Azure-Sentinel/Solutions
v-shukore 4ccd215e46 Updated ReleaseNote.json 2024-10-28 16:57:59 +05:30
..
1Password Solution packaged 2024-10-21 14:04:49 +05:30
42Crunch API Protection solution branding validation 2024-07-15 15:09:28 +05:30
AI Analyst Darktrace Repackaged for OMS Migration 2024-07-12 11:43:23 +05:30
AIShield AI Security Monitoring
ALC-WebCTRL
ARGOSCloudSecurity Update ExploitableSecurityIssues.yaml 2024-07-16 09:43:42 +05:30
AWS Systems Manager
AWSAthena Solution packaged for updating the post deployment steps of playbook 2024-08-09 15:35:08 +05:30
AWS_IAM
AbnormalSecurity Packaging from Python 3.8 till 3.11 (#4) 2024-10-22 14:05:48 +05:30
AbuseIPDB
Agari
AgileSec Analytics Connector
Akamai Security Events Solution packaged 2024-08-21 16:26:03 +05:30
Alibaba Cloud Updated Release Notes 2024-09-11 10:36:32 +05:30
Alsid For AD
Amazon Web Services Test 2024-07-26 11:30:02 +05:30
Apache Log4j Vulnerability Detection log4j packaged 2024-07-26 18:48:52 +05:30
ApacheHTTPServer Apache Http Service 2024-08-13 11:25:37 +05:30
AristaAwakeSecurity updated solutionMetadata and mainTemplate 2024-07-10 12:51:31 +05:30
Armis Added latest code after merge conflicts 2024-09-11 15:20:36 +05:30
Armorblox Update ArmorbloxAzureFunction.zip 2024-09-11 11:50:34 +05:30
Aruba ClearPass Arubaclearpass updated 2024-07-11 14:38:15 +05:30
AtlassianConfluenceAudit Updated Release Notes 2024-09-09 15:46:34 +05:30
AtlassianJiraAudit Update ReleaseNotes.md 2024-09-02 14:35:35 +05:30
Attacker Tools Threat Protection Essentials
Australian Cyber Security Centre
Auth0 Update ReleaseNotes.md 2024-09-09 16:06:36 +05:30
Authomize Update Stale_IAAS_policy_attachment_to_role.yaml 2024-07-16 01:25:19 +05:30
Azure Activity
Azure Batch Account
Azure Cloud NGFW by Palo Alto Networks Update ReleaseNotes link 2024-07-26 09:33:43 -07:00
Azure Cognitive Search
Azure DDoS Protection
Azure Data Lake Storage Gen1
Azure Event Hubs
Azure Firewall Merge branch 'master' into v-shukore/Azure_firewall-entra-mde-log4j 2024-07-31 17:04:51 +05:30
Azure Key Vault Updated ReleaseNote.json 2024-10-28 16:57:59 +05:30
Azure Logic Apps
Azure Network Security Groups
Azure SQL Database solution for sentinel Updated ReleaseNote.json 2024-10-28 16:57:59 +05:30
Azure Service Bus
Azure Storage
Azure Stream Analytics
Azure Web Application Firewall (WAF)
Azure kubernetes Service
AzureDevOpsAuditing Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-22 21:23:13 +05:30
AzureSecurityBenchmark
BETTER Mobile Threat Defense (MTD)
Barracuda CloudGen Firewall Repackage - Barracuda CloudGen Firewall (OMS Migration) 2024-07-18 15:17:46 +05:30
Barracuda WAF updated solutionMetaData and mainTemplate 2024-07-10 12:27:53 +05:30
Beyond Security beSECURE
BitSight Fixed CodeQl error 2024-09-30 15:52:19 +05:30
Bitglass Update ReleaseNotes.md 2024-10-28 15:11:17 +05:30
Bitwarden updated publisher id 2024-10-03 15:50:40 +01:00
Blackberry CylancePROTECT Repackage - Blackberry CylancePROTECT (OMS Migration) 2024-07-18 16:32:13 +05:30
BloodHound Enterprise
Box Updated Python version to 3.11 2024-08-21 13:55:43 +05:30
Broadcom SymantecDLP Broadcom upadted 2024-07-11 14:42:42 +05:30
Business Email Compromise - Financial Fraud
CTERA Solution packaged 2024-10-25 11:20:34 +05:30
CTM360 Release Notes Updated 2024-09-27 13:56:29 +05:30
Check Point
CheckPhish by Bolster
Cisco ACI Repackaged - Cisco ACI 2024-07-23 18:28:05 +05:30
Cisco ETD Cisco-ETD-3.11-version-update 2024-09-18 16:23:56 +05:30
Cisco Firepower EStreamer updated packages 2024-07-11 12:34:07 +05:30
Cisco ISE Revert "Solution package for ttp changes" 2024-07-31 17:50:45 +05:30
Cisco Meraki Events via REST API Update ReleaseNotes.md 2024-09-30 13:01:59 +05:30
Cisco SD-WAN Updated analytic rules for missing TTPs 2024-07-16 02:12:39 +05:30
