Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Solution - Microsoft Defender Threat Intelligence missing 4 playbooks #9829

Closed
MikeP1375 opened this issue Jan 26, 2024 · 3 comments · Fixed by #9880
Closed

Solution - Microsoft Defender Threat Intelligence missing 4 playbooks #9829

MikeP1375 opened this issue Jan 26, 2024 · 3 comments · Fixed by #9880
Assignees
Labels
Solution Solution specialty review needed

Comments

@MikeP1375
Copy link

Describe the bug
The content hub solution "Microsoft Defender Threat Intelligence" only has 4 playbooks but GitHub solution itself reports 8 playbooks.

To Reproduce
Steps to reproduce the behavior:

  1. Go to Content Hub.
  2. Install content solution 'Deploy the content hub solution "Microsoft Defender Threat Intelligence" and you will get 4 playbooks.'
  3. Go to automation -> Playbook templates.
  4. Filter for 'MDTI'.
  5. Output is 'MDT-Automated-Triage', 'MDTI-Intel-Reputation', 'MDTI-Base', 'MDTI-Data-WebComponents'.

Expected behavior
Output should have the following playbooks

  • MDT-Automated-Triage
  • MDTI-Intel-Reputation
  • MDTI-Base
  • MDTI-Data-WebComponents
  • MDTI-Data-Cookies
  • MDTI-PassiveDns
  • MDTI-PassiveDnsReverse
  • MDTI-Trackers

See Playbook folder in GitHub - https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Microsoft%20Defender%20Threat%20Intelligence/Playbooks

Screenshots
image

image

Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-sudkharat v-sudkharat added the Solution Solution specialty review needed label Jan 29, 2024
@v-sudkharat
Copy link
Contributor

Hi @MikeP1375, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 01-02-2024. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @MikeP1375, I hope you are doing well. We have created a pull request by including those playbooks in the solution. The changes will be reflected in the upcoming version of the solution.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants