Azure-Sentinel/Solutions
NCsteven 1bc719c26e Revert "Updates"
This reverts commit c41c899b2c.
2023-07-03 13:42:28 +02:00
..
42Crunch API Protection Fix MacOS Zip issue 2023-04-05 13:37:14 +01:00
AI Analyst Darktrace
AIShield AI Security Monitoring Update AIShield.json 2023-05-29 21:16:15 +05:30
ALC-WebCTRL
ARGOSCloudSecurity
AWS Systems Manager/Playbooks Update deploy button links 2023-06-06 10:06:09 +05:30
AWSAthena
AWS_IAM Update domain 2023-05-30 14:36:00 +05:30
AbnormalSecurity Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
AbuseIPDB Update azuredeploy.json 2023-01-23 12:02:37 +05:30
Agari Arm-ttk Tools error in validation (#7857) 2023-04-19 14:46:23 +05:30
AgileSec Analytics Connector
Akamai Security Events data connector description update 2023-03-14 12:51:19 +05:30
Alibaba Cloud Merge pull request #8070 from Azure/v-prasadboke-alicloud-repackaging- 2023-05-26 16:11:52 +05:30
Alsid For AD
Amazon Web Services Merge pull request #8300 from ep3p/patch-19 2023-06-19 19:19:04 +05:30
Apache Log4j Vulnerability Detection update 2023-04-25 16:44:02 +05:30
ApacheHTTPServer Repackaging solutions with Parser and connector description updates 2023-04-05 12:28:23 +05:30
AristaAwakeSecurity
Armis Description updated 2023-04-13 13:18:29 +05:30
Armorblox Repackaged Zero nw & Armorblox 2023-05-17 11:43:19 +05:30
Aruba ClearPass updated zip 2023-04-06 12:40:26 +05:30
AtlassianConfluenceAudit create ui update 2023-05-26 11:02:05 +05:30
AtlassianJiraAudit Sentinel Workspace Name customfield_10070 updated to customfield_10170 in readme.md table to match azuredeploy.json 2023-06-01 14:33:03 +12:00
Attacker Tools Threat Protection Essentials correction og "keyword" 2023-04-24 16:10:10 +05:30
Australian Cyber Security Centre ACSC Solution repackaging (#7112) 2023-01-20 11:24:26 +05:30
Auth0 Bump requests from 2.27.1 to 2.31.0 in /Solutions/Auth0/Data Connectors (#8104) 2023-05-24 14:06:11 +05:30
Authomize
Azure Active Directory Update azuredeploy.json 2023-06-29 11:56:00 +05:30
Azure Active Directory Identity Protection Repackage AADIP 2023-05-10 14:40:56 +05:30
Azure Activity Merge pull request #7322 from ccmsft/subscription-migration-detection 2023-05-29 10:18:45 +05:30
Azure Batch Account Azure Batch Account Repackaging Changes 2023-02-02 17:37:57 +05:30
Azure Cognitive Search
Azure DDoS Protection Main template update 2023-02-22 16:51:05 +05:30
Azure Data Lake Storage Gen1 updated the logo path 2023-02-21 18:04:18 +05:30
Azure Event Hubs
Azure Firewall Merge pull request #8247 from Azure/v-atulyadav/azurefirewall 2023-06-30 14:18:43 +05:30
Azure Key Vault Repackaging Azure Key Vault Solution (#7710) 2023-03-31 16:57:55 +05:30
Azure Logic Apps
Azure Network Security Groups Repackage Azure Network Security Groups 2023-02-06 15:28:12 +05:30
Azure SQL Database
Azure SQL Database solution for sentinel Hunting Queries changes for KQL validations 2023-05-25 19:28:21 +05:30
Azure Service Bus
Azure Storage Packaged Azure Storage solution for link addition 2023-02-02 14:29:21 +05:30
Azure Stream Analytics
Azure Web Application Firewall (WAF) Azure Web Application Firewall Repackaging (#7711) 2023-03-31 16:57:39 +05:30
Azure kubernetes Service Repackaging Azure Kubernetes 2023-02-02 16:36:08 +05:30
AzureDevOpsAuditing Updated analytic rule and updated package to 2.0.2 2023-02-20 20:23:45 +05:30
AzureSecurityBenchmark Updating Azure Sentinel to Microsoft Sentinel 2023-06-13 19:00:40 +05:30
BETTER Mobile Threat Defense (MTD)
