Azure-Sentinel/Sample Data/Custom/PaloAltoPrismaCloudAlert_CL...

464 строки
20 KiB
JSON

[
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "low",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::other:eu-central-1:999999999999:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa:arn%3Aaws%3Alambda%3Aeu-central-1%3A999999999999%3Afunction%3ALambdaUploadFile",
"resource_id": "arn:aws:lambda:eu-central-1:999999999999:function:LambdaUploadFile",
"resource_name": "LambdaUploadFile",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Frankfurt",
"resource_regionId": "eu-central-1",
"resource_resourceType": "OTHER",
"resource_resourceApiName": "aws-lambda-list-functions",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423871430",
"id": "P-64",
"policy_policyId": "00000000-0000-0000-0000-00000000000",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "11",
"riskDetail_riskScore_maxScore": "21",
"riskDetail_rating": "B",
"riskDetail_score": "11/21",
"status": "open",
"firstSeen": "1616424563915",
"lastSeen": "1616424563915",
"alertTime": "1616424563915"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "low",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "",
"resource_id": "999999999999",
"resource_name": "AWS Account",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "global",
"resource_regionId": "",
"resource_resourceType": "PSEUDO_RESOURCE",
"resource_resourceApiName": "account-agg-entity",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423577101",
"id": "P-66",
"policy_policyId": "00000000-0000-0000-0000-00000000000",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "4",
"riskDetail_riskScore_maxScore": "44",
"riskDetail_rating": "B",
"riskDetail_score": "4/44",
"status": "open",
"firstSeen": "1616424563957",
"lastSeen": "1616424563957",
"alertTime": "1616424563957"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "low",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::other:eu-central-1:999999999999:test:arn%3Aaws%3Aacm%3Aeu-central-1%3A999999999999%3Acertificate%2Ftest",
"resource_id": "arn:aws:acm:eu-central-1:999999999999:certificate/test",
"resource_name": "*.tf.aws.cloud.test.name",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Frankfurt",
"resource_regionId": "eu-central-1",
"resource_resourceType": "OTHER",
"resource_resourceApiName": "aws-acm-describe-certificate",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423890898",
"id": "P-67",
"policy_policyId": "test",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "11",
"riskDetail_riskScore_maxScore": "34",
"riskDetail_rating": "B",
"riskDetail_score": "11/34",
"status": "open",
"firstSeen": "1616424563979",
"lastSeen": "1616424563979",
"alertTime": "1616424563979"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "medium",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::other:eu-central-1:999999999999:test:arn%3Aaws%3Alambda%3Aeu-central-1%3A999999999999%3Afunction%3ALambdaDeleteByName",
"resource_id": "arn:aws:lambda:eu-central-1:999999999999:function:LambdaDeleteByName",
"resource_name": "LambdaDeleteByName",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Frankfurt",
"resource_regionId": "eu-central-1",
"resource_resourceType": "OTHER",
"resource_resourceApiName": "aws-lambda-list-functions",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423871430",
"id": "P-68",
"policy_policyId": "test",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "10",
"riskDetail_riskScore_maxScore": "21",
"riskDetail_rating": "B",
"riskDetail_score": "10/21",
"status": "open",
"firstSeen": "1616424563997",
"lastSeen": "1616424563997",
"alertTime": "1616424563997"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "medium",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::other:eu-central-1:999999999999:test:arn%3Aaws%3Alambda%3Aeu-central-1%3A999999999999%3Afunction%3ALambdaGetAllUpdates",
"resource_id": "arn:aws:lambda:eu-central-1:999999999999:function:LambdaGetAllUpdates",
"resource_name": "LambdaGetAllUpdates",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Frankfurt",
"resource_regionId": "eu-central-1",
"resource_resourceType": "OTHER",
"resource_resourceApiName": "aws-lambda-list-functions",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423871430",
"id": "P-69",
"policy_policyId": "test",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "11",
"riskDetail_riskScore_maxScore": "21",
"riskDetail_rating": "B",
"riskDetail_score": "11/21",
"status": "open",
"firstSeen": "1616424564018",
"lastSeen": "1616424564018",
"alertTime": "1616424564018"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "medium",
"policy_recommendation": "test",
"policy_labels": "[]",
"policy_lastModifiedOn": "1616422497101",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "",
"policy_remediation_impact": "",
"policy_remediation_cliScriptTemplate": "",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::other:eu-west-3:999999999999:test:arn%3Aaws%3Alambda%3Aeu-west-3%3A999999999999%3Afunction%3AVirusTotal",
"resource_id": "arn:aws:lambda:eu-west-3:999999999999:function:VirusTotal",
"resource_name": "VirusTotal",
"resource_account": "AWS Account",
"resource_accountId": "999999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Paris",
"resource_regionId": "eu-west-3",
"resource_resourceType": "OTHER",
"resource_resourceApiName": "aws-lambda-list-functions",
"resource_url": "",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616424157777",
"id": "P-70",
"policy_policyId": "test",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "false",
"alertRules": "[]",
"riskDetail_riskScore_score": "20",
"riskDetail_riskScore_maxScore": "21",
"riskDetail_rating": "C",
"riskDetail_score": "20/21",
"status": "open",
"firstSeen": "1616424564051",
"lastSeen": "1616424564051",
"alertTime": "1616424564051"
},
{
"reason": "NEW_ALERT",
"policy_name": "test",
"policy_description": "test",
"policy_severity": "medium",
"policy_recommendation": "test",
"policy_labels": "test",
"policy_lastModifiedOn": "1595561593000",
"policy_lastModifiedBy": "test@example.com",
"policy_deleted": "false",
"policy_remediation_description": "test",
"policy_remediation_impact": "test",
"policy_remediation_cliScriptTemplate": "test",
"resource_id": "f1a71111-1111-1111-1111-ee8ba53c1725",
"history": "",
"resource_data_mfa_active": "",
"resource_data_cert_1_active": "",
"resource_data_cert_2_active": "",
"resource_data_password_enabled": "",
"resource_data_password_last_used": "",
"resource_data_user_creation_time": "",
"resource_data_access_key_1_active": "",
"resource_data_access_key_2_active": "",
"resource_data_cert_1_last_rotated": "",
"resource_data_cert_2_last_rotated": "",
"resource_data_password_last_changed": "",
"resource_data_password_next_rotation": "",
"resource_data_access_key_1_last_rotated": "",
"resource_data_access_key_2_last_rotated": "",
"resource_data_access_key_1_last_used_date": "",
"resource_data_access_key_2_last_used_date": "",
"resource_data_access_key_1_last_used_region": "",
"resource_data_access_key_2_last_used_region": "",
"resource_data_access_key_1_last_used_service": "",
"resource_data_access_key_2_last_used_service": "",
"resource_rrn": "rrn::kmsKeyRotation:eu-central-1:99999999999:xxxxxxxxxxxxxxxxxxxxxxxxxx:xxxxxxxxxxxxxxxxxxxxxxxx",
"resource_name": "Test",
"resource_account": "AWS Account",
"resource_accountId": "99999999999",
"resource_cloudAccountGroups": "[\n \"Default Account Group\"\n]",
"resource_region": "AWS Frankfurt",
"resource_regionId": "eu-central-1",
"resource_resourceType": "KMS_KEY_ROTATION",
"resource_resourceApiName": "aws-kms-get-key-rotation-status",
"resource_url": "https://console.aws.amazon.com/iam/home?region=eu-central-1#/encryptionKeys/eu-central-1/xxxxxxxxxxxxxxxxxxxxxxxxxxx",
"resource_data_arn": "",
"resource_data_user": "",
"resource_additionalInfo_accessKeyAge": "",
"resource_additionalInfo_inactiveSinceTs": "",
"resource_cloudType": "aws",
"resource_resourceTs": "1616423855088",
"id": "P-79",
"policy_policyId": "497f7e2c-xxxx-xxxx-xxxx-f0f6404ac896",
"policy_policyType": "config",
"policy_systemDefault": "true",
"policy_remediable": "true",
"alertRules": "[]",
"riskDetail_riskScore_score": "20",
"riskDetail_riskScore_maxScore": "80",
"riskDetail_rating": "C",
"riskDetail_score": "20/80",
"status": "open",
"firstSeen": "1616424564314",
"lastSeen": "1616424564314",
"alertTime": "1616424564314"
}
]