Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CTERA Solution for Azure Sentinel #11169

Open
wants to merge 7 commits into
base: master
Choose a base branch
from

Conversation

roberteliass
Copy link

Required items, please complete

Change(s):
Updated files:

  • Analytic Rules
    • RansomwareUserBlocked.yaml
    • RansomwareDetected.yaml
  • Data
    • Solution_CTERA.json
  • Data Connectors
    • CTERA_Data_Connector.json
  • Hunting Queries
    • MassAccessDenied.yaml
    • MassPermissionChanges.yaml
    • MassDeletions.yaml
  • Package
    • mainTemplate.json
    • createUiDefinition.json
  • Workbooks
    • CTERA_Workbook.json
  • ReleaseNotes.md
  • SolutionMetadata.json

Reason for Change(s):

  • These updates include enhancements to the overall structure, improved detection capabilities, and better integration with the CTERA solution. Bug fixes and optimizations. Resolves validation issues encountered in prior submissions.

Version Updated:

  • yes
  • Version field updated for Detections/Analytic Rule templates.

Testing Completed:

  • Tested in Microsoft Sentinel environment without custom parsers, functions, or tables.
  • Validated functionality and ensured proper syntax execution.

Checked that the validations are passing and have addressed any issues that are present:
- Yes, validation checks were run, and all identified issues were addressed.

@roberteliass roberteliass requested review from a team as code owners September 23, 2024 10:59
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Sep 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants