Azure-Sentinel/Workbooks
v-amolpatil 6639753cbb
Playbook Preparation: Log4j Vulnerability Detection (#5807)
* Updated playbook and package

* Added Log4jImpactAssessment section un WorkbooksMetadata file

* Rename of file and updated workbooksmetadata

* Minor change in file name and updated package

* Updated package and solution metadata ipconnector to true as it is 1P

* Updated link in readme file

* Deleted extra file

* updated playbook content

* added back moved file

* rename of file as earlier source file was having space in file name
2022-08-18 16:55:33 +05:30
..
Images removing illegal attributes from svg 2022-07-08 10:45:33 +01:00
ADXvsLA.json Update ADXvsLA.json 2021-07-29 11:07:05 +02:00
AIA-Darktrace.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AIVectraDetectWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AMAmigrationTracker.json Update AMAmigrationTracker.json 2022-06-23 10:12:03 +02:00
ASC-ComplianceandProtection.json
AWSS3.json AWS S3 Workbook 2022-02-21 14:47:29 +00:00
AdvancedKQL.json colums spelling mistake in line no. 3149 2022-03-09 13:39:33 +05:30
AksSecurity.json Updating workbook AKS for one ICM 2022-04-07 17:57:41 +05:30
AlsidIoA.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AlsidIoE.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AmazonWebServicesNetworkActivities.json
AmazonWebServicesUserActivities.json
AnalyticsEfficiency.json
AnomaliesVisualization.json Added Anomaly Visualization Workbook and Anomaly Data workbook (#5226) 2022-06-17 10:36:56 +05:30
AnomalyData.json Added Anomaly Visualization Workbook and Anomaly Data workbook (#5226) 2022-06-17 10:36:56 +05:30
ArchivingBasicLogsRetention.json Update Change Log and Workbook Version 2022-05-16 17:45:48 -07:00
AzureActiveDirectoryAuditLogs.json Logged By Service Trend 2021-09-21 00:58:59 +05:30
AzureActiveDirectorySignins.json merge from master 2021-12-08 17:13:09 +02:00
AzureActivity.json changes per PR review by Shain 2021-09-23 14:13:17 -07:00
AzureAuditActivityAndSignin.json successful was incorrectly spelled as successfull 2022-01-11 16:33:54 +05:30
AzureFirewall.json
AzureFirewallWorkbook.json Update AzureFirewallWorkbook.json 2021-09-21 11:59:02 -07:00
AzureKeyVaultWorkbook.json
AzureNetworkWatcher.json
AzureSentinelCost.json fixed date order issue in E5 Sentinel benefit chart 2022-03-01 20:29:12 +11:00
AzureSentinelSecurityAlerts.json
BETTER_MTD_Workbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
Barracuda.json
CheckPoint.json
Cisco.json
CiscoFirepower.json Removing resource references 2022-06-01 08:51:42 +05:30
CiscoMeraki.json
CiscoUmbrella.json
Citrix.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CitrixWAF.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CognniIncidentsWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CyberArkEPV.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CyberpionOverviewWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
DSTIMWorkbook.json Bug 13880823: [DSTIM][Workbook] use aka.ms link for survey 2022-03-21 11:19:24 +02:00
DataCollectionHealthMonitoring.json
Dns.json DNS workbook query fix (#5318) 2022-06-15 18:22:52 +05:30
DuoSecurity.json Move New Community Content to Proper Location 2021-06-10 10:41:18 -07:00
EventAnalyzer.json
ExchangeCompromiseHunting.json
ExchangeOnline.json
ExtraHopDetectionSummary.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
F5BIGIPSystemMetrics.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
F5Networks.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointCASB.json Removed stype parameter 2022-05-17 20:58:49 +05:30
ForcepointCloudSecuirtyGatewayworkbook.json
ForcepointDLP.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointNGFW.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointNGFWAdvanced.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
Fortigate.json
GitHubSecurityWorkbook.json
IOT_Alerts.json
IdentityAndAccess.json
IllusiveADS.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
IllusiveASM.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
IncidentOverview.json Incident Overview Workbook query fix for ICM (#5168) 2022-06-01 10:33:28 +05:30
InfobloxNIOS.json
InsecureProtocols.json Updates fromTemplateId field in InsecureProtocols Workbook 2022-02-21 09:06:42 +02:00
IntrotoKQL.json Updating KQL workbook for summer update 2022-07-26 14:00:49 -04:00
IntsightsIOCWorkbook.json
InvestigationInsights.json Revert "Revert "Merge branch 'master' of https://github.com/Azure/Azure-Sentinel"" 2022-01-03 16:21:46 +02:00
IoTAssetDiscovery.json
LinuxMachines.json Revert "Package Creation for Syslog-- DO NOT MERGE AS 1P" (#5140) 2022-05-31 12:36:05 +05:30
Log4j Impact Assessment.json Playbook Preparation: Log4j Vulnerability Detection (#5807) 2022-08-18 16:55:33 +05:30
Log4jPostCompromiseHunting.json Rename Log4jPostCompromiseHunting to Log4jPostCompromiseHunting.json 2022-01-26 08:57:58 +05:30
LogSourcesAndAnalyticRulesCoverage.json Update LogSourcesAndAnalyticRulesCoverage.json 2022-06-17 14:30:13 +02:00
M365SecurityPosture.json Adding M365 Security Posture workbook to go with playbook. 2021-05-24 18:03:49 -04:00
MITREAttack.json updates to workbook with new KQL queries 2022-05-24 15:56:54 -07:00
MicrosoftCloudAppSecurity.json
MicrosoftDefenderForEndPoint.json Update MicrosoftDefenderForEndPoint.json 2022-04-15 00:35:40 +05:30
MicrosoftDefenderForOffice365.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
MicrosoftSentinelDeploymentandMigrationTracker.json remediating check issues 2022-06-06 15:50:05 -04:00
MicrosoftTeams.json Update MicrosoftTeams.json 2022-02-24 22:45:32 +05:30
NormalizedNetworkEvents.json
Office365.json Fixed typo for label 2021-06-21 18:28:41 +05:30
OnapsisAlarmsOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
OneIdentity.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
OrcaAlerts.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
PaloAltoNetworkThreat.json Updating to include new CEF Changes 2022-05-31 17:06:53 +05:30
PaloAltoOverview.json Updating to include new CEF Changes 2022-05-31 17:06:53 +05:30
Perimeter81OverviewWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ProofPointThreatDashboard.json add-new-proofpoint-workbook 2021-08-26 18:26:27 +08:00
ProofpointPOD.json Updated a live link for parser deployment (#5422) 2022-06-23 13:00:56 +05:30
ProofpointTAP.json Added the proofpoint tap workbook back 2021-07-23 11:22:14 +05:30
PulseConnectSecure.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
QualysVM.json
QualysVMv2.json updated dataType for Qualys V2 version 2021-08-17 12:01:52 +05:30
README.md branding changes 2021-11-29 11:00:33 -08:00
SOCProcessFramework.json Removing the parameters filters from the workbooks 2021-09-20 22:29:52 +05:30
SecurityOperationsEfficiency.json Fix for the workbooks logs not loading ICM 2021-09-08 17:37:37 +05:30
SecurityStatus.json Update SecurityStatus.json (#2231) 2021-04-29 13:22:27 -07:00
SentinelCentral.json Adding Retention Tab 2021-12-23 14:08:41 +05:30
SharePointAndOneDrive.json Update SharePointAndOneDrive.json 2022-02-25 18:09:14 +05:30
SolarWindsPostCompromiseHunting.json
SophosXGFirewall.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SquadraTechnologiesSecRMM.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SymantecProxySG.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SymantecVIP.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SysmonThreatHunting.json
ThreatIntelligence.json Update 2022-05-11 08:14:01 -04:00
ThycoticWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
TrendMicroDeepSecurityAttackActivity.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
TrendMicroDeepSecurityOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
TrendMicroXDROverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
UnifiSG.json Unifi Security Gateway Connector (#1096) 2021-06-01 11:19:21 -07:00
UnifiSGNetflow.json Unifi Security Gateway Connector (#1096) 2021-06-01 11:19:21 -07:00
UserEntityBehaviorAnalytics.json Update UserEntityBehaviorAnalytics.json 2021-06-17 17:06:54 -04:00
UserMap.json Update UserMap.json 2022-02-21 11:12:50 +00:00
VirtualMachinesInsights.json
VisualizationDemo.json
WebApplicationFirewallFirewallEvents.json
WebApplicationFirewallGatewayAccessEvents.json
WebApplicationFirewallOverview.json
WebApplicationFirewallWAFTypeEvents.json update WebApplicationFirewallFirewallEvents.json and template validation 2022-04-20 17:29:28 -07:00
WindowsFirewall.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
WorkbooksMetadata.json Merge pull request #5788 from Azure/v-ntripathi/UpdatingTheVersionOfWOrkbook 2022-08-03 12:43:26 +05:30
WorkspaceAuditing.json
WorkspaceUsage.json Workspace Usage 2022-01-12 10:48:27 +00:00
ZimperiumWorkbooks.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerFirewall.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerOffice365Apps.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerThreats.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerWebOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
esetSMCWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
microsoftdefenderforidentity.json Update and rename defenderforidentity.json to microsoftdefenderforidentity.json 2022-06-15 21:30:16 +05:30
pfsense.json

README.md

How to contribute new workbook

This assumes you already have a workbook that you want to share as a Microsoft Sentinel template.
Once this process is completed, Microsoft Sentinel users will be able to save an instance of your template that will visualize the data in their own workspace.

To learn how to create workbooks - go to workbooks documentation.

  1. Go to your workbook -> edit mode -> advanced editor.

  2. Copy the gallery template.

  3. Add fromTemplateId to your template - this allows us to identify in our telemetry the specific sentinel workbook that was opened. Please be consistent with the format sentinel-"workbookName", for example (in the end of the gallery template):

     "styleSettings": {},
     "fromTemplateId": "sentinel-MyNewWorkbook",
     "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
    
    
  4. Capture 2 screenshots of your workbook - in dark and light theme (this will eventually be the preview images displayed in the workbooks blade).

Step 2 - Create a pull request to this repository

This pull request will contain:

  • The screenshots of your workbook. Place them under workbooks/images/preview.
    Please be consistent with the filename conventions - the dark theme filename should contain the word "black" and the light theme image should contain the word "white".

  • The gallery template json of your workbook. Place it directly under workbooks directory.

  • (optional) A logo that you want the workbook to display. Place it under workbooks/images/logos - if not supplied - it will be the generic workbooks logo.
    This logo should be in SVG format.

  • Change workbooksMetadata.json file, so that it will contain a new section, which will include:

    {
     "workbookKey": "YourWorkbookKey", // in the format of "<Name>Workbook" - not important what exactly is the name, just make sure it is unique and related to the workbook, for example PaloAltoOverviewWorkbook
    
     "logoFileName": "",//If you added logo - its name goes here
    
     "description": "description of the workbook.", // Will be displayed on the workbooks blade next to the logo and preview images
    
     "dataTypesDependencies": [ "Datatype" ],//The data type(s) that your workbook queries
    
     "dataConnectorsDependencies": [],//Relevant connectors
    
     "previewImagesFileNames": [ ],//The relative path of the preview images you saved under workbooks/images/previews
    
     "version": "1.0", // if this is a new workbook - this should be "1.0"
    
     "title": "Workbook title",//This should be the name of the workbook which will be displayed in the main workbooks blade - for example "Palo Alto overview"
    
     "templateRelativePath": "MyNewWorkbook.json",//The relative path of the JSON of the template (the gallery template you saved) 
    
     "subtitle": "",
    
     "provider": "Microsoft" //The provider of the workbook
     }
    
    

Here is an example of the JSON of Palo Alto workbook:

   {
  "workbookKey": "PaloAltoOverviewWorkbook",
  "logoFileName": "paloalto_logo.svg",
  "description": "Gain insights and comprehensive monitoring into Palo Alto firewalls by analyzing traffic and activities.\nThis workbook correlates all Palo Alto data with threat events to identify suspicious entities and relationships.\nYou can learn about trends across user and data traffic, and drill down into Palo Alto Wildfire and filter results.",
  "dataTypesDependencies": [ "CommonSecurityLog" ],
  "dataConnectorsDependencies": [ "PaloAlto" ],
  "previewImagesFileNames": [ "PaloAltoOverviewWhite1.png", "PaloAltoOverviewBlack1.png", "PaloAltoOverviewWhite2.png", "PaloAltoOverviewBlack2.png", "PaloAltoOverviewWhite3.png", "PaloAltoOverviewBlack3.png" ],
  "version": "1.1",
  "title": "Palo Alto overview",
  "templateRelativePath": "PaloAltoOverview.json",
  "subtitle": "",
  "provider": "Microsoft"
  },

After this PR is approved and completed, every 2 weeks the workbooks in Sentinel will be synced with the ones in github.

How to update an existing workbook

Just create a pull request to this repository in which you change the version of the relevant workbook in the WorkbooksMetadata.json file and change the relevant JSON of the workbook you would like to update. If needed, also update the preview images or the data types.

For any feedback on the instructions Open an issue