From d5bfcc4dad054eaf02bf1aa7aa3e22207ab33970 Mon Sep 17 00:00:00 2001 From: Dvir Naim <106969883+dvir-ms@users.noreply.github.com> Date: Thu, 7 Sep 2023 14:52:37 +0300 Subject: [PATCH 1/5] Update sapcon-sentinel-ui-agent-kickstart.sh --- Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh b/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh index da2daa00203..aeb304cc3ce 100644 --- a/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh +++ b/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh @@ -61,6 +61,10 @@ while [[ $# -gt 0 ]]; do APPID="$2" shift 2 ;; + --hostnetwork) + HOSTNETWORK=1 + shift 1 + ;; --appsecret) APPSECRET="$2" shift 2 @@ -424,7 +428,9 @@ elif [ "$MODE" == "kvsi" ]; then log "Creating agent and configuring to use Azure Key vault and application authentication" cmdparams+=" -e AZURE_CLIENT_ID=$APPID -e AZURE_CLIENT_SECRET=$APPSECRET -e AZURE_TENANT_ID=$TENANT" fi - +if [ $HOSTNETWORK ]; then + cmdparams+=" --network host" +fi sudo docker create -v "$sysfileloc":/sapcon-app/sapcon/config/system $cmdparams --name "$containername" $dockerimage$tagver >/dev/null log 'Created Microsoft Sentinel SAP agent '"$AGENTNAME" From edee3c4fc2ba0c674c8a49846b74eee6c561c7b8 Mon Sep 17 00:00:00 2001 From: Dvir Naim <106969883+dvir-ms@users.noreply.github.com> Date: Thu, 7 Sep 2023 15:29:21 +0300 Subject: [PATCH 2/5] Update sapcon-sentinel-kickstart.sh --- Solutions/SAP/sapcon-sentinel-kickstart.sh | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/Solutions/SAP/sapcon-sentinel-kickstart.sh b/Solutions/SAP/sapcon-sentinel-kickstart.sh index fc7c5dcd35b..a06cd1548c4 100755 --- a/Solutions/SAP/sapcon-sentinel-kickstart.sh +++ b/Solutions/SAP/sapcon-sentinel-kickstart.sh @@ -118,6 +118,10 @@ while [[ $# -gt 0 ]]; do SID="$2" shift 2 ;; + --hostnetwork) + HOSTNETWORK=1 + shift 1 + ;; --clientnumber) CLIENTNUMBER="$2" shift 2 @@ -787,6 +791,10 @@ cmdparams=" --label Cloud=$CLOUD" # Generating SENTINEL_AGENT_GUID cmdparams+=" -e SENTINEL_AGENT_GUID=$(uuidgen) " +if [ $HOSTNETWORK ]; then + cmdparams+=" --network host" +fi + if [ "$MODE" == "kvmi" ]; then echo "Creating docker container for use with Azure Key vault and managed VM identity" sudo docker create -v "$sysfileloc":/sapcon-app/sapcon/config/system $cmdparams $sncline $httpproxyline --name "$containername" $dockerimage$tagver >/dev/null From d0a9fa4af02a08e01330cc6c9f559a665ebbd4e1 Mon Sep 17 00:00:00 2001 From: Dvir Naim <106969883+dvir-ms@users.noreply.github.com> Date: Thu, 7 Sep 2023 15:30:03 +0300 Subject: [PATCH 3/5] Update sapcon-sentinel-ui-agent-kickstart.sh --- Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh b/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh index aeb304cc3ce..9e9187f3301 100644 --- a/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh +++ b/Solutions/SAP/sapcon-sentinel-ui-agent-kickstart.sh @@ -136,6 +136,7 @@ while [[ $# -gt 0 ]]; do echo "--keymode [kvmi|kvsi]" echo "--configpath " echo "--sdk " + echo "--hostnetwork" echo "--network " echo "--appid " echo "--appsecret " From 01e9d64812ce2b90a2c970a6c9e92ed17cc44db2 Mon Sep 17 00:00:00 2001 From: Dvir Naim <106969883+dvir-ms@users.noreply.github.com> Date: Thu, 7 Sep 2023 15:30:25 +0300 Subject: [PATCH 4/5] Update sapcon-sentinel-kickstart.sh --- Solutions/SAP/sapcon-sentinel-kickstart.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/Solutions/SAP/sapcon-sentinel-kickstart.sh b/Solutions/SAP/sapcon-sentinel-kickstart.sh index a06cd1548c4..64852cce9c6 100755 --- a/Solutions/SAP/sapcon-sentinel-kickstart.sh +++ b/Solutions/SAP/sapcon-sentinel-kickstart.sh @@ -269,6 +269,7 @@ while [[ $# -gt 0 ]]; do echo "--abapserver " echo "--systemnr " echo "--sid " + echo "--hostnetwork" echo "--clientnumber " echo "--messageserverhost " echo "--messageserverport " From 0742d02cd94d2a8f17aed36931611c0c94a72b02 Mon Sep 17 00:00:00 2001 From: v-prasadboke <117061676+v-prasadboke@users.noreply.github.com> Date: Fri, 8 Sep 2023 12:48:58 +0530 Subject: [PATCH 5/5] Update WorkbookPreviewImageValidationSkipList.json --- .../WorkbookPreviewImageValidationSkipList.json | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.script/utils/workbookCheckers/WorkbookPreviewImageValidationSkipList.json b/.script/utils/workbookCheckers/WorkbookPreviewImageValidationSkipList.json index 4ecde38d3a7..47e3cdf3f87 100644 --- a/.script/utils/workbookCheckers/WorkbookPreviewImageValidationSkipList.json +++ b/.script/utils/workbookCheckers/WorkbookPreviewImageValidationSkipList.json @@ -22,6 +22,12 @@ "NCProtectWorkbook", "SAP-Monitors-AlertsandPerformance", "SAP-SecurityAuditlogandInitialAccess", - "SAP-AuditControls" + "SAP-AuditControls", + "IslandAdminAuditOverview", + "IslandUserActivityOverview", + "BloodHoundEnterpriseAttackPathWorkbook", + "BloodHoundEnterprisePostureWorkbook", + "UserWorkbook-alexdemichieli-github-update-1", + "SalemDashboard" ] }