Barracuda CloudGen Firewall Repackaging BarracudaCloudGen Firewall, Watchguard Firebox, Tomcat 2023-04-04 14:38:50 +05:30
Barracuda WAF
Beyond Security beSECURE
Bitglass update 2023-05-23 19:17:45 +05:30
Blackberry CylancePROTECT Updating UI for BlackberryCyclaneProtect 2023-03-14 15:09:34 +05:30
Box Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Broadcom SymantecDLP Repackaging Broadcom SymantecDLP 2023-03-15 18:28:45 +05:30
Check Point Repackaging Checkpoint Solution 2023-03-15 13:06:38 +05:30
CheckPhish by Bolster
Cisco ACI
Cisco Firepower EStreamer Updating template 2023-05-30 17:09:32 +05:30
Cisco ISE Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Cisco Secure Endpoint Bump requests from 2.26.0 to 2.31.0 in /Solutions/Cisco Secure Endpoint/Data Connectors (#8100) 2023-05-26 19:11:45 +05:30
Cisco UCS Updating CiscoUCS and Cisco Meraki 2023-03-14 11:52:44 +05:30
CiscoASA Updating date format 2023-06-15 15:08:53 +05:30
CiscoDuoSecurity CiscoDuoSecurity Function App code update 2023-06-16 15:08:13 +10:00
CiscoMeraki Merge pull request #8209 from Azure/v-rbajaj/CiscoMeraki 2023-06-14 17:26:53 +05:30
CiscoSEG CiscoSEG Parser Optimization Regarding IcM 355468251 (#7503) 2023-05-08 10:54:54 +05:30
CiscoStealthwatch Cisco Stealthwatch 2023-03-31 17:25:23 +05:30
CiscoUmbrella Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
CiscoWSA
Citrix ADC Repackaging solutions with Parser and connector description updates 2023-04-05 12:28:23 +05:30
Citrix Analytics for Security
Citrix Web App Firewall
Claroty
Cloud Identity Threat Protection Essentials Repackaging Cloud Identity Threat Protection and Cloud Service Threat Protection 2023-05-09 16:34:42 +05:30
Cloud Service Threat Protection Essentials Repackaging Cloud Identity Threat Protection and Cloud Service Threat Protection 2023-05-09 16:34:42 +05:30
Cloudflare Updated createUiDefinition.json in Package/2.0.3.zip 2023-06-15 01:25:56 -04:00
CofenseTriage Added Solution for Cofense Triage. (#7649) 2023-04-19 17:39:00 +05:30
Cognni
CohesitySecurity Fix python CodeQL warnings for file open 2023-04-06 14:05:46 -07:00
Common Event Format Repackaging changes with Data connector Description update 2023-02-01 14:33:47 +05:30
ContinuousDiagnostics&Mitigation
Contrast Protect
Corelight
CrowdStrike Falcon Endpoint Protection updating version 2023-05-25 14:46:44 +05:30
CyberArk Enterprise Password Vault (EPV) Events Changing in CreateUIDefinition 2023-06-15 14:36:18 +05:30
CyberArkEPM Updating zip 2023-06-30 17:31:15 +05:30
Cyberpion
CybersecurityMaturityModelCertification(CMMC)2.0 update folder name 2023-06-12 19:00:08 +05:30
Cybersixgill-Actionable-Alerts Update 2.1.0.zip 2023-06-27 12:12:11 +05:30
Cynerio replace azure sentinel also on parsers files 2023-04-20 12:09:40 +03:00
DEV-0537DetectionandHunting
DNS Essentials Bug5505 - Repackaged Network Session Essentials and DNS Essentials 2023-06-14 15:34:49 +05:30
Darktrace Updated API versions for Darktrace Solution 2023-05-15 10:37:26 +05:30
Delinea Secret Server
Dev 0270 Detection and Hunting version update 2023-03-30 18:54:46 +05:30
Digital Shadows corrected zip file 2023-05-31 17:59:58 +05:30
DigitalGuardianDLP KQL-validations-failures-fixed-for-multiple-solutions 2023-02-06 19:25:04 +05:30
DomainTools Updated function app of domaintools (#8046) 2023-05-19 09:57:39 +05:30
Dynamics 365 Repackage Dynamic 365 2023-03-02 12:45:50 +05:30
Dynatrace Updating playbooks and package for Dynatrace 2023-02-16 22:58:32 +05:30
ESET Inspect
ESETPROTECT Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
EatonForeseer
EclecticIQ
Elastic Search
ElasticAgent
Endpoint Threat Protection Essentials Resolving comments1 2023-06-12 14:44:59 +05:30
Entrust Identity SOAR 2.0.0 2023-05-24 20:09:41 +05:30
Eset Security Management Center
Exabeam Advanced Analytics Updated the broken links (#7957) 2023-05-03 16:29:33 +05:30
ExtraHop Reveal(x)
F5 BIG-IP Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
F5 Networks
FalconFriday - removal 2023-04-24 19:22:47 +05:30
Farsight DNSDB/Playbooks
FireEye Network Security FireEye Network Security Repackaging 2023-02-14 16:17:53 +05:30
Flare Adding more Analytics rules 2023-05-11 09:24:30 -04:00
Forcepoint CASB
Forcepoint CSG
Forcepoint DLP Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Forcepoint NGFW
Forescout Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
ForescoutHostPropertyMonitor Update createUiDefinition.json 2023-05-26 19:01:24 +05:30
ForgeRock Common Audit for CEF
FortiWebCloud Updated Shortlink 2023-01-31 12:43:07 +05:30
Fortinet-FortiGate Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
GitHub Bump requests from 2.27.1 to 2.31.0 in /Solutions/GitHub/Data Connectors/GithubWebhook (#8103) 2023-05-25 10:41:15 +05:30
GitLab Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Google Apigee Updated Google ApigeeX solution 2023-05-19 19:05:47 +05:30
Google Cloud Platform Audit Logs Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Google Cloud Platform BigQuery Updated UI description 2023-03-08 15:55:42 +05:30
Google Cloud Platform Cloud Monitoring updating logo path 2023-05-18 16:16:48 +05:30
GoogleCloudPlatformDNS Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
GoogleCloudPlatformIAM Updating zip 2023-05-19 12:21:07 +05:30
GoogleDirectory/Playbooks
GoogleWorkspaceReports Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Group-IB/Playbooks
HYAS
HolmSecurity Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
HoneyTokens Updated Function App code to fix 354220983 ICM 2023-03-27 10:34:40 +05:30
IPQualityScore Updated API version - Cloudflare and IPQualityScore 2023-05-16 16:51:55 +05:30
ISC Bind Updated CreateUI and repackaged 2023-03-09 17:22:19 +05:30
Illumio Core Updated the broken links (#7957) 2023-05-03 16:29:33 +05:30
Illusive Active Defense
Illusive Platform
Images ASIM parser development guideline (#7673) 2023-04-05 08:42:26 -07:00
Imperva WAF Gateway
ImpervaCloudWAF Added more precise catching 2023-06-28 13:23:08 +05:30
Infoblox Cloud Data Connector zip with recent updates 2023-06-12 08:12:09 -07:00
Infoblox NIOS Updated parser version 2023-04-27 22:50:20 +05:30
InsightVM/Package
Intel471/Playbooks/Intel471-ImportMalwareIntelligenceToSentinel Intel 471 integration - updating readme 2023-02-23 10:04:59 +01:00
IoTOTThreatMonitoringwithDefenderforIoT Merge branch 'master' into origin/users/rahul/playbook-AD4IoT-AutoAlertStatusSync-bugfix 2023-02-07 15:43:37 +05:30
IronNet IronDefense
Island repackaged 2023-05-15 13:23:02 -04:00
Ivanti Unified Endpoint Management
JBoss
Jamf Protect Jamf Protect for Microsoft Sentinel v2.1.3 2023-04-13 09:27:10 +02:00
Joshua-Cyberiskvision
Juniper SRX Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
JuniperIDP
KQL Training
KasperskySecurityCenter
LastPass
Legacy IOC based Threat Protection Merge pull request #8134 from Azure/v-vdixit/KQL-validations-update1 2023-06-14 12:44:31 +05:30
Lookout
Lookout Cloud Security Platform for Microsoft Sentinel Update LookoutCSConn.zip 2023-06-12 14:21:06 +05:30
MailRisk Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
MarkLogicAudit Watchguard, MarkLogicAudit, MongoDBAudit DC Description Update 2023-04-10 19:44:00 +05:30
MaturityModelForEventLogManagementM2131 Updating Playbooks with same name in solutions 2023-06-13 15:25:32 +05:30
McAfee Network Security Platform
McAfee ePolicy Orchestrator
Microsoft 365 Repackaging Microsoft 365 solution 2023-05-22 12:57:45 +05:30
Microsoft 365 Defender Repackaging Microsoft 365 Defender 2023-05-11 12:19:36 +05:30
Microsoft Defender For Identity Updating description for Microsoft Defender For Identity and Microsoft Purview Information Protection 2023-02-27 13:01:56 +05:30
Microsoft Defender Threat Intelligence Merge pull request #7917 from Azure/MDTI-Solution-Newplaybooks-Yanivsh 2023-06-01 12:05:19 +05:30
Microsoft Defender for Cloud Endpoint threat Protection 2023-05-09 14:41:56 +05:30
Microsoft Defender for Cloud Apps Updating workbook text 2023-04-24 16:15:07 +05:30
Microsoft Defender for Office 365 Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Microsoft Exchange Security - Exchange On-Premises Fix merge conflict mistake 2023-06-14 11:46:58 +02:00
Microsoft Exchange Security - Exchange Online Updated API version 2023-06-12 19:05:34 +05:30
Microsoft PowerBI Updated connector id 2023-03-23 12:06:02 +05:30
Microsoft Project
Microsoft Purview Microsoft Purview Repackaging changes (#7305) 2023-02-09 17:31:19 +05:30
Microsoft Purview Information Protection Updating description for Microsoft Defender For Identity and Microsoft Purview Information Protection 2023-02-27 13:01:56 +05:30
Microsoft Sysmon For Linux Fixing bug for Sysmon for linux data connector 2023-04-20 16:07:42 +05:30
Microsoft Windows SQL Server Database Audit Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
MicrosoftDefenderForEndpoint api update 2023-06-30 12:34:05 +05:30
MicrosoftPurviewInsiderRiskManagement Fixing the bug for Insider risk Management playbook 2023-04-04 13:07:57 +05:30
Minemeld
MongoDBAudit Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Morphisec Changing in CreateUIDefinition 2023-06-15 14:36:18 +05:30
Mulesoft Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
NGINX HTTP Server fixing validation 2023-04-05 15:17:09 +05:30
NISTSP80053 update folder name 2023-06-12 19:00:08 +05:30
NXLog BSM macOS updating the solution id for NX log BSM 2023-06-13 17:12:26 +05:30
NXLog FIM SOLUTION: NXLog FIM (File Integrity Monitoring) 2023-05-30 12:22:11 +02:00
NXLog LinuxAudit [SOLUTION: NXLog LinuxAudit] 2023-06-02 09:37:18 +02:00
NXLogAixAudit [SOLUTION: NXLog AIX Audit] 2023-06-02 07:40:06 +02:00
NXLogDnsLogs
NetClean ProActive Revert "Updates" 2023-07-03 13:42:28 +02:00
Netskope Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Network Session Essentials Update NetworkPortSweepFromExternalNetwork.yaml 2023-06-21 12:59:54 +05:30
Network Threat Protection Essentials Repackaging Network Threat Essential 2023-05-04 16:38:41 +05:30
Netwrix Auditor
Neustar IP GeoPoint
NonameSecurity Add files via upload 2023-02-06 08:21:17 -08:00
NozomiNetworks
OSSEC Azure to microsoft 2023-03-20 11:19:58 +05:30
Okta Single Sign-On Workbook updated 2023-02-01 16:22:34 +05:30
Onapsis Platform Update 2023-02-01 14:19:47 +05:30
OneIdentity Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
OneLoginIAM One Login iam repackaging 2023-06-05 16:28:45 +05:30
OpenCTI Revert "Merge branch 'OpenCTIFix' of https://github.com/Azure/Azure-Sentinel into OpenCTIFix" 2023-01-16 09:59:36 +05:30
OpenVPN Update OpenVpnEvent.txt 2023-04-05 16:24:25 +05:30
Oracle Cloud Infrastructure Update OCILogsConn.zip 2023-06-28 18:02:57 +05:30
OracleDatabaseAudit Merge pull request #7545 from Azure/v-prasadboke-DataConnectorDescriptionUpdate3 2023-03-20 18:58:24 +05:30
OracleWebLogicServer Repackaging solutions with Parser and connector description updates 2023-04-05 12:28:23 +05:30
Orca Security Alerts
PCI DSS Compliance
Package
Palo Alto - XDR (Cortex)
PaloAlto-PAN-OS Update readme.md 2023-06-06 11:07:22 +05:30
PaloAltoCDL updating createui 2023-05-03 10:01:45 +05:30
PaloAltoPrismaCloud updating logo 2023-03-07 13:52:17 +05:30
Perimeter 81 Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
PingFederate
PostgreSQL
PrismaCloudCompute fixing text changes for Palo alto cloud compute 2023-02-17 14:36:30 +05:30
ProofPointTap Converted to PSObject 2023-04-25 13:35:13 +05:30
Proofpoint On demand(POD) Email Security Updating apiversion in maintemplate 2023-06-08 15:57:41 +05:30
Pulse Connect Secure Updated the broken links (#7957) 2023-05-03 16:29:33 +05:30
Qualys VM Knowledgebase update 2023-03-27 18:05:18 +05:30
QualysVM Repackaging - QualysVM 2023-06-06 17:27:19 +05:30
RSA SecurID rsa secureid 2023-06-13 14:53:49 +05:30
Rapid7InsightVM Description updated 2023-05-26 12:38:50 +05:30
Recorded Future Sample data 2023-05-29 12:14:18 +02:00
Recorded Future Identity Layout 2023-03-14 16:38:15 +01:00
Red Canary
ReversingLabs ReversingLabs-Solution-v2.1.2 2023-04-13 15:32:43 -04:00
RiskIQ
RubrikSecurityCloud Addressing review comments on PR 2023-03-27 10:11:41 -07:00
SAP Updated demo files 2023-06-28 21:38:32 +10:00
SIGNL4 Repackaging - signal4 2023-06-13 11:28:10 +05:30
SOC Handbook updated zip 2023-06-07 15:38:10 +05:30
SOC-Process-Framework update readme 2023-05-03 11:35:03 +01:00
SailPointIdentityNow
Salesforce Service Cloud Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
SecurityBridge App Text Updated from Azure Sentinel to Microsoft Sentinel 2023-04-10 15:33:40 +05:30
SecurityScorecard Cybersecurity Ratings Updated function version to 4 2023-06-05 23:01:21 +05:30
SecurityThreatEssentialSolution Repackaging SecurityThreatEssentials 2023-04-24 13:55:54 +05:30
Semperis Directory Services Protector Adding missing section to YAML for analytic rules 2023-03-23 12:14:24 -04:00
SenservaPro Update package to fix workbook descriptions 2023-06-19 15:20:59 +05:30
SentinelOne Replaced Azure Sentinel with Microsoft Sentinel 2023-05-19 13:20:39 +05:30
SentinelSOARessentials Sentinel to Microsoft Sentinel 2023-06-27 12:38:04 +05:30
Servicenow Updated ServiceNow solution for app store link 2023-06-14 14:25:31 +05:30
ShadowByte Aria
Shodan Updating description and entities 2023-03-01 18:15:23 +05:30
SlackAudit Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
SlashNext
Snowflake Update SnowflakeConn.zip 2023-06-12 10:15:29 +05:30
SonicWall Firewall Repackaged SonicWall Firewall 2023-05-31 11:48:18 +05:30
SonraiSecurity
Sophos Cloud Optix Changing in CreateUIDefinition 2023-06-15 14:36:18 +05:30
Sophos Endpoint Protection Bump requests from 2.25.1 to 2.31.0 in /Solutions/Sophos Endpoint Protection/Data Connectors (#8095) 2023-05-31 19:28:49 +05:30
Sophos XG Firewall UI update 2023-03-20 17:54:02 +05:30
Squadra Technologies SecRmm
SquidProxy Main template update 2023-03-20 17:57:07 +05:30
Symantec Endpoint Protection ui update 2023-03-23 12:58:04 +05:30
Symantec Integrated Cyber Defense
Symantec VIP UI update 2023-03-20 11:29:24 +05:30
SymantecProxySG Update parser description 2023-06-30 15:48:07 +05:30
Synack Upgrading version of Synack 2023-01-24 11:02:42 +05:30
Syslog Data connector description updated 2023-03-29 18:04:25 +05:30
Talon Update zip 2023-03-21 16:35:56 +05:30
Tanium
Teams Updated teams Solution to fix ARM-TTK 2023-06-19 19:06:21 +05:30
Templates
TenableAD
TenableIO Update TenableIO.json 2023-05-08 11:10:41 +12:00
TheHive Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Theom
Threat Intelligence Merge branch 'master' into pr/8142 2023-06-16 11:12:55 +05:30
Threat Intelligence Solution for Azure Government Updating display name 2023-03-09 14:13:01 +05:30
ThreatAnalysis&Response Repacking 2023-02-13 15:39:02 +05:30
ThreatXCloud
Tomcat Repackaging BarracudaCloudGen Firewall, Watchguard Firebox, Tomcat 2023-04-04 14:38:50 +05:30
Training/Azure-Sentinel-Training-Lab
Trend Micro Apex One
Trend Micro Cloud App Security
Trend Micro Deep Security
Trend Micro TippingPoint Repackaging Trend Micro TippingPoint 2023-05-30 16:26:35 +05:30
Trend Micro Vision One Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
UEBA Essentials Merge branch 'v-rusraut/UEBAEssentials' of https://github.com/Azure/Azure-Sentinel into v-rusraut/UEBAEssentials 2023-05-09 17:47:49 +05:30
URLhaus
Ubiquiti UniFi KQL validations for Hunting Queries 2023-02-07 12:23:55 +05:30
VMWareESXi update description 2023-06-09 10:24:21 +05:30
VMware Carbon Black Cloud Update azuredeploy.json 2023-06-30 15:04:07 +05:30
VMware vCenter Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Vectra AI Detect Updating for solutions validations 2023-05-31 15:13:44 +05:30
Vectra AI Stream Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
VirusTotal updated zip 2023-03-10 13:43:02 +05:30
Watchguard Firebox Updated the API version - Forescout, Watchguard and WireX 2023-05-23 17:45:23 +05:30
Watchlists Utilities
Web Shells Threat Protection data file and create ui fix 2023-05-25 19:57:53 +05:30
Windows Firewall Update template_WindowsFirewallAma.JSON 2023-03-20 12:32:39 -07:00
Windows Forwarded Events Repackaged Microsoft 365, MicrosoftDefenderForEndpoint, Windows Forwarded Events (#7978) 2023-05-08 18:49:35 +05:30
Windows Security Events Queries in support of Blog post 2023-05-24 04:26:30 -07:00
Windows Server DNS Updating zip 2023-04-06 16:07:21 +05:30
WireX Network Forensics Platform Updated the API version - Forescout, Watchguard and WireX 2023-05-23 17:45:23 +05:30
WithSecureElementsViaConnector fix: update DeviceVendor for WithSecureElementsViaConnector solution 2023-03-14 16:24:05 +01:00
Workplace from Facebook Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
ZeroNetworks Repackaged Zero nw & Armorblox 2023-05-17 11:43:19 +05:30
ZeroTrust(TIC3.0) Updating Playbooks with same name in solutions 2023-06-13 15:25:32 +05:30
Zimperium Mobile Threat Defense
Zinc Open Source Updating analytics rules 2023-06-02 09:57:14 +05:30
ZoomReports Revert "Revert "Merge branch 'master' into pr/8145"" 2023-06-26 18:55:20 +05:30
Zscaler Internet Access Repackaging ZIA 2023-05-29 18:42:30 +05:30
Zscaler Private Access (ZPA) [DO NOT MERGE]ZPA Parser Optimization (#6921) 2023-03-28 10:56:19 +05:30
archTIS
iboss updating domain 2023-03-30 12:01:04 +05:30
vArmour Application Controller
README.md Update README.md 2023-06-14 11:37:57 +05:30
known_issues.md

