Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Template analytics rule - PossibleAiTMPhishingAttemptAgainstAAD - has an error #8833

Closed
Celine-REN opened this issue Aug 21, 2023 · 9 comments
Assignees

Comments

@Celine-REN
Copy link

Bug Description
Upon attempting to enable the "Possible AiTM Phishing Attempt Against Azure AD" analytics rule within the "Security Threat Essentials" solution from the Content hub, an error is encountered. This occurs despite having ingested Sign-In logs in the Sentinel workspace. The query consistently triggers the following error message:

"Some aspects of the query had errors, resulting in incomplete results. Should the issue persist, we recommend opening a support ticket. Request ID: 182d8822-3279-4c3e-b001-112a4a4573ec."

Steps to Reproduce

  1. Install the "Security Threat Essentials" solution from the Content hub.
  2. Enable the "Possible AiTM Phishing Attempt Against Azure AD" analytics rule.
  3. Simulate the query.

Expected Behavior
The query should execute without errors.

Screenshots
image

Additional Context
This issue is reproducible across all of our Sentinel workspaces.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

2 similar comments
@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-rbajaj
Copy link
Contributor

Hi @Celine-REN, thanks for flagging this, we will soon provide an update on this.

@Celine-REN
Copy link
Author

Hello @v-rbajaj, Anticipating your updates eagerly! Thank you!

@v-rbajaj
Copy link
Contributor

Hi @Celine-REN, Thanks for flagging, I can see this analytical rule has been modified recently in our 3.0.0 version of the solution which is currently live as well, can you please let me know if you are using the latest version of the solution?
Thanks.

@v-rbajaj
Copy link
Contributor

Hi @Celine-REN, can you please provide an update on this?

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Sep 1, 2023

Since we have not received a response in the last 5 days, we are closing your issue #8833 as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

@v-rbajaj v-rbajaj closed this as completed Sep 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants