Azure-Sentinel/Playbooks
dicolanl efdd232a75
Merge pull request #382 from Azure/liortamirmicrosoft-patch-2
Update Open-Zendesk-Ticket.json
2019-12-07 11:12:32 -08:00
..
Block-AADUser.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Change-Incident-Severity.json Change-Incident-Severity 2019-10-03 08:25:23 +03:00
Confirm-AADRiskyUser.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Get-GeoFromIpAndTagIncident.json Fixes due to changes in Connector 2019-11-13 15:21:36 -05:00
Get-IPReputation.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Get-MDATPInvestigationPackage.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Isolate-MDATPMachine.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Open-JIRA-Ticket.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Open-SNOW-Ticket.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Open-Zendesk-Ticket.json Update Open-Zendesk-Ticket.json 2019-11-14 16:05:00 +02:00
Post-Message-Slack.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Post-Message-Teams.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Prompt-User.json Update Prompt-User.json 2019-10-22 09:34:22 -04:00
ReadMe.md Add more playbooks and update readme 2019-09-11 16:32:48 -04:00
Reset-AADUserPassword.json fixes to Logic Apps 2019-11-21 13:45:39 -05:00
Restrict-MDATPAppExectution.json Updates to some playbooks and add some new ones 2019-09-15 20:21:01 -04:00
Revoke-AADSignInSessions.json Updates to some playbooks and add some new ones 2019-09-15 20:21:01 -04:00
Run-MDATPAntivirus.json Updates to some playbooks and add some new ones 2019-09-15 20:21:01 -04:00

ReadMe.md

About

This repo contains sample security playbooks for automation, orchestration and response

This folder contains security playbooks ARM templates that can be used using Microsoft Azure Sentinel connector. After selecting a playbook, in the Azure Sentinel portal:

  1. Search for deploy a custom template
  2. Click build your own template in the editor
  3. Paste the conents from the GitHub playbook
  4. Click Save
  5. Fill in needed data and click purchase

Once deployment is complete, you will need to authorize each connection.

  1. Click the Azure Sentinel connection resource
  2. Click edit API connection
  3. Click Authorize
  4. Sign in
  5. Click Save
  6. Repeat steps for other connections a. For Azure Log Analytics Data Collector, you will need to add the workspace ID and Key

You can now edit the playbook in Logic apps.

Suggestions and feedback

We value your feedback. Let us know if you run into any problems or share your suggestions and feedback by sending email to AzureSentinel@microsoft.com