Cisco Secure Cloud Analytics Cisco Secure Cloud Analytics 2024-07-24 13:39:05 +05:30
Cisco Secure Endpoint CSE Solution packaged 2024-09-10 13:00:37 +05:30
Cisco UCS Update ReleaseNotes.md 2024-08-01 17:14:40 +05:30
CiscoASA
CiscoDuoSecurity Python Version Updated to 3.11 in CiscoDuo 2024-08-28 18:14:37 +05:30
CiscoMeraki Solution packaged 2024-08-20 15:46:58 +05:30
CiscoSEG Update ReleaseNotes.md 2024-07-22 17:05:28 +05:30
CiscoUmbrella Merge branch 'master' into dependabot/pip/Solutions/CiscoUmbrella/Data-Connectors/urllib3-1.26.19 2024-10-23 18:05:27 +05:30
CiscoWSA updated package 2024-07-25 17:16:51 +05:30
Citrix ADC Repackaged - Citrix ADC(OMS Migration) 2024-08-01 14:45:15 +05:30
Citrix Analytics for Security
Citrix Web App Firewall updated packages 2024-07-11 12:34:07 +05:30
Claroty claroty sol updated 2024-07-11 12:35:27 +05:30
Claroty xDome
Cloud Identity Threat Protection Essentials Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-22 21:23:13 +05:30
Cloud Service Threat Protection Essentials
Cloudflare Changed default values of Environment variables 2024-10-16 15:14:02 +05:30
CofenseIntelligence
CofenseTriage
Cognni
CognyteLuminar Update CognyteLuminar_FunctionApp.json 2024-08-21 12:42:22 +05:30
CohesitySecurity Update ReleaseNotes.md 2024-10-21 12:26:43 +05:30
Common Event Format Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-22 21:23:13 +05:30
Commvault Security IQ Solution packaged 2024-10-15 19:01:53 +05:30
ContinuousDiagnostics&Mitigation
Contrast Protect updated version of analytical rules 2024-07-11 16:20:20 +05:30
Corelight Fixed codeql error 2024-10-11 18:40:18 +05:30
Cortex XDR
Cribl Cribl Solution Update with fixes 2024-09-05 17:19:27 -04:00
CrowdStrike Falcon Endpoint Protection Update CrowdstrikeFalconAPISentinelConn.zip 2024-10-18 11:41:05 +05:30
CustomLogsAma Update ReleaseNotes.md 2024-08-08 11:37:04 +05:30
CyberArk Enterprise Password Vault (EPV) Events updated title and description 2024-07-15 13:52:36 +05:30
CyberArkAudit
CyberArkEPM Updated CyberARK solution to fix the deployment validation 2024-08-14 16:29:28 +05:30
CybersecurityMaturityModelCertification(CMMC)2.0
Cybersixgill-Actionable-Alerts Python version upgrade to 3.11 and function version V4 2024-09-24 12:04:06 +05:30
Cyborg Security HUNTER
Cynerio
Cyware
DEV-0537DetectionandHunting
DNS Essentials solution packaged 2024-07-29 13:03:03 +05:30
Darktrace
Datalake2Sentinel
Dataminr Pulse
Delinea Secret Server Repackaged for OMS Migration 2024-07-12 11:43:23 +05:30
Dev 0270 Detection and Hunting
Digital Guardian Data Loss Prevention Repackaged - Digital Guardian Data Loss Prevention 2024-07-25 15:57:03 +05:30
Digital Shadows Python Version Updated to 3.11 in Digital Shadows 2024-09-02 13:12:00 +05:30
DomainTools Updated Shortlink 2024-08-27 12:30:25 +05:30
Dynamics 365 Solution packaged 2024-09-24 12:22:28 +05:30
Dynatrace Update Analytics Rules for missing TTPs 2024-07-16 09:15:53 +05:30
ESET Inspect Python Version Updated to 3.11 in ESET Inspect 2024-09-03 15:37:09 +05:30
ESETPROTECT updated package 2024-07-19 15:21:27 +05:30
EatonForeseer
EclecticIQ
Egress Defend
Egress Iris
Elastic Search
ElasticAgent
Endpoint Threat Protection Essentials Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-22 21:23:13 +05:30
Entrust identity as Service
Ermes Browser Security
Eset Security Management Center Update Analytic rules for missing techniques 2024-07-16 10:27:52 +05:30
Exabeam Advanced Analytics Repackaged - Exabeam Advanced Analytics 2024-07-26 11:47:05 +05:30
ExtraHop Reveal(x) update solutionMetadata,json 2024-07-12 13:36:18 +05:30
F5 BIG-IP
F5 Networks updated solution description 2024-07-15 14:20:51 +05:30
FalconFriday
Farsight DNSDB/Playbooks
Feedly
