Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added 5 New Analytic Rule Detections for Azure WAF #8784

Merged
merged 19 commits into from
Aug 29, 2023

Conversation

shabaz-github
Copy link
Contributor

Added new analytic rules for Path Traversal Attack, Code Injection Attack and Scanner Detection Attack

Required items, please complete:

Change(s):

  • Added the following 5 New Analytic Rule Detections for Azure WAF
    - AFD-WAF-Code-Injection.yaml
    - AFD-WAF-Path-traversal-Attack.yaml
    - App-GW WAF-Code_injection.yaml
    - App-GW-WAF-Path-Traversal-Attack.yaml
    - App-GW-WAF-Scanner-detection.yaml

Reason for Change(s):

  • Adding new detection queries for Azure WAF

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Added new analytic rules for Path Traversal Attack, Code Injection Attack and Scanner Detection Attack
@shabaz-github shabaz-github requested review from a team as code owners August 14, 2023 16:31
@v-atulyadav v-atulyadav added Solution Solution specialty review needed Analytic Rules labels Aug 16, 2023
@v-atulyadav
Copy link
Contributor

Hi @shabaz-github,
Thank you for raising Pull Request with us! We will review the Pull Request internally and get back to you by shortly.
Thanks

@v-rusraut
Copy link
Contributor

Hi @shabaz-github,
Status property is not present in Analytic Rule, please add it.
And we need sample data for testing Analytic Rule.
Please upload sample data into below path.
Path : \Azure-Sentinel\Sample Data\Custom
Thanks

@v-rusraut
Copy link
Contributor

Hi @shabaz-github,
Please work on above comment and also provide sample data for testing Analytic Rule.
Thanks.

@v-rusraut
Copy link
Contributor

Hi @shabaz-github,
Please add status property in Analytic Rules, refer below image for reference.

4

And also provide sample data for testing Analytic Rules.
Thanks

@shabaz-github
Copy link
Contributor Author

@v-rusraut Status property has been added - Could you please guide on how to get the sample data added?

@shabaz-github
Copy link
Contributor Author

shabaz-github commented Aug 24, 2023

@v-rusraut Could you please also help with fixing the check error 'run script on changing detections / add-comment / comment (pull_request)' not sure why this check is failing.

@v-rusraut
Copy link
Contributor

@v-rusraut Status property has been added - Could you please guide on how to get the sample data added?
Hi @shabaz-github,
Please upload sample data on below path
https://github.com/Azure/Azure-Sentinel/tree/master/Sample%20Data/Custom
Thanks

@v-rusraut
Copy link
Contributor

Hi @shabaz-github,
To resolve the validation error please update your branch from master branch and commit again.
Thanks

@v-atulyadav
Copy link
Contributor

Hi @shabaz-github,
Please add sample data as requested earlier. Thanks

Added Sample data for analytic detection validation
@shabaz-github
Copy link
Contributor Author

@v-atulyadav Sample data csv files have been added

@v-atulyadav v-atulyadav merged commit 52c84c5 into Azure:master Aug 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Analytic Rules Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants