Azure-Sentinel/Detections
Shain eb818b4448
Merge pull request #1661 from Cyb3rWard0g/master
Update MailPermissionsAddedToApplication.yaml
2021-02-01 16:00:03 -08:00
..
AWSCloudTrail Remove inconsistent BOMs from detections 2020-11-19 16:57:39 +00:00
AlsidForAD Replace hard coded codenames by datatable in analytic rules 2020-12-07 11:55:04 +01:00
AuditLogs Merge pull request #1661 from Cyb3rWard0g/master 2021-02-01 16:00:03 -08:00
AzureActivity New queries and some fixes 2020-12-19 17:31:36 +00:00
AzureDevOpsAuditing updating connector value in template 2021-01-15 16:29:02 -08:00
AzureDiagnostics Merge pull request #1590 from Azure/shainw-connectorFix 2021-01-19 21:37:02 -08:00
AzureFirewall Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
CommonSecurityLog adding materialise in time series queries 2021-01-20 17:58:08 -08:00
DeviceEvents Removing unicod chars 2021-01-31 12:59:07 -08:00
DeviceFileEvents Add identifier-level validation for new entity mappings in templates (#1680) 2021-01-31 16:35:50 +02:00
DeviceNetworkEvents Add identifier-level validation for new entity mappings in templates (#1680) 2021-01-31 16:35:50 +02:00
DeviceProcessEvents Add identifier-level validation for new entity mappings in templates (#1680) 2021-01-31 16:35:50 +02:00
DnsEvents Remove inconsistent BOMs from detections 2020-11-19 16:57:39 +00:00
EsetSMC Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
GitHub Merge pull request #1582 from Azure/Fix-a-template 2021-01-19 23:00:10 -08:00
InfobloxNIOS Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
LAQueryLogs Removing validation skip 2021-01-21 07:50:03 -08:00
MultipleDataSources Couple additional fixes 2021-02-01 08:22:36 -08:00
OfficeActivity Merge pull request #1590 from Azure/shainw-connectorFix 2021-01-19 21:37:02 -08:00
OktaSSO Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
ProofpointTAP Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
PulseConnectSecure Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
QualysVM Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
SecurityAlert adding tags 2021-01-15 17:26:22 -08:00
SecurityEvent adding materialise in time series queries 2021-01-20 17:58:08 -08:00
SigninLogs Updated Brute Force Attack against GitHub Account detection query 2021-01-20 12:59:23 -08:00
SophosXGFirewall Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
SymantecEndpointProtection added validation 2020-12-21 16:36:01 -08:00
SymantecProxySG Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
SymantecVIP Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
Syslog Remove inconsistent BOMs from detections 2020-11-19 16:57:39 +00:00
ThreatIntelligenceIndicator updating connector value in template 2021-01-15 16:29:02 -08:00
TrendMicroXDR Trend Micro XDR Initial Commit (#1353) 2020-12-09 18:57:49 -08:00
VMwareCarbonBlack Feature/lahisham/migrate scheduled templates to new entity mapping (#1319) 2020-11-17 17:27:25 +02:00
W3CIISLog Merge pull request #1601 from Ronmarsiano/master 2021-01-19 23:00:46 -08:00
ZoomLogs Couple additional fixes 2021-02-01 08:22:36 -08:00
readme.md Update readme.md 2020-06-26 11:46:22 -07:00

readme.md

About

This folder contains Detections based on different types of data sources that you can leverage in order to create alerts and respond to threats in your environment.

For general information please start with the Wiki pages.

More Specific to Detections:

  • Contribute to Analytic Templates (Detections) and Hunting queries
  • Specifics on what is required for Detections and Hunting queries is in the Query Style Guide
  • These detections are written using KQL query langauge and will provide you a starting point to protect your environment and get familiar with the different data tables.
  • To enable these detections in your environment follow the out of the box guidance.
  • The rule created will run the query on the scheduled time that was defined, and trigger an alert that will be seen both in the SecurityAlert table and in a case in the Incidents tab

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com