FireEye Network Security Fireeye sec updated 2024-07-11 12:54:26 +05:30
Flare
Forcepoint CASB Updated Forcepoint CASB solution 2024-07-15 21:16:05 +05:30
Forcepoint CSG updated releasenotes for forcecsg solution 2024-07-25 18:26:57 +05:30
Forcepoint DLP
Forcepoint NGFW Updated Forcepoint NGFW solution 2024-07-15 22:01:18 +05:30
Forescout (Legacy) revert Forescout legacy from 3.0.1 to 3.0.0 package 2024-08-01 15:51:53 +05:30
ForescoutHostPropertyMonitor
ForgeRock Common Audit for CEF small case solutionid for ForgeRock 2024-07-10 17:29:57 +05:30
Fortinet FortiGate Next-Generation Firewall connector for Microsoft Sentinel update type from string to securestring 2024-08-22 13:37:16 +05:30
Fortinet FortiNDR Cloud Fix SSL issue 2024-09-25 14:37:08 -07:00
Fortinet FortiWeb Cloud WAF-as-a-Service connector for Microsoft Sentinel
Gigamon Connector
GitHub Version Changes Updated 2024-08-27 17:21:57 +05:30
GitLab Gitlab Solution 2024-07-24 16:17:18 +05:30
Global Secure Access Update Solution_GlobalSecureAccess.json 2024-10-10 10:36:26 +05:30
Google Apigee Apigee solution packaged 2024-09-10 13:16:43 +05:30
Google Cloud Platform Audit Logs Update mainTemplate.json 2024-08-27 16:41:33 +05:30
Google Cloud Platform BigQuery
Google Cloud Platform Cloud Monitoring Merge branch 'master' into dependabot/pip/Solutions/Google-Cloud-Platform-Cloud-Monitoring/Data-Connectors/aiohttp-3.10.2 2024-10-22 15:57:56 +05:30
Google Cloud Platform Security Command Center
GoogleCloudPlatformDNS Update ReleaseNotes.md 2024-09-11 10:42:20 +05:30
GoogleCloudPlatformIAM Update ReleaseNotes.md 2024-09-06 10:55:11 +05:30
GoogleDirectory/Playbooks
GoogleWorkspaceReports Updated Parser and Release Notes 2024-09-20 12:07:40 +05:30
GreyNoiseThreatIntelligence
Group-IB/Playbooks
HYAS
HYAS Protect
HolmSecurity HolmSecurity-3.11-version-update 2024-09-18 17:53:18 +05:30
HoneyTokens
IONIX
IPQualityScore
IPinfo Update ReleaseNotes.md 2024-07-10 15:27:40 +05:30
ISC Bind Update Solution_ISC Bind.json 2024-07-25 21:13:42 +05:30
Illumio Core Updated Illumio Core solution 2024-07-15 14:11:31 +05:30
IllumioSaaS change versions of packages, update function app zip 2024-10-22 15:38:36 -07:00
Illusive Active Defense
Illusive Platform Updated rule for missing TTPs 2024-07-25 00:51:46 +05:30
Images
Imperva WAF Gateway
ImpervaCloudWAF Update ReleaseNotes.md 2024-09-06 10:56:26 +05:30
Infoblox Update ReleaseNotes.md 2024-10-07 19:09:48 +05:30
Infoblox Cloud Data Connector Repackaged for OMS Migration 2024-07-12 15:40:43 +05:30
Infoblox NIOS Repackage - Infoblox NIOS 2024-08-01 16:32:32 +05:30
Infoblox SOC Insights revert change to this parser 2024-07-30 11:27:53 +03:00
InsightVM/Package
Integration for Atlassian Beacon
Intel471
IoTOTThreatMonitoringwithDefenderforIoT
IronNet IronDefense
Island
Ivanti Unified Endpoint Management Ivanti Unified Endpoint Management 2024-07-24 16:57:53 +05:30
JBoss updated packages 2024-08-13 14:53:33 +05:30
Jamf Protect Update Analytic rule for missing technique 2024-07-16 11:08:22 +05:30
Joshua-Cyberiskvision
Juniper SRX Juniper SRX solution 2024-07-19 14:59:11 +05:30
JuniperIDP updated packages 2024-08-13 14:53:33 +05:30
KQL Training
LastPass
Legacy IOC based Threat Protection Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-22 21:23:13 +05:30
Lookout Python Version Updated to 3.11 in Lookout 2024-09-03 12:12:34 +05:30
Lookout Cloud Security Platform for Microsoft Sentinel Update ReleaseNotes.md 2024-09-06 11:45:53 +05:30
MISP2Sentinel
MailGuard 365
MailRisk
Malware Protection Essentials update releasenotes 2024-10-18 16:14:42 +05:30
MarkLogicAudit updated packages 2024-08-13 14:53:33 +05:30
MaturityModelForEventLogManagementM2131
McAfee Network Security Platform updated releasenotes 2024-07-24 16:06:44 +05:30
McAfee ePolicy Orchestrator McAfee ePolicy Orchestrator solution 2024-07-24 17:20:34 +05:30
Microsoft 365 update 2024-10-06 14:53:45 +03:00
Microsoft Defender For Identity
Microsoft Defender Threat Intelligence
Microsoft Defender XDR Packaged solution for adding new HQ 2024-09-20 17:44:35 +05:30
Microsoft Defender for Cloud updated code as per review comments from atul 2024-07-23 14:16:03 +05:30
Microsoft Defender for Cloud Apps
Microsoft Defender for Office 365 Merge branch 'master' into static-and-generic-ui-tool-change 2024-07-26 18:19:00 +05:30
Microsoft Entra ID Updated PrivlegedRoleAssignedOutsidePIM.yaml version string 2024-10-17 17:11:33 -07:00
Microsoft Entra ID Protection Repackaging Solution for Analytic rule 2024-08-01 15:36:30 +05:30
Microsoft Exchange Security - Exchange On-Premises Merge pull request #11145 from austinmccollum/patch-4 2024-10-01 13:55:13 +05:30
Microsoft Exchange Security - Exchange Online
Microsoft PowerBI
Microsoft Project
Microsoft Purview
Microsoft Purview Information Protection
Microsoft Sysmon For Linux Microsoft Sysmon For Linux solution 2024-07-26 17:54:09 +05:30
Microsoft Windows SQL Server Database Audit
MicrosoftDefenderForEndpoint Merge branch 'master' into v-shukore/Azure_firewall-entra-mde-log4j 2024-07-31 17:04:51 +05:30
MicrosoftPurviewInsiderRiskManagement Update CreateUiDefinition.json 2024-10-16 12:15:46 +05:30
Mimecast Resolving a Code QL notes in Mimecast Audit 2024-10-18 15:30:24 +05:30
MimecastAudit Update azuredeploy_MimecastAudit_AzureFunctionApp.json 2024-08-27 13:53:11 +05:30
MimecastSEG Update azuredeploy_MimecastSEG_AzureFunctionApp.json 2024-09-19 14:42:58 +05:30
MimecastTIRegional MimecastTIRegional-3.11-version-update 2024-09-19 14:52:03 +05:30
MimecastTTP MimecastTTP-3.11-version-update 2024-09-19 16:14:14 +05:30
Minemeld
MongoDBAudit Custom Dataconnector OMS Migration 2024-08-09 10:16:39 +05:30
Morphisec Update Solution_Morphisec.json 2024-07-17 13:30:59 +05:30
Mulesoft Update ReleaseNotes.md 2024-09-18 12:09:02 +05:30
Multi Cloud Attack Coverage Essentials - Resource Abuse Repackage Multicloud 2024-07-16 17:16:10 +05:30
NGINX HTTP Server updated solutionMetadata and mainTemplate 2024-08-09 10:39:18 +05:30
NISTSP80053
NXLog BSM macOS
NXLog FIM
NXLog LinuxAudit
NXLogAixAudit
NXLogDnsLogs
Nasuni Nasuni solution 2024-07-18 17:15:20 +05:30
NetClean ProActive
Netskope
Netskopev2
Network Session Essentials Update analytic rule for missing TTPs 2024-07-16 11:17:55 +05:30
Network Threat Protection Essentials
Netwrix Auditor Netwrix updated 2024-07-11 13:52:56 +05:30
Neustar IP GeoPoint
NonameSecurity
NozomiNetworks OSSEC packaged 2024-07-12 11:29:05 +05:30
OSSEC updated CreateUiDefinition 2024-07-15 16:09:04 +05:30
Okta Single Sign-On Update ReleaseNotes.md 2024-10-18 15:53:11 +05:30
Onapsis Platform
OneIdentity
OneLoginIAM revert 2024-09-17 14:17:59 +05:30
OpenCTI
OpenVPN OpenVPN solution 2024-07-23 20:14:02 +05:30
Oracle Cloud Infrastructure Python Version Updated to 3.11 in Oracle Cloud Infrastructure 2024-09-10 11:39:45 +05:30
OracleDatabaseAudit updated analytic rule version 2024-07-24 15:49:18 +05:30
OracleWebLogicServer Repackage - OracleWebLogicServer 2024-08-09 13:48:57 +05:30
Orca Security Alerts
PCI DSS Compliance Updating PCI DSS Compliance solution to 3.0.0 2024-10-16 19:05:35 +05:30
PDNS Block Data Connector
Palo Alto - XDR (Cortex)
Palo Alto Prisma Cloud CWPP
PaloAlto-PAN-OS solution packaged for entity mappings 2024-08-01 17:00:05 +05:30
PaloAltoCDL PaloaltoCDL packaged 2024-07-12 14:05:15 +05:30
PaloAltoPrismaCloud Python Version Updated to 3.11 in Palo Alto Prism Cloud 2024-09-12 12:43:32 +05:30
Perimeter 81
Phosphorus Update ReleaseNotes.md 2024-09-10 11:27:34 +05:30
PingFederate PingFederate packaged 2024-07-12 16:18:45 +05:30
PostgreSQL Merge branch 'master' into v-rusraut/CustomSolnOMSMigration 2024-08-14 15:51:40 +05:30
Power Platform Update ReleaseNotes.md 2024-09-02 11:59:15 +05:30
Prancer PenSuiteAI Integration
ProofPointTap
Proofpoint On demand(POD) Email Security Python Version Updated to 3.11 in Proofpoint On demand 2024-09-06 14:49:40 +05:30
Pulse Connect Secure updated release notes 2024-08-02 18:21:39 +05:30
Pure Storage
Qualys VM Knowledgebase Update ReleaseNotes.md 2024-09-10 10:42:25 +05:30
QualysVM
RSA SecurID updated release notes 2024-08-02 18:21:39 +05:30
Radiflow Solution packaged 2024-08-07 15:00:11 +05:30
Rapid7InsightVM Python Version Updated to 3.11 in Rapid7 2024-09-11 15:17:10 +05:30
Recorded Future solution packaged 2024-10-09 15:22:53 +05:30
Recorded Future Identity Merge pull request #11037 from recordedfuture/RecordedFutureIdentityFixes 2024-09-11 18:11:03 +05:30
Red Canary Update Analytic rule for missing Techniques 2024-07-16 14:21:48 +05:30
ReversingLabs update ReversingLabs solution to v3.0.1 2024-07-29 09:58:45 -04:00
RidgeSecurity updated package and release notes for oms migration 2024-07-10 14:25:13 +05:30
RiskIQ
RubrikSecurityCloud Updated azuredeploy template to prevent public access and cross tenant replicaion in storage account 2024-10-03 00:00:58 +05:30
SAP Merge pull request #11079 from Azure/dvir-ms-patch-16 2024-10-01 13:17:11 +05:30
SAP BTP
SIGNL4
SOC Handbook
SOC-Process-Framework Update ReleaseNotes.md 2024-07-30 14:02:05 +05:30
SailPointIdentityNow Update SearchEvent.zip 2024-09-04 16:56:09 +05:30
SalemCyber
Salesforce Service Cloud Python Version updated to 3.11 in Salesforce Service Cloud 2024-09-12 14:34:21 +05:30
SecurityBridge App fixed validation error 2024-08-12 14:49:38 +05:30
SecurityScorecard Cybersecurity Ratings Updated python version from 3.8 to 3.9 for Security Scorecard Data Connectors and updated python packages accordingly. 2024-07-17 19:06:40 +05:30
SecurityThreatEssentialSolution
Semperis Directory Services Protector Update SemperisDSP_RecentsIDHistoryChangesOnADObjects.yaml 2024-07-16 12:07:46 +05:30
SenservaPro
SentinelOne Update SentinelOneAPISentinelConn.zip 2024-10-25 10:43:18 +05:30
SentinelSOARessentials
SeraphicSecurity
Servicenow updated role 2024-08-23 12:40:14 +05:30
SevcoSecurity
ShadowByte Aria
Shodan
Silverfort Updated based on feedback 2024-09-23 07:25:21 -07:00
Sinec Security Guard Update data_connector_GenericUI.json 2024-08-12 18:30:22 +05:30
SlackAudit SlackAudit-3.11-version-update 2024-09-11 15:58:48 +05:30
SlashNext Update deploy.json 2024-09-10 15:48:56 +05:30
SlashNext SIEM Updated the name of data table as well as a few nodes of data. 2024-07-18 14:19:31 +05:00
Snowflake Update SnowflakeDiscoveryActivity.yaml 2024-07-16 16:28:12 +05:30
SonicWall Firewall
SonraiSecurity Update analytic rules for missing TTPs 2024-07-24 21:47:17 +05:30
Sophos Cloud Optix
Sophos Endpoint Protection Sophose-3.11-version-update 2024-09-06 13:03:07 +05:30
Sophos XG Firewall updated parser query and package as it was giving error in parser query 2024-08-02 18:17:45 +05:30
SpyCloud Enterprise Protection updated URL 2024-07-18 17:15:19 +05:30
Squadra Technologies SecRmm
SquidProxy Merge branch 'master' into v-rusraut/CustomSolnOMSMigration 2024-08-14 15:51:40 +05:30
Symantec Endpoint Protection updated release notes 2024-08-02 18:55:29 +05:30
Symantec Integrated Cyber Defense
Symantec VIP updated release notes 2024-08-02 18:55:29 +05:30
SymantecProxySG updated release notes 2024-08-02 18:21:39 +05:30
Synack
Syslog Updated solution for Syslog to update parser parameter 2024-08-28 20:35:50 +05:30
Talon
Tanium
Team Cymru Scout Fixing CodeQl errors 2024-10-01 16:15:57 +05:30
Teams
Templates
Tenable App Update ReleaseNotes.md 2024-09-05 12:52:02 +05:30
TenableAD
TenableIO TenableiO 2024-09-05 13:21:01 +05:30
TestSolution Update ReleaseNotes.md 2024-10-11 11:35:01 +05:30
TheHive TheHive-3.11-version-update 2024-09-03 17:30:03 +05:30
Theom Update Analytic rule for missing TTPs 2024-07-25 00:20:49 +05:30
Threat Intelligence Update mainTemplate.json 2024-10-23 12:22:19 +05:30
Threat Intelligence Solution for Azure Government Merge branch 'user/nibhandari/update-uploadapi-template' of https://github.com/ni-bhandari/Azure-Sentinel into user/nibhandari/update-uploadapi-template 2024-08-23 17:57:36 -07:00
ThreatAnalysis&Response
ThreatConnect
ThreatXCloud
Tomcat Minor change 2024-08-13 11:49:44 +05:30
Training/Azure-Sentinel-Training-Lab
TransmitSecurity Update ReleaseNotes.md 2024-09-03 14:51:24 +05:30
Trend Micro Apex One trend micro apex packaged 2024-07-12 17:42:22 +05:30
Trend Micro Cloud App Security Update TerndMicroCAS_API_FunctionApp.json 2024-09-06 11:57:39 +05:30
Trend Micro Deep Security
Trend Micro TippingPoint
Trend Micro Vision One [MXDR-2156] add modelId in WB table (#97) 2024-08-09 12:09:19 +08:00
UEBA Essentials updated createUiDefinition and zip 2024-09-23 14:37:16 +05:30
URLhaus
Ubiquiti UniFi Repackaged - Ubiquiti UniFi (OMS Migration) 2024-08-09 15:21:30 +05:30
VMWareESXi updated release notes 2024-08-02 18:55:29 +05:30
VMware Carbon Black Cloud arm ttk resolved 2024-10-15 20:21:09 +05:30
VMware SD-WAN and SASE
VMware vCenter Repackaged VMware VCenter (OMS Migration) 2024-08-09 15:41:39 +05:30
Valence Security
VaronisSaaS - The Offer Name mentioned in the Partner Center (varonis.microsoft-sentinel-solution-varonissaas) is different from one mentioned in solutionId (varonis.azure-sentinel-solution-varonis) 2024-10-15 14:06:46 +03:00
Vectra AI Detect Update VectraDetect-Suspected-Behavior-by-Tactics.yaml 2024-07-15 12:39:34 +05:30
Vectra AI Stream reverted vectra AI solution changes 2024-08-12 17:36:09 +05:30
Vectra XDR Fixed TLS default version related thing by udating it to TLS1.2 2024-10-23 15:30:07 +05:30
Veritas NetBackup Solution packaged 2024-07-22 13:06:39 +05:30
VirusTotal
Votiro updated package and release notes for oms migration 2024-07-10 14:25:13 +05:30
Watchguard Firebox Watchguard firefox solution 2024-07-18 14:13:02 +05:30
Watchlists Utilities
Web Session Essentials
Web Shells Threat Protection
Windows Firewall
Windows Forwarded Events
Windows Security Events Update ReleaseNotes.md 2024-10-03 12:33:20 +05:30
Windows Server DNS
WireX Network Forensics Platform
WithSecureElementsViaConnector updated package and release notes for oms migration 2024-07-10 14:25:13 +05:30
WithSecureElementsViaFunction
Wiz Create ui corrected 2024-07-23 16:24:29 +05:30
Workday
Workplace from Facebook Update azuredeploy_Connector_FacebookWorkplaceWebhooks_AzureFunction.json 2024-09-06 10:33:31 +05:30
ZeroFox Merge pull request #10963 from Azure/dependabot/pip/Solutions/ZeroFox/Data-Connectors/CTI/aiohttp-3.10.2 2024-10-24 18:13:01 +05:30
ZeroNetworks Delete ZNSegmentAudit.txt 2024-10-10 11:59:44 +05:30
ZeroTrust(TIC3.0)
Zimperium Mobile Threat Defense
Zinc Open Source
ZoomReports ZoomReports-Python-3.11-version-update 2024-08-29 13:05:12 +05:30
Zscaler Internet Access updated versions 2024-07-24 17:51:22 -07:00
Zscaler Private Access (ZPA) Zscaler Private Access solution package 2024-08-22 11:48:52 +05:30
archTIS
iboss change to CommonSecurityLog to get it to work 2024-09-17 20:24:33 -04:00
vArmour Application Controller
ContentHubCatalog.xlsx
ContentHubSolutionsCatalog.md
README.md Added the newly created Learn links for publishing Sentinel solutions 2024-10-16 12:21:22 +05:30
ReleaseNotesGuidance.md
ReleaseNotesSample.md
azuredeploy_parameters.json
known_issues.md

README.md

Guide to building Microsoft Sentinel solutions

This guide provides an overview of Microsoft Sentinel solutions, and how to build and publish a solution for Microsoft Sentinel.

Microsoft Sentinel solutions provide an in-product experience for central discoverability, single-step deployment, and enablement of end-to-end product, domain, and/or vertical scenarios in Microsoft Sentinel. This experience is powered by:

Providers and partners can deliver combined product, domain, or vertical value via solutions in Microsoft Sentinel in order to productize investments. More details are covered in the Microsoft Sentinel documentation. Review the catalog for complete list of out-of-the-box Microsoft Sentinel solutions.

Microsoft Sentinel solutions include packaged content, integrations, or service offerings for Microsoft Sentinel. This guide focuses on how to build packaged content into solutions, including combinations of data connectors, workbooks, analytic rules, playbooks, hunting queries, parsers, watchlists, and more for Microsoft Sentinel. Reach out to the Microsoft Sentinel Solutions Onboarding Team if you are planning or building another type of integration or service offering, or want to include other types of content in your solution that isn't listed here.

The following image shows the steps in the solution building process, including content creation, packaging, and publishing:

Microsoft Sentinel solutions build process

Step 1 – Create your content

Start with the Get started documentation on the Microsoft Sentinel GitHub Wiki to identify the content types you plan to include in your solution package. For example, supported content types include data connectors, workbooks, analytic rules, playbooks, hunting queries, and more. Each content type has its own contribution guidance for development and validation.

The guidance for each content type in the Wiki describes how to contribute individual pieces of content. However, you want to contribute your content in a packaged solution. Therefore, hold off on submitting your content to the relevant folders as described in the Wiki guidance, and instead place your content in the Solutions folder of the Microsoft Sentinel GitHub repo.

Use the following steps to create your content structure:

  1. In the Microsoft Sentinel Solutions folder, create a new folder with your solution name.

  2. In your solution folder, create a blank folder structure as follows to store the content you've developed:

  • Data Connectors – the data connector json files or Azure Functions, etc. goes in this folder.
  • Workbooks – workbook json files and black and white preview images of the workbook goes here.
  • Analytic Rules – yaml file templates of analytic rules goes in this folder.
  • Hunting queries – yaml file templates of hunting queries goes in this folder.
  • Playbooks – json playbook and Azure Logic Apps custom connectors can go in this folder.
  • Parser – yaml file for Kusto Functions or Parsers can go in this folder. Use this as reference.

