Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Analytic rule description link is broken #9129

Closed
applefacts opened this issue Sep 29, 2023 · 4 comments · Fixed by #9136
Closed

Analytic rule description link is broken #9129

applefacts opened this issue Sep 29, 2023 · 4 comments · Fixed by #9136
Assignees
Labels

Comments

@applefacts
Copy link

https://github.com/Azure/Azure-Sentinel/blob/a6593c2bb08c6cb6fbcaabdd961c83ef9f9b89b1/Solutions/Network%20Session%20Essentials/Analytic%20Rules/PossibleBeaconingActivity.yaml

This rule identifies beaconing patterns from Network traffic logs based on recurrent frequency patterns. Such potential outbound beaconing pattern to untrusted public networks should be investigated for any malware callbacks or data exfiltration attempts as discussed in this Blog.<br>

This analytic rule uses ASIM and supports any built-in or custom source that supports the ASIM NetworkSession schema'

The blog doesn't exist anymore.

Additional context
Add any other context about the problem here.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Oct 3, 2023

Hi @applefacts, I think this blog can be found here - https://medium.com/@HuntOperator/detect-beaconing-with-flare-elastic-stack-and-intrusion-detection-systems-110dc74e0c56

Please confirm the link, we will raise a PR and update the same.

@azurekid
Copy link
Contributor

azurekid commented Oct 3, 2023

Validated link and added a PR: #9136

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Oct 3, 2023

Hi @azurekid, thanks for confirming, we will review the PR and will update you.

@v-rbajaj v-rbajaj linked a pull request Oct 3, 2023 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants