Skip to content

Commit

Permalink
add IdentityInfo/BehaviourAnalytics to missing detections
Browse files Browse the repository at this point in the history
  • Loading branch information
Sebastian Wiszowaty committed Aug 30, 2023
1 parent 858f865 commit 3e8b65b
Show file tree
Hide file tree
Showing 4 changed files with 12 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,9 @@ requiredDataConnectors:
- connectorId: BehaviorAnalytics
dataTypes:
- BehaviorAnalytics
- connectorId: BehaviorAnalytics
dataTypes:
- IdentityInfo
queryFrequency: 1d
queryPeriod: 1d
triggerOperator: gt
Expand Down
3 changes: 3 additions & 0 deletions Detections/MultipleDataSources/RunCommandUEBABreach.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: AzureActivity
dataTypes:
- AzureActivity
- connectorId: BehaviorAnalytics
dataTypes:
- BehaviorAnalytics
queryFrequency: 1d
queryPeriod: 2d
triggerOperator: gt
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ requiredDataConnectors:
- connectorId: BehaviorAnalytics
dataTypes:
- BehaviorAnalytics
- connectorId: BehaviorAnalytics
dataTypes:
- IdentityInfo
queryFrequency: 1d
queryPeriod: 7d
triggerOperator: gt
Expand Down
3 changes: 3 additions & 0 deletions Detections/SigninLogs/PrivilegedUserLogonfromnewASN.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@ requiredDataConnectors:
- connectorId: BehaviorAnalytics
dataTypes:
- BehaviorAnalytics
- connectorId: BehaviorAnalytics
dataTypes:
- IdentityInfo
queryFrequency: 1d
queryPeriod: 7d
triggerOperator: gt
Expand Down

0 comments on commit 3e8b65b

Please sign in to comment.