Skip to content

New NRT Rules Created#4112

Merged
aprakash13 merged 4 commits into
masterfrom
pebryan/2022-2-7_NRT_Rules
Feb 8, 2022
Merged

New NRT Rules Created#4112
aprakash13 merged 4 commits into
masterfrom
pebryan/2022-2-7_NRT_Rules

Conversation

@petebryan
Copy link
Copy Markdown
Contributor

Change(s):
Created several new NRT rule templates:

  • Created from existing scheduled detections
  • Some minor changes to support NRT limitations.
  1. AWS Login without MFA
  2. ADFS Trust Modifications
  3. New App or SP Credential
  4. PIM request rejected
  5. User added to privileged group
  6. New ADFS Server
  7. KeyVault Sensitive Operation
  8. Mining Pool Detection (2 detections)
  9. Malicious inbox rules (2 detections)
  10. Security Logs being cleared
  11. B64 Encoded PE files or command lines (2 detections)
  12. MFA rejected by user

The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly. If your submission requires a custom parser or function, it must be submitted with the PR.

Testing Completed:

  • Yes

Note: If updating a detection, you must update the version field.

After the submission has been made, please look at the Validation Checks.

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Note: Let us know if you have tried fixing the validation error and need help.

References:


@petebryan petebryan marked this pull request as ready for review February 8, 2022 00:16
Copy link
Copy Markdown
Contributor

@aprakash13 aprakash13 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The queries look great. Thanks @petebryan. A couple of small typos that we can probably fix and this would be ready to be merged

Comment thread Detections/AWSCloudTrail/NRT_AWS_ConsoleLogonWithoutMFA.yaml Outdated
Comment thread Detections/SigninLogs/NRT_MFARejectedbyUser.yaml Outdated
@aprakash13 aprakash13 self-assigned this Feb 8, 2022
@aprakash13 aprakash13 added the Detection Detection specialty review needed label Feb 8, 2022
@petebryan
Copy link
Copy Markdown
Contributor Author

Thanks so much @aprakash13! Good spot on those typos, all updated.

Copy link
Copy Markdown
Contributor

@aprakash13 aprakash13 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Pete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Detection Detection specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants