Skip to content
Merged

commit #4547

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions Sample Data/CEF/Fortigate.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
[
{
"TimeGenerated": "3/31/2022, 10:52:35.857 AM",
"DeviceVendor": "Fortinet",
"DeviceProduct": "Fortigate",
"DeviceEventClassID": 28704,
"LogSeverity": 2,
"Computer": "Contoso-MainFW",
"CommunicationDirection": 1,
"DestinationPort": 3389,
"DestinationIP": "192.168.20.58",
"Message": "Remote.Access: RDP,",
"Protocol": 6,
"SourcePort": 15577,
"SourceIP": "213.252.245.73",
"RemoteIP": 0,
"RemotePort": 3389,
"DeviceVersion": "v6.4.7",
"Activity": "utm:app-ctrl signature pass",
"AdditionalExtensions": "FortinetFortiGateeventtime=1647873918304240923;FortinetFortiGatetz=-0700;FortinetFortiGatelogid=1059028704;cat=utm:app-ctrl;FortinetFortiGatesubtype=app-ctrl;FortinetFortiGateeventtype=signature;FortinetFortiGatelevel=information;FortinetFortiGatevd=root;FortinetFortiGateappid=15511;FortinetFortiGatesrcintfrole=wan;FortinetFortiGatedstintfrole=lan;FortinetFortiGatepolicyid=3;FortinetFortiGateapplist=default;FortinetFortiGateaction=pass;FortinetFortiGateappcat=Remote.Access;FortinetFortiGateapp=RDP;FortinetFortiGateincidentserialno=212209995;FortinetFortiGateapprisk=high",
"ApplicationProtocol": "RDP",
"DeviceExternalID": "FGVM4VTM21000724",
"DeviceInboundInterface": "port1",
"DeviceOutboundInterface": "port2",
"ExternalID": 14430578,
"Type": "CommonSecurityLog"
},
{
"TimeGenerated": "3/31/2022, 10:52:35.857 AM",
"DeviceVendor": "Fortinet",
"DeviceProduct": "Fortigate",
"DeviceEventClassID": 28704,
"LogSeverity": 2,
"Computer": "Contoso-MainFW",
"CommunicationDirection": 1,
"DestinationPort": 3389,
"DestinationIP": "192.168.20.44",
"Message": "Remote.Access: RDP,",
"Protocol": 6,
"SourcePort": 15577,
"SourceIP": "104.168.141.190",
"RemoteIP": 0,
"RemotePort": 3389,
"DeviceVersion": "v6.4.7",
"Activity": "utm:app-ctrl signature pass",
"AdditionalExtensions": "FortinetFortiGateeventtime=1647873918304240923;FortinetFortiGatetz=-0700;FortinetFortiGatelogid=1059028704;cat=utm:app-ctrl;FortinetFortiGatesubtype=app-ctrl;FortinetFortiGateeventtype=signature;FortinetFortiGatelevel=information;FortinetFortiGatevd=root;FortinetFortiGateappid=15511;FortinetFortiGatesrcintfrole=wan;FortinetFortiGatedstintfrole=lan;FortinetFortiGatepolicyid=3;FortinetFortiGateapplist=default;FortinetFortiGateaction=pass;FortinetFortiGateappcat=Remote.Access;FortinetFortiGateapp=RDP;FortinetFortiGateincidentserialno=212209995;FortinetFortiGateapprisk=high",
"ApplicationProtocol": "RDP",
"DeviceExternalID": "FGVM4VTM21000724",
"DeviceInboundInterface": "port1",
"DeviceOutboundInterface": "port2",
"ExternalID": 14430578,
"Type": "CommonSecurityLog",
"_ResourceId": "/subscriptions/d1d8779d-38d7-4f06-91db-9cbc8de0176f/resourcegroups/soc-fortinet/providers/microsoft.compute/virtualmachines/soc-fw-cef"
}
]
52 changes: 52 additions & 0 deletions Sample Data/CEF/ZScaler.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
[
{
"TimeGenerated": "