Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recorded Future solution2.5 #8473

Merged
merged 19 commits into from
Oct 11, 2023

Conversation

RecordedFutureOskbo
Copy link
Contributor

@RecordedFutureOskbo RecordedFutureOskbo commented Jul 7, 2023

Changes:

  • New playbooks using the new TI Api for ingesting ThreatIntelligenceIndicator
  • Message in app and documetaion about deprecating graph API for TI indicators.
  • New correlation workbooks using the format of the TI data.
  • New Alert logic app and workbook, downloading alerts from Recorded Future into custom log and visualizing the result.
  • New "PlaybookAlert" logic app and workbook, pulling playbookalerts from Recorded Future to a custom log and visualizing the result.
  • Render incident comments serverside for entity enrichment.
  • Solution versioning, tagging and changelog improvements.
  • Readme updates

Reason for Changes:

  • Deprication of GraphAPI for ingesting Threat Intelligence.
  • New Alert and PlaybookAlert integration.

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Please contact us if you have questions or want to set up a meeting where we talk through the changes.

@v-prasadboke v-prasadboke added Playbook Playbook specialty review needed Solution Solution specialty review needed labels Jul 7, 2023
@v-prasadboke
Copy link
Contributor

We wanted to check on the status of PR #8473. PR is pending for more than 30 days. Please let us know if you need any assistance to review this PR. Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR. Thank you for your cooperation.

@RecordedFutureOskbo
Copy link
Contributor Author

We wanted to check on the status of PR #8473. PR is pending for more than 30 days. Please let us know if you need any assistance to review this PR. Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR. Thank you for your cooperation.

We have been waiting for our Power Platform Connector to be certified and rolled out before activating this PR. Good news is that it's released since last week. We are doing final testing and will activate this PR within days.

@RecordedFutureOskbo RecordedFutureOskbo marked this pull request as ready for review September 13, 2023 18:00
@RecordedFutureOskbo RecordedFutureOskbo requested review from a team as code owners September 13, 2023 18:00
@RecordedFutureOskbo
Copy link
Contributor Author

@v-prasadboke we are ready for review finally.

@v-prasadboke
Copy link
Contributor

v-prasadboke commented Sep 14, 2023

Hello @RecordedFutureOskbo, Thank you for marking this PR as ready for review. This PR will be investigated and will update you about the same before 19 September, 2023. Till Then please repackage the solution using V3 tool. You can refer this readme for more clarification.
https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md
Thanks.

@RecordedFutureOskbo
Copy link
Contributor Author

I did a merge with master yesterday and did used the V3 tool for packaging the solution.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Please update the branch from master.

@RecordedFutureOskbo
Copy link
Contributor Author

@v-prasadboke I need help!
After I updated the version in the Solution_RecordedFuture.json to 3.0.0 I get validation errors that I have a hard time to track back to my ARM files.
image

My current ARM files works when I run them in [Deploy custom template] and the same files validated in previous versions.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Is there any other except this

@v-prasadboke
Copy link
Contributor

Thank you @RecordedFutureOskbo, For adding the sample data. I'll test the content and update you about the same before 22 September, 2023.

@RecordedFutureOskbo
Copy link
Contributor Author

I see the Azure.Sentinel test is failing on "RecordedFutureURLCorrelationWhite.png" but the file is in the PR if I'm not mistaken.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Please rename the underlined text to
"RecordedFutureUrlCorrelationWhite.png"
"RecordedFutureUrlCorrelationBlack.png"
image

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Can you provide me access to your branch.
Thanks.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Sorry for the inconvenience. This PR is still under investigation and will update you before 26 September, 2023.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, We have uploaded the sample data to test the content of the solution. Will review the content and update you before 29 September, 2023.

@v-prasadboke
Copy link
Contributor

Hello @RecordedFutureOskbo, Deployment is failing for Recorded Future Alert Importer playbook.
image

@RecordedFutureOskbo
Copy link
Contributor Author

Hello @RecordedFutureOskbo, Deployment is failing for Recorded Future Alert Importer playbook. image

Thanks, found and fixed.

@v-atulyadav
Copy link
Contributor

Hi @RecordedFutureOskbo, validations are stuck could you please take latest of master into your branch. Thanks

@v-atulyadav
Copy link
Contributor

Thanks @RecordedFutureOskbo.

@v-prasadboke
Copy link
Contributor

Thank you @RecordedFutureOskbo for committing the requested changes.
Will take a look at it and update you about the same before 09 October, 2023.

@RecordedFutureOskbo
Copy link
Contributor Author

@v-prasadboke I don't mind going on a teams call in order to get progression on this PR.

@v-prasadboke
Copy link
Contributor

v-prasadboke commented Oct 9, 2023

Hello @RecordedFutureOskbo Can you please tell me your time zone and availability as per the same.
I work in IST time zone and I'm available tomorrow from 4:30 PM IST onwards.
Also can you please provide me your branch access. I'm unable to pull all the latest changes.
Thanks.

@RecordedFutureOskbo
Copy link
Contributor Author

c

I'm in Europe CET and will make time for you if you set up a call.

@v-prasadboke
Copy link
Contributor

v-prasadboke commented Oct 10, 2023

@v-prasadboke
Copy link
Contributor

v-prasadboke commented Oct 10, 2023

v-prasadboke
v-prasadboke previously approved these changes Oct 10, 2023
@v-prasadboke
Copy link
Contributor

14983aa3-9ee2-40f2-a01e-8563d61ca383
b5d64d9f-a518-434f-9d60-992c2b6db6ad
bafd4f38-0de9-4078-98d7-320b7c73a7ee
1bf28b68-3d97-4cad-a1bb-72cdb688daac
b6783ce6-a718-4d77-a960-ce446a011af1
b17f3ea8-b0da-4713-9382-bee881db284c

Screenshot received

@v-atulyadav v-atulyadav merged commit 0a00eb1 into Azure:master Oct 11, 2023
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-package Playbook Playbook specialty review needed Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants