Updates to GitHub Custom table JSON
2021-07-14 13:01:06 -07:00
v-jayakal 64f3b9feb1
Merge pull request #2514 from ericlanteigne-semperis/DirectoryServicesProtector
Semperis DirectoryServicesProtector connector for Azure Sentinel
2021-07-13 22:42:17 -07:00
Sreedhar Ande 263105e038 removed Template Id:aac495a9-feb1-446d-b08e-a1164a539452 2021-07-12 09:43:03 -07:00
Sreedhar Ande f52269448b Merge branch 'master' of https://github.com/Azure/Azure-Sentinel into githubfunctionsecretscanning 2021-07-12 07:36:08 -07:00
v-rucdu 43bad3a170 Skip data connector validation for event datatype 2021-07-09 15:18:36 +05:30
v-rucdu f4c396f744 Fix for Events Datatype 2021-07-09 15:09:02 +05:30
Sreedhar Ande 98af45aad8 Updated GitHub Repo Custom table JSON 2021-07-07 17:03:11 -07:00
Sreedhar Ande ae9d990e7d CustomTable json updated 2021-07-07 16:52:29 -07:00
Alex Verbniak a9d7102b2f ImpervaWAF: fix conn page, zip archive, schema 2021-07-07 09:52:40 +03:00
Shain Wray (MSTIC) 3f4fbc604b Updating to proper column name and removing validation exception 2021-07-06 22:44:02 -07:00
v-jayakal ca92600995
Merge pull request #2506 from socprime/gcp_dns_connector
GCP DNS Data Connector
2021-07-06 17:49:41 -07:00
v-rucdu 87c74fcd51 Fix for Data Connector Validations 2021-07-06 14:50:08 +05:30
Caroline Palha 3441137581 Fixed Analytic rule validation erros 2021-07-01 22:43:56 +05:30
Ofer Shezaf 4e1cc4cb4a
Merge pull request #2553 from Azure/dev/Authentication
First commit - take 2
2021-07-01 11:03:03 +03:00
Igal Shapira 79269ec6e7 Merge branch 'master' into origin/dev/process_events 2021-07-01 10:32:26 +03:00
v-jayakal c47bb815b2
Merge pull request #2507 from socprime/InsightVMCloud
InsightVMCloud: data_connector,parsers,datasamples
2021-06-30 22:28:12 -07:00
Vitalii Uslystyi 6f1123cdd8 cisco duo - add mapping 2021-06-29 17:43:51 +03:00
Ofer Shezaf 3c7a1c7488
Merge pull request #2537 from Azure/yaronfr/2021/Jun/M365DNwS
Adding M365D to NwS and converting to new format
2021-06-29 16:13:57 +03:00
Alex Verbniak 73c9cf00ab ImpervaWAF: dataconnector, parser, samples 2021-06-29 14:00:53 +03:00
v-jayakal a23ff174f5
Merge pull request #2418 from socprime/gcp_iam_connector
GCP IAM Data Connector
2021-06-24 20:31:46 -07:00
v-jayakal 40c429d5fe
Merge pull request #2417 from socprime/TenableNessus
TenableNessus: added io and sc dataconnectors, parser, data sample
2021-06-24 20:16:10 -07:00
v-jayakal bbc4ab79c2
Merge pull request #2249 from tj-senserva/master
Update to Senserva format and queries
2021-06-23 23:18:05 -07:00
Amit Bergman 5a85c66301 commit 2021-06-23 19:06:55 +03:00
Amit Bergman 67f1062215 Update DetectionTemplateSchemaValidationTests.cs
improve test
2021-06-23 19:05:53 +03:00
Yaron Fruchtmann 05ece4934c updateing folder structure, adding custom table 2021-06-23 16:07:09 +03:00
Yaron Fruchtmann 78a8ccf995 typos in file names 2021-06-23 13:50:04 +03:00
Yaron Fruchtmann b63509de42 Authentication Initial deployment- take 2 2021-06-23 13:45:25 +03:00
Ofer Shezaf 8e7fba8732 Add missing fields to empty parser 2021-06-23 12:29:16 +03:00
Ofer Shezaf 9156406cf9 Fix ProcessCreation -> ProcessCreate 2021-06-23 11:26:55 +03:00
Ofer Shezaf 5da84de3ba Add KQL validation custom tables 2021-06-23 11:18:26 +03:00
Alex Verbniak 7281e29184 InsightVMCloud: fixes 2021-06-23 10:31:15 +03:00
v-jayakal c9b22fde50
Merge pull request #2508 from socprime/gcp_monitor_connector
GCP Monitoring Data Connector
2021-06-22 15:58:47 -07:00
Yaron Fruchtmann bcbd3d0f1b Adding custom table - imAuthentication 2021-06-22 13:36:04 +03:00
v-jayakal 533d32054d
Merge pull request #2478 from gate6/master
Lookout Workbook and Analytic Rule updated
2021-06-21 15:59:25 -07:00
v-jayakal 59ceefb46e
Merge pull request #2414 from socprime/JuniperIDP
JuniperIDP: data connector, parser, samples
2021-06-21 14:40:59 -07:00
ericlanteigne-semperis d560abf43b Semperis DirectoryServicesProtector connector for Azure Sentinel 2021-06-17 09:40:05 -04:00
Vitalii Uslystyi abca3c48ee gcp monitor - add mapping file 2021-06-17 15:30:10 +03:00
Alex Verbniak 34bb70895a InsightVMCloud: data_connector,parsers,datasamples 2021-06-17 15:09:20 +03:00
Vitalii Uslystyi 96fb7d82ef gcp dns - ad mapping file 2021-06-17 15:02:20 +03:00
Rajendra Khabiya ee3b996fa4
Merge branch 'master' into master 2021-06-15 12:25:08 +05:30
Rajendra Khabiya 3104779b54 Table details and Data connector id added 2021-06-15 12:20:32 +05:30
v-jayakal 73a6ef5086
Merge pull request #2473 from Azure/v-rucdu/LogoValidationExtensionToSolutionsWorkbookFolder
Extended validation for workbook logos
2021-06-14 08:35:05 -07:00
v-jayakal ad704793b0
Merge pull request #2380 from adirDev/CognniDataConnector
Add Cognni's Analytic Rule Templates
2021-06-14 07:51:35 -07:00
tj-senserva 4265ce945f
Merge pull request #15 from Azure/master
Bringing up to date
2021-06-14 09:38:40 -05:00
v-rucdu 383f7fccc6 Extended validation for workbook logos 2021-06-14 19:17:09 +05:30
Yaron 6c3986b281
DNS Normalization - Parsers and content (#2379)
* Adding DNS parsers. ARM Query templates. 
* Adding ASim versions for alert rules
* Adding support for DNS schema to existing detections
2021-06-14 13:10:47 +03:00
v-jayakal 4c98a3c186
Merge pull request #2402 from Azure/v-rucdu/PRValidationFixesForSolutionsFolder
Extension of PR Validations to solutions folder
2021-06-13 22:18:59 -07:00
Shain 2cad1a602c
Merge pull request #2281 from t-shaviv/shaharBranch2
Azure Activity columns alignments
2021-06-13 09:57:18 -07:00
v-jayakal 6e4f1e7832
Merge pull request #1832 from Azure/AADUserData
AADUserInfo Function
2021-06-10 10:24:08 -07:00
Amit Bergman 9c9e5d85d7 fixes 2021-06-10 20:05:57 +03:00
Amit Bergman 5ad478092a
Update ScheduledTemplateInternalModel.cs 2021-06-10 18:52:30 +03:00
Amit Bergman 4f6beb686e
Create NoTemplateVersionWithoutTemplateName.cs 2021-06-10 18:52:05 +03:00
Amit Bergman 7064dbb10e
add validation on templateVersion 2021-06-10 18:50:25 +03:00
Lior Tamir 518875e35c
Merge pull request #2431 from ityankel/feature/ityankel/fixFalingValidation
Fix regression due to playbook validation
2021-06-09 13:00:21 +03:00
v-jayakal 79ab895e50
Merge pull request #2375 from socprime/cisco_seg_data_connector
Cisco SEG Data Connector
2021-06-08 16:05:03 -07:00
Itai Yankelevsky 1640a99830 Fix regression due to playbook validation 2021-06-08 14:55:17 +03:00
v-jayakal a35d776f34
Merge pull request #2422 from Azure/duoconnector2
Add DuoSecurity Tables to validation
2021-06-07 22:19:46 -07:00
dicolanl cd232e7f0d Update ValidConnectorIds.json 2021-06-07 22:15:10 +00:00
dicolanl 9b1bf4bd7c Add DuoSecurity Tables to validation 2021-06-07 22:10:43 +00:00
Vitalii Uslystyi 30b2481d19 GCP IAM - add sample data 2021-06-07 16:15:01 +03:00
Alex Verbniak ce1f5e2b95 TenableNessus: added io and sc dataconnectors, parser, data sample 2021-06-07 16:07:15 +03:00
v-rucdu 8c0e0a52a5 Add Event connector template and updated tests 2021-06-07 17:20:48 +05:30
Alex Verbniak d575f40c26 JuniperIDP: data connector, parser, samples 2021-06-07 12:02:25 +03:00
dicolanl 7a1c26dd25 Fixes
Moved to solutions folder
Added sample data
Added CL Schema
2021-06-04 16:51:40 +00:00
Thomas Dolan d0d43fa9ce merge 2021-06-04 10:03:43 -05:00
v-rucdu 0cd0b05801 Removed all references of Advanced settins blade 2021-06-04 18:33:22 +05:30
v-rucdu 2875e51a4b Handled validation for parsers under solutions folder 2021-06-04 17:17:13 +05:30
v-rucdu 59e992e434 Handled scenario for Validations in Parsers 2021-06-04 17:10:24 +05:30
v-rucdu fa983a9db0 Extended validation to Solutions folder 2021-06-04 16:55:32 +05:30
v-rucdu 3d3d89eb22 Handle Event type connectors 2021-06-04 12:11:08 +05:30
v-rucdu 83317a8a7d Updated idchange validator condition 2021-06-04 01:12:46 +05:30
v-rucdu 041365ba26 Removed unwanted import 2021-06-04 01:08:34 +05:30
v-rucdu 2ec59c3b3e updated logo file check 2021-06-04 01:05:37 +05:30
v-rucdu af93075a06 updates 2021-06-04 00:47:09 +05:30
v-rucdu 06c32e1dad Updated logo validator 2021-06-04 00:38:09 +05:30
v-rucdu c07c1b6585 Updated logo validation condition 2021-06-04 00:14:06 +05:30
v-rucdu 17fa95c0b9 Updated folder path for solutions 2021-06-04 00:00:14 +05:30
v-rucdu d823d05f26 Added check for Data COnnectors/ Logo folder 2021-06-03 20:29:10 +05:30
v-rucdu 59d53ab3cc Fixes for PR Validations 2021-06-03 19:36:54 +05:30
Vitalii Uslystyi 70d5e9a67c Cisco SEG connector - rename fields 2021-06-03 16:29:05 +03:00
Vitalii Uslystyi 478fa3780f Cisco SEG - update connector 2021-06-02 16:54:36 +03:00
adirDev c0de339a37 Add 'CognniIncidents_CL.json' to CustomTables 2021-05-30 15:58:25 +03:00
adirDev 59915e0232 Revert "Add 'CognniIncidents_CL.json' to CustomTables"
This reverts commit bed6680098.
2021-05-30 15:54:48 +03:00
adirDev bed6680098 Add 'CognniIncidents_CL.json' to CustomTables 2021-05-30 15:49:46 +03:00
adirDev 0b83e86d3c
Merge branch 'master' into CognniDataConnector 2021-05-30 15:19:45 +03:00
adirDev 145a19ba46 PR fixes
- Update ValidConnectorIds.json with 'CognniSentinelDataConnector' id
- Add 'version' to all yaml files
2021-05-30 15:17:10 +03:00
Lior Tamir 25d62eade2
Merge pull request #2332 from ityankel/feature/playbookValidations
Add basic playbooks validations
2021-05-30 12:12:27 +03:00
Vitalii Uslystyi 91b1784aa2 Cisco SEG - add data connector, parser and sample data 2021-05-28 16:58:15 +03:00
Amit Bergman c06b718fc3
Update ValidConnectorIds.json 2021-05-27 11:39:14 +03:00
v-jayakal 46b6220e5d
Merge pull request #2242 from dmaasland/master
Add ESET PROTECT connector
2021-05-26 12:35:19 -07:00
Donny Maasland e4d021ef31
add esetportect to validconnectorids 2021-05-26 10:25:40 +02:00
v-jayakal a6f6275b4b
Merge pull request #2144 from Azure/v-maudan/ExtendDetectionValidationToSolution
Extend detection validation to solution folder
2021-05-25 21:38:28 -07:00
Donny Maasland da73b26c7e
add table schema 2021-05-25 14:03:07 +02:00
Itai Yankelevsky ad545e49eb add UT for playbook resource 2021-05-23 13:40:16 +03:00
Itai Yankelevsky 3231bbd390 update UT 2021-05-23 13:25:31 +03:00
Itai Yankelevsky 7de0d096ee fix ARM template schema 2021-05-23 13:24:27 +03:00
Itai Yankelevsky 55f6d0c6bf Add UT 2021-05-23 12:38:05 +03:00
Itai Yankelevsky a70e2e2263 Add basic playbook validations 2021-05-23 12:29:55 +03:00
t-shaviv 3500009baa fixed test script 2021-05-19 13:48:27 +03:00
t-shaviv f0a66629d3 fixed test script 2021-05-19 13:37:39 +03:00
t-shaviv 22caf9bc2e fixed test script 2021-05-19 13:30:15 +03:00
v-maudan 0f03512291 Added Version to analytics present in solution 2021-05-19 15:39:41 +05:30
t-shaviv 0c6c4fecb2 Merge branch 'master' into shaharBranch2 2021-05-19 10:12:21 +03:00
v-maudan 9df1232a11 Merge branch 'master' into v-maudan/ExtendDetectionValidationToSolution 2021-05-18 13:54:31 +05:30
v-maudan f289e9f838 Merge branch 'master' into v-maudan/KQLDetectionValidationToSolution 2021-05-18 13:33:26 +05:30
Amit Bergman 4ce8e8acab
Merge pull request #2299 from Azure/feature/ambergma/fixTest
Update DetectionTemplateSchemaValidationTests.cs
2021-05-17 11:53:03 +03:00
Amit Bergman ef63688040 Update DetectionTemplateSchemaValidationTests.cs 2021-05-17 11:50:46 +03:00
t-shaviv d64dee1097 Merge branch 'shaharBranch2' of https://github.com/t-shaviv/Azure-Sentinel into shaharBranch2 2021-05-13 12:22:31 +03:00
t-shaviv d60a9e9c8a update nuget file 2021-05-13 12:20:03 +03:00
Amit Bergman 407c87bfea changes 2021-05-11 08:45:08 +03:00
Amit Bergman 952f8823b2
Update SkipValidationsTemplates.json 2021-05-06 13:54:29 +03:00
Amit Bergman 9ca59e8dc7 Fix files to be jsons 2021-05-06 13:39:44 +03:00
Amit Bergman da78ec2774
Update SkipValidationsTemplates.json 2021-05-06 13:13:40 +03:00
Amit Bergman 98acf16b1b
Update LAQueryLogs 2021-05-06 12:58:28 +03:00
Amit Bergman c714780d41
Create LAQueryLogs 2021-05-06 12:57:28 +03:00
Thomas Dolan e3532abb72 Updating data format, updating queries to match new data format 2021-05-04 15:57:21 -05:00
Pete Bryan 42143326dc Removed validation skip 2021-05-03 07:48:02 -07:00
v-maudan 629cdd9ac5 Update KqlValidationTests.cs 2021-04-27 18:51:07 +05:30
v-maudan 0a27d16a37 Merge branch 'master' into v-maudan/KQLDetectionValidationToSolution 2021-04-27 18:16:08 +05:30
v-maudan 3e8816ec35 updated variable names 2021-04-27 12:37:40 +05:30
v-maudan 17e866ab1d Fixed PR review comments 2021-04-21 11:33:44 +05:30
v-maudan 4014056e01 Updated missing data connector id from solution folder and updadted dupliicate guid 2021-04-21 10:31:49 +05:30
v-maudan 43ebefe1ef fixed PR review comments 2021-04-21 09:42:20 +05:30
v-maudan 0a59ac3c33
Merge branch 'master' into v-maudan/ExtendDetectionValidationToSolution 2021-04-21 09:28:50 +05:30
Amit Bergman f98f2c2d52
Update ValidConnectorIds.json 2021-04-20 19:51:23 +03:00
Amit Bergman 12f2370dfd
Update ValidConnectorIds.json 2021-04-20 19:50:57 +03:00
Amit Bergman c3723247b9
Update ValidConnectorIds.json 2021-04-20 18:43:17 +03:00
Amit Bergman af80fc3c6d
Update ValidConnectorIds.json 2021-04-20 18:42:54 +03:00
Amit Bergman 4e5e15c576
Update ValidConnectorIds.json 2021-04-20 18:41:59 +03:00
Amit Bergman 003ca2f1fc
Update ValidConnectorIds.json 2021-04-20 18:03:04 +03:00
Amit Bergman 3f5b4cdf04
Update ValidConnectorIds.json 2021-04-20 14:59:20 +03:00
v-jayakal bb603c2d48
Merge pull request #2147 from socprime/ping_federate_content
Ping Federate Content
2021-04-16 09:54:13 -07:00
v-maudan b21c2cfad6 Fixed PR review comments 2021-04-16 16:44:39 +05:30
v-maudan 4ccad3bcb7
added ContrastProtect connector id in ValidConnectorIds.json 2021-04-16 16:29:35 +05:30
v-maudan 2ab5f79a17 Removed empty readme.md file and updated count for same 2021-04-16 15:18:10 +05:30
v-jayakal 2163caf2be
Merge pull request #2024 from K-Patel-NC/KP_NucleusCyber_NCProtect
Kp nucleus cyber nc protect
2021-04-15 13:48:03 -07:00
Vitalii Uslystyi 92e9c3a4a1 ping federate - add mapping 2021-04-15 12:51:36 +03:00
v-maudan ea8408c15e removed commented code 2021-04-15 12:08:02 +05:30
v-maudan a0573bc20c Extend kql detection validation to solution folder 2021-04-15 12:05:40 +05:30
v-maudan 0f61e5f6f8 updated code 2021-04-15 09:25:34 +05:30
v-maudan ac3e66823b removed additonal try catch block 2021-04-14 19:02:54 +05:30
v-maudan 670fd66b7a Extending detection PR validation for solution folder 2021-04-14 17:51:58 +05:30
Amit Bergman 9322269b44
Merge branch 'master' into Amitbergman-patch-28 2021-04-13 19:08:56 +03:00
Amit Bergman 79a5117b1a remove unneeded code 2021-04-12 09:35:13 +03:00
Amit Bergman d475094160 Update KqlValidationTests.cs 2021-04-12 09:33:05 +03:00
Amit Bergman b319cb2e90 fix 2021-04-12 09:32:08 +03:00
Amit Bergman ab56292dbb More expressive model of whitelist 2021-04-12 09:31:17 +03:00
Amit Bergman 0379c4439b
Update SkipValidationsTemplates.json 2021-04-12 09:29:42 +03:00
v-jayakal e40a87e692
Merge pull request #2060 from socprime/prisma_cloud_data_conn
Palo Alto Prisma Cloud Data Connector
2021-04-09 00:03:59 -07:00
v-rucdu 67d91d91a3 Added check to validate workbook json 2021-04-08 14:59:45 +05:30
v-rucdu dc7a61f9af Fix for PR validations 2021-04-08 10:27:06 +05:30
v-jayakal 87629396c1
Merge pull request #1992 from socprime/ConfluenceAudit
Confluence audit
2021-04-06 21:56:20 -07:00
roabadie-microsoft a6c444e7c4
Add test to verify version incrementation on workbook template modifi… (#2080)
* Add test to verify version incrementation on workbook template modification
2021-04-06 15:45:15 +03:00
Amit Bergman edbbc49db6
Remove AzureNetworkAnalytics_CL template from whitelist
Update SkipValidationsTemplates.json
2021-04-06 13:02:58 +03:00
Amit Bergman 60d1457f8e
Update AzureNetworkAnalytics_CL.json 2021-04-06 13:01:01 +03:00
Amit Bergman aebe1978ba
Update AzureNetworkAnalytics_CL.json 2021-04-06 13:00:12 +03:00
Amit Bergman 6b0d31c702
Update SkipValidationsTemplates.json 2021-04-06 12:52:47 +03:00
Amit Bergman 88ac927ac9
Create AzureNetworkAnalytics_CL.json 2021-04-06 12:50:40 +03:00
v-jayakal 9d8a617b68
Merge pull request #2050 from socprime/WorplaceFacebook
WorkplaceFacebook: connector+parser+schema
2021-04-06 00:28:55 -07:00
v-jayakal 2c95f0f18a
Merge pull request #2028 from socprime/oracle_web_logic_server
Oracle Web Logic Server Data Connector
2021-04-05 00:15:43 -07:00
Amit Bergman d13cef0be3
Merge pull request #2074 from Azure/updateNuget
Create microsoft.azure.sentinel.kustoservices.1.0.13.nupkg
2021-04-04 15:58:18 +03:00
Amit Bergman 39a79b1981
Update Kqlvalidations.Tests.csproj 2021-04-04 14:54:48 +03:00
Amit Bergman 5a840e6d2f Create microsoft.azure.sentinel.kustoservices.1.0.13.nupkg 2021-04-04 14:52:41 +03:00
Amit Bergman 8feb18736c Update DetectionTemplateSchemaValidationTests.cs 2021-04-04 13:43:45 +03:00
Vitalii Uslystyi 0ef391f9b5 prisma cloud - add mapping 2021-04-01 17:45:02 +03:00
Alex Verbniak 7dfa441aed WorkplaceFacebook: connector+parser+schema 2021-03-31 14:40:48 +03:00
v-jayakal 7bc16dd799
Merge pull request #2006 from socprime/zpa_data_conn
ZPA Data Connector
2021-03-31 00:42:51 -07:00
v-jayakal b2b2c4f4f1
Merge pull request #1988 from socprime/tomcat_data_conn
Tomcat Data Connector
2021-03-30 23:24:35 -07:00
v-jayakal cd360c6101
Update ValidConnectorIds.json 2021-03-30 23:21:20 -07:00
v-jayakal 853aa28d06
Merge pull request #2004 from socprime/corelight_rules_and_queries
Corelight Rules and Queries
2021-03-30 23:14:45 -07:00
v-ampami 886cc9b134 Added CustomTable JSON with the Parser name(Corelight.json) 2021-03-31 11:36:41 +05:30
v-jayakal c49e8b61f6
Merge pull request #2019 from socprime/cloudflare_rules_and_queries
Cloudflare rules and queries
2021-03-30 22:42:11 -07:00
v-maudan 0f669c4326 Added CustomTable JSON with the Parser name(Cloudflare.json) 2021-03-31 11:05:53 +05:30
v-ampami f76b6ed5bd
Merge branch 'master' into ubiquiti_data_conn 2021-03-30 13:02:25 +05:30
v-ampami ce81a52c0a Adding Dataconnector Id in Detection Template Schema validation 2021-03-30 12:58:48 +05:30
Sergiy Prystaiko b3d631abb3 OracleWebLogicServer - add data connector 2021-03-29 13:54:45 +03:00
tj-senserva e6cab59daf
Merge pull request #5 from Azure/master
Bringing up to Date
2021-03-26 13:36:53 -05:00
Shain ed882ad61e
Update ValidConnectorIds.json (#2023)
Adding in Solutions connectors that are valid
2021-03-25 14:29:41 -07:00
tj-senserva 0e386b2b4f
Merge pull request #4 from Azure/master
Bringing Up To Date
2021-03-25 09:24:46 -05:00
v-jayakal c4a913585a
Merge pull request #1995 from socprime/ZoomReports
Zoom reports
2021-03-24 23:01:27 -07:00
Thomas Dolan 41c2874ccf Adding Multiple Workspace Workbook 2021-03-24 17:45:38 -05:00
Thomas Dolan 13736fa3e5 Resolving merge conflicts 2021-03-24 09:25:38 -05:00
Vitalii Uslystyi 93ee4622f1 Merge branch 'master' into box_rules_and_queries 2021-03-24 11:37:41 +02:00
Shain 227614b88f
Merge pull request #1796 from socprime/SlackAuditConnector
SlackAudit: dataconnector+workbook
2021-03-23 20:40:58 -07:00
Shain 6741ab7e8a
Merge pull request #1801 from socprime/oracle_db_audit_rules_and_queries
Add Oracle DB Audit Parser and Rules
2021-03-23 20:33:23 -07:00
Thomas Dolan b8bdbb9553 Merge in Updates 2021-03-23 15:22:46 -05:00
Vitalii Uslystyi 15f3ab7111 zpa - add mapping 2021-03-23 19:17:51 +02:00
v-rucdu b5d263b90a Added connector id to valid connector ids json 2021-03-23 12:19:27 +05:30
v-jayakal 66b39e221e
Merge pull request #1799 from socprime/mcafeeepo_parser_and_rules
McAfeeePO Parser and Rules
2021-03-22 22:19:03 -07:00
v-rucdu 033330b696 Added McAfeeePO connectorId to ValidateConnectorIds json 2021-03-23 10:38:21 +05:30
v-jayakal 35ef5ce6ea
Merge pull request #1917 from socprime/exabeam_data_conn
Exabeam Data Connector
2021-03-22 21:20:56 -07:00
Thomas Dolan 33ef927c3a typo 2021-03-22 17:06:53 -05:00
Thomas Dolan d7dcf4a714 typo 2021-03-22 17:00:57 -05:00
Thomas Dolan e718a98d0f Adding Sample Data Schema 2021-03-22 16:52:50 -05:00
Shain Wray (MSTIC) 50421e0425 adding in TimeGenerated and Action to CustomTable JSON to pass final validation issues 2021-03-22 13:44:09 -07:00
Thomas Dolan f22caa79c9 Merge branch 'master' into senserva-tj 2021-03-22 13:42:39 -05:00
Alex Verbniak f83a9e1478 ZoomReports: table, parser, sample 2021-03-22 16:23:57 +02:00
Alex Verbniak 2e8a0694ec ConfluenceAudit: table schema,parser,samples 2021-03-22 15:34:21 +02:00
v-jayakal c5280bc226
Merge pull request #1951 from socprime/cloudflare_data_conn
Cloudflare Data Connector
2021-03-22 05:39:45 -07:00
Sergiy Prystaiko 0f4e37cf09 tomcat - add mapping 2021-03-22 13:06:01 +02:00
K-Patel-NC 9bef531ea9 rename file 2021-03-22 11:38:08 +11:00
K-Patel-NC 7885b5b2fe Sample Data in Json format and CSV format added 2021-03-22 10:11:29 +11:00
K-Patel-NC b83686734c Logo, TableSchema, Json Related changes added 2021-03-19 11:30:52 +11:00
Amit Bergman de4cc65870
Update SkipValidationsTemplates.json 2021-03-18 08:43:26 +02:00
Amit Bergman 02aa2e95c0
Update KqlValidationTests.cs 2021-03-18 08:40:13 +02:00
Amit Bergman f23ccf6fa6
Update PulseConnectSecure.json 2021-03-18 08:38:34 +02:00
Amit Bergman 6c549cb735
Update InfobloxNIOS.json 2021-03-18 08:38:06 +02:00
Amit Bergman 17c776446a
Update SkipValidationsTemplates.json 2021-03-18 08:14:39 +02:00
Amit Bergman 9d37360471
Update SkipValidationsTemplates.json 2021-03-18 08:11:01 +02:00
Amit Bergman 75e797883c
Update SkipValidationsTemplates.json 2021-03-18 08:07:07 +02:00
Amit Bergman 08ec1acf0b
Update SkipValidationsTemplates.json 2021-03-18 08:03:39 +02:00
Amit Bergman 631338fe41
Update SkipValidationsTemplates.json 2021-03-18 08:02:36 +02:00
Amit Bergman 0e8d8d2a0c
Update KqlValidationTests.cs 2021-03-18 07:57:58 +02:00
Amit Bergman 70f2acaa92
Update SkipValidationsTemplates.json 2021-03-18 07:57:07 +02:00
Amit Bergman 7d7cfca3ca
Update SkipValidationsTemplates.json 2021-03-18 07:52:41 +02:00
Amit Bergman 8db5326f04
Update SkipValidationsTemplates.json 2021-03-18 07:47:26 +02:00
Thomas Dolan a260a91087 Data Connector 2021-03-16 15:23:46 -05:00
v-jayakal a50aeb71ae
Merge pull request #1898 from socprime/Crowdstrike-FDR
CrowdstrikeFDR
2021-03-16 12:32:07 -07:00
v-rucdu 7161df23ba
Added Box connector Id to ValidConnectorIds json 2021-03-16 13:11:24 +05:30
v-rucdu ee02cae67b
Merge branch 'master' into SlackAuditConnector 2021-03-16 10:27:24 +05:30
Amit Bergman 3dd7578ba4
Merge pull request #1933 from Azure/addTestsToTemplates
Update DetectionTemplateSchemaValidationTests.cs
2021-03-15 21:06:24 +02:00
Vitalii Uslystyi 64aa88091b cloudflare - added mapping 2021-03-15 20:59:48 +02:00
Amit Bergman 659ec435f8
Update DetectionTemplateSchemaValidationTests.cs 2021-03-15 20:33:21 +02:00
Amit Bergman 8450d74a1b
Update DetectionTemplateSchemaValidationTests.cs 2021-03-15 20:28:35 +02:00
Amit Bergman 3b24c07878
Update DetectionTemplateSchemaValidationTests.cs 2021-03-15 20:25:29 +02:00
Amit Bergman 878f634c74
Merge pull request #1935 from Azure/RemoveUnsupportedTactics
Update AttackTactic.cs
2021-03-15 18:57:23 +02:00
dicolanl 7974737f08
Merge pull request #1929 from oshvartz/UpdateKustoNugetUpdtingAppServiceHTTPLogs
Update kusto validation nuget  - update appServiceHttpLogs Schema
2021-03-15 07:40:42 -07:00
Amit Bergman ebbab06da3
Update AttackTactic.cs 2021-03-14 20:42:57 +02:00
Amit Bergman fb8cbdb0f7
Update DetectionTemplateSchemaValidationTests.cs 2021-03-14 16:29:12 +02:00
Amit Bergman 7547869b29
Update DetectionTemplateSchemaValidationTests.cs 2021-03-14 13:09:47 +02:00
Amit Bergman 2c688ea494
Update DetectionTemplateSchemaValidationTests.cs 2021-03-14 12:54:06 +02:00