For example, see the folder structure for our Cisco ISE solution.

  1. Store your logo, in SVG format, in the central Logos folder.

  2. Store sample data in the sample data folder, within the relevant content type folder, depending on your data connector type.

  3. Submit a PR with all of your solution content. The PR will go through automated GitHub validation. Address potential errors as needed.

After your content has been succesfully validated, the Microsoft Sentinel team will review your PR and reply with any feedback as needed. You can expect an initial response within five business days.

The PR will be approved and merged after any feedback has been incorportated and the full review is successful.

Step 2 – Package your content

The solution content package is called a solution template, and has the following files:

  • mainTemplate.json: The Azure Resource Manager (ARM) template that includes the resources offered by the solution. Each piece of content that you want to package in your solution must first be converted to ARM format. The mainTemplate file is the overall ARM template file that combines each invididual ARM content file.

  • createUIDefinition.json: The deployment experience definition provided to customers installing your solution. This is a step-by-step wizard experience.

For more information, see the solution template documentation (deployment package).

After creating both the mainTemplate.json and the createUIDefinition.json files, validate them, and package them into a .zip file that you can upload as part of the publishing process (Step 3).

Use the package creation tool to help you create and validate the package, following the solutions packaging tool guidance to use the tool and package your content.

Updating your solution

If you already have an Microsoft Sentinel solution and want to update your package, use the package creation tool with updated content to create a new version of the package.

For your solution's versioning format, always use {Major}.{Minor}.{Revision} syntax, such as 3.0.1, to align with the Azure Marketplace recommendation and versioning support.

When updating your package, make sure to raise the version value, regardless of how small or trivial the change is, including typo fixes in a content or solution definition file.

For example, if your original package version is 3.0.1, you might update your versions as follows:

  • Major updates have a new version of 3.0.0 - this is usually reserved for major tooling or package level changes
  • Minor updates, for changes in content of the package, might have a new version of 3.1.0
  • Revisions, such as those scoped to a single piece of content or just metadata or text updates, might have a new version of 3.0.2

Since solutions use ARM templates, you can customize the solution text as well as tabs as needed to cater to specific scenarios.

Step 3 – Publish your solution

For a detailed walkthrough of how to publish your solutions, please refer to the following links -

  1. Publish solutions to Microsoft Sentinel - https://learn.microsoft.com/en-us/azure/sentinel/publish-sentinel-solutions
  2. Solution tracking after publishing in the Microsoft Partner center - https://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-post-publish-tracking

Feedback

Email Azure Sentinel Solutions Onboarding Team with any feedback on this process, for new scenarios not covered in this guide, or with any constraints you may encounter.

FAQs

CSP (Cloud Solution Provider)

What is CSP?

Microsoft Azure Customers may purchase their Azure Subscriptions either directly from Microsoft, or via an Azure Reseller who is part of the Microsoft Cloud Solution Provider (CSP) program. Microsoft Sentinel Solutions are valid for both subscription purchase paths.

Why is there a “CSP Opt-in” option on Microsoft Sentinel solution offers?

“CSP Opt-in” is a general feature of the Azure Marketplace and applies to multiple offer types, including the Azure App offer type used by Microsoft Sentinel solutions. For some publishers, there is occasionally a desire to restrict individual offers to only be deployable in subscriptions that were purchased directly through Microsoft. This is controllable via the “CSP opt-in” flag for each individual offer.

Is Microsoft Sentinel available to customers who purchased their Azure subscription from a CSP Reseller partner?

Yes. There are many customers purchasing directly from Microsoft, via a CSP Reseller and even some who purchase Azure via both programs.

What happens when you enable “CSP opt-in” for your Microsoft Sentinel Solution offer?

Quite simply, it permits your Microsoft Sentinel solution to be deployed into Microsoft Sentinel Workspaces regardless of how the customer acquired it. It is more of a pro-active stance to eliminate an message for your customers who are trying to deploy your Microsoft Sentinel Solution into a CSP purchase subscription.

What does not happen when you enable “CSP opt-in” for your Microsoft Sentinel solution offer?

You are not joining the CSP program. Each offer is individually enabled or disabled for deployability in CSP sourced subscriptions, and setting this flag for your Microsoft Sentinel solution does not affect any other offer in your Marketplace publishing account.

What will happen if you do not enable “CSP opt-in” for your Microsoft Sentinel solution offer?

If the customer who wants to deploy your solution offer, purchased their subscription from a CSP Reseller partner, the solution will not deploy and the customer will get an error message about why.