README.md

Guide to building Microsoft Sentinel solutions

This guide provides an overview of Microsoft Sentinel solutions, and how to build and publish a solution for Microsoft Sentinel.

Microsoft Sentinel solutions provide an in-product experience for central discoverability, single-step deployment, and enablement of end-to-end product, domain, and/or vertical scenarios in Microsoft Sentinel. This experience is powered by:

Providers and partners can deliver combined product, domain, or vertical value via solutions in Microsoft Sentinel in order to productize investments. More details are covered in the Microsoft Sentinel documentation. Review the catalog for complete list of out-of-the-box Microsoft Sentinel solutions.

Microsoft Sentinel solutions include packaged content, integrations, or service offerings for Microsoft Sentinel. This guide focuses on how to build packaged content into solutions, including combinations of data connectors, workbooks, analytic rules, playbooks, hunting queries, parsers, watchlists, and more for Microsoft Sentinel. Reach out to the Microsoft Sentinel Solutions Onboarding Team if you are planning or building another type of integration or service offering, or want to include other types of content in your solution that isn't listed here.

The following image shows the steps in the solution building process, including content creation, packaging, and publishing:

Microsoft Sentinel solutions build process

Step 1 – Create your content

Start with the Get started documentation on the Microsoft Sentinel GitHub Wiki to identify the content types you plan to include in your solution package. For example, supported content types include data connectors, workbooks, analytic rules, playbooks, hunting queries, and more. Each content type has its own contribution guidance for development and validation.

The guidance for each content type in the Wiki describes how to contribute individual pieces of content. However, you want to contribute your content in a packaged solution. Therefore, hold off on submitting your content to the relevant folders as described in the Wiki guidance, and instead place your content in the Solutions folder of the Microsoft Sentinel GitHub repo.

Use the following steps to create your content structure:

  1. In the Microsoft Sentinel Solutions folder, create a new folder with your solution name.

  2. In your solution folder, create a blank folder structure as follows to store the content you've developed:

  • Data Connectors – the data connector json files or Azure Functions, etc. goes in this folder.
  • Workbooks – workbook json files and black and white preview images of the workbook goes here.
  • Analytic Rules – yaml file templates of analytic rules goes in this folder.
  • Hunting queries – yaml file templates of hunting queries goes in this folder.
  • Playbooks – json playbook and Azure Logic Apps custom connectors can go in this folder.
  • Parser – txt file for Kusto Functions or Parsers can go in this folder.

For example, see the folder structure for our Cisco ISE solution.

  1. Store your logo, in SVG format, in the central Logos folder.

  2. Store sample data in the sample data folder, within the relevant content type folder, depending on your data connector type.

  3. Submit a PR with all of your solution content. The PR will go through automated GitHub validation. Address potential errors as needed.

After your content has been succesfully validated, the Microsoft Sentinel team will review your PR and reply with any feedback as needed. You can expect an initial response within five business days.

The PR will be approved and merged after any feedback has been incorportated and the full review is successful.

Step 2 – Package your content

The solution content package is called a solution template, and has the following files:

  • mainTemplate.json: The Azure Resource Manager (ARM) template that includes the resources offered by the solution. Each piece of content that you want to package in your solution must first be converted to ARM format. The mainTemplate file is the overall ARM template file that combines each invididual ARM content file.

  • createUIDefinition.json: The deployment experience definition provided to customers installing your solution. This is a step-by-step wizard experience.

For more information, see the solution template documentation (deployment package).

After creating both the mainTemplate.json and the createUIDefinition.json files, validate them, and package them into a .zip file that you can upload as part of the publishing process (Step 3).

Use the package creation tool to help you create and validate the package, following the solutions packaging tool guidance to use the tool and package your content.

Updating your solution

If you already have an Microsoft Sentinel solution and want to update your package, use the package creation tool with updated content to create a new version of the package.

For your solution's versioning format, always use {Major}.{Minor}.{Revision} syntax, such as 1.0.1, to align with the Azure Marketplace recommendation and versioning support.

When updating your package, make sure to raise the version value, regardless of how small or trivial the change is, including typo fixes in a content or solution definition file.

For example, if your original package version is 1.0.1, you might update your versions as follows:

  • Major updates have a new version of 2.0.0 - this is usually reserved for major tooling or package level changes
  • Minor updates, for changes in content of the package, might have a new version of 1.1.0
  • Revisions, such as those scoped to a single piece of content or just metadata or text updates, might have a new version of 1.0.2

Since solutions use ARM templates, you can customize the solution text as well as tabs as needed to cater to specific scenarios.

Step 3 – Publish your solution

The Microsoft Sentinel solution publishing experience is powered by the Microsoft Partner Center.

Registration (one-time)

If you or your company is a first-time app publisher on Azure Marketplace, follow the steps to register and create a Commercial Marketplace account in Partner Center. This process provides you with a unique Publisher ID and access to the Commercial Marketplace authoring and publishing experience, where you'll create, certify, and publish your solution.

Author and publish a solution offer

The following steps reference the Partner Center's more detailed documentation.

  1. Create an Azure application type offer and configure the offer setup details as per the relevant guidance.

Ensure that the OfferID contains the keyword "sentinel". Consider using the format: microsoft-sentinel-solution-<productname>

  1. Configure the Offer properties.

  2. Configure the Offer listing details, including the title, description, pictures, videos, support information, and so on.

    • As one of your search keywords, add f1de974b-f438-4719-b423-8bf704ba2aef to have your solution appear in the Microsoft Sentinel content hub.
    • Ensure to provide CSP (Cloud Solution Provider) Program contact and relevant CSP information as requested. This will enable you to offer the solution to CSP subscriptions and increased visibility and adoption of your solution. Refer to the CSP FAQs for further details on why this is recommended for Microsoft Sentinel solutions.
    • If you want to start your solution in Preview (Public Preview), you can do so by appending "(Preview)" in the solution / offer title. This will ensure your offer gets tagged with Preview tag in Microsoft Sentinel Content hub.
  3. Create a plan and select Solution Template as the plan type.

    • If your offer needs to be available for customers from U.S. federal, state, local, or tribal entities, follow the steps to select the Azure Government check box and subsquent guidance.
  4. Configure the Solutions template plan. This is where youll upload the zip file that you'd created in step two and set a version for your package. Make sure to follow the versioning guidance described in step 2, above.

  5. Enable CSP for your offer by going to the Resell through CSPs tab in Partner Center and selecting Any partner in the CSP program. This will enable you to offer the solution to CSP subscriptions and increased visibility and adoption of your solution. Refer to the CSP FAQs for further details on why this is recommended for Microsoft Sentinel solutions.

  6. Validate and test your solution offer.

  7. After the validation passes, publish the offer live. This will trigger the certification process, which can take up to 3 business days.

Note: The Microsoft Sentinel team will need to modify your files so that your solution appears in the Microsoft Sentinel content hub. Therefore, before going live, email the Azure Sentinel Solutions Onboarding Team with your solutions offer ID and your Publisher ID so that we can make the required changes.

Note: You must make the offer public in order for it to show up in the Microsoft Sentinel content hub so that customers can find it.

Feedback

Email Azure Sentinel Solutions Onboarding Team with any feedback on this process, for new scenarios not covered in this guide, or with any constraints you may encounter.

FAQs

CSP (Cloud Solution Provider)

What is CSP?

Microsoft Azure Customers may purchase their Azure Subscriptions either directly from Microsoft, or via an Azure Reseller who is part of the Microsoft Cloud Solution Provider (CSP) program. Microsoft Sentinel Solutions are valid for both subscription purchase paths.

Why is there a “CSP Opt-in” option on Microsoft Sentinel solution offers?

“CSP Opt-in” is a general feature of the Azure Marketplace and applies to multiple offer types, including the Azure App offer type used by Microsoft Sentinel solutions. For some publishers, there is occasionally a desire to restrict individual offers to only be deployable in subscriptions that were purchased directly through Microsoft. This is controllable via the “CSP opt-in” flag for each individual offer.

Is Microsoft Sentinel available to customers who purchased their Azure subscription from a CSP Reseller partner?

Yes. There are many customers purchasing directly from Microsoft, via a CSP Reseller and even some who purchase Azure via both programs.

What happens when you enable “CSP opt-in” for your Microsoft Sentinel Solution offer?

Quite simply, it permits your Microsoft Sentinel solution to be deployed into Microsoft Sentinel Workspaces regardless of how the customer acquired it. It is more of a pro-active stance to eliminate an message for your customers who are trying to deploy your Microsoft Sentinel Solution into a CSP purchase subscription.

What does not happen when you enable “CSP opt-in” for your Microsoft Sentinel solution offer?

You are not joining the CSP program. Each offer is individually enabled or disabled for deployability in CSP sourced subscriptions, and setting this flag for your Microsoft Sentinel solution does not affect any other offer in your Marketplace publishing account.

What will happen if you do not enable “CSP opt-in” for your Microsoft Sentinel solution offer?

If the customer, who wants to deploy your solution offer, purchased their subscription from a CSP Reseller partner, the solution will not deploy and the customer will get an error message about why.