-
Notifications
You must be signed in to change notification settings - Fork 3.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create Protocols passing authentication in cleartext (ASIM Network Se… #9975
Conversation
Hello @praveenthepro, any reason behind adding multiple connector id's |
…ssion schema) updated the required connectors
@v-prasadboke The hunting query was written using the ASIM functions that's why I used all the related connectors, but I removed all the connectors after validating with the engineer team, So kindly checkout again |
...ion Essentials/Hunting Queries/Detect Outbound LDAP Traffic(ASIM Network Session schema).txt
Outdated
Show resolved
Hide resolved
... Essentials/Hunting Queries/Remote Desktop Network Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
e55ae48
to
c9a0e5d
Compare
reduce description below 255
Reduced the description below 255
…).yaml Enhenced the grouping
Hello @praveenthepro, Please let me know if you have any pending updates/modification from your side so that I can investigate the PR. |
@v-prasadboke go ahead and start investigating the PR |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@praveenthepro Few suggestions for Hunting queries,
- Add entity mappings
- For every entity mapping extend the KQL as entity_0_field = column_name
- Add version property
Refer this hunting query for reference, https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Windows%20Security%20Events/Hunting%20Queries/CommandsexecutedbyWMIonnewhosts-potentialImpacket.yaml
added the entity mappings and version
…ssion schema).yaml added version and entity mappings
added version and entity mappings
@v-prasadboke added the entity and version |
Hello @praveenthepro, I see you have committed changes which were requested by Rahul. But these are incomplete commits. I have attached a screenshot for your reference. Thanks, |
Hello @praveenthepro, I see you have committed changes which were requested by Rahul. But these are incomplete commits. Rahul has mentioned to update KQL query with adding **entity_0_field = column_name** to it. @v-prasadboke Thanks Prasad, Added the new entities as like on the screenshot, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@praveenthepro Please address the inline comment.
...k Session Essentials/Analytic Rules/Anomaly in SMB Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
...k Session Essentials/Analytic Rules/Anomaly in SMB Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
...k Session Essentials/Analytic Rules/Anomaly in SMB Traffic(ASIM Network Session schema).yaml
Show resolved
Hide resolved
...sentials/Analytic Rules/Remote Desktop Network Bruteforce (ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
...sentials/Analytic Rules/Remote Desktop Network Bruteforce (ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
...ing Queries/Protocols passing authentication in cleartext (ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
... Essentials/Hunting Queries/Remote Desktop Network Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
... Essentials/Hunting Queries/Remote Desktop Network Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
... Essentials/Hunting Queries/Remote Desktop Network Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
... Essentials/Hunting Queries/Remote Desktop Network Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
Changed the time filter to use built-in function and fixed the description.
…sion schema).yaml to Remote Desktop Network Brute force (ASIM Network Session schema).yaml fixed the event filters using built-in functions and updated the description
updated the function and fixed the entity
…ssion schema).yaml fixed the function and updated the entities
fixed the function and the entity
…ssion schema).yaml
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@praveenthepro There is one more inline comment.
...k Session Essentials/Analytic Rules/Anomaly in SMB Traffic(ASIM Network Session schema).yaml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes look good.
Thank you Rahul for the approval. |
…ssion schema)
Required items, please complete
Change(s):
Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present:
Guidance <- remove section before submitting
Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:
Thank you for your contribution to the Microsoft Sentinel Github repo.
Change(s):
Reason for Change(s):
Version updated:
Testing Completed:
Note: If updating a detection, you must update the version field.
Checked that the validations are passing and have addressed any issues that are present:
Note: Let us know if you have tried fixing the validation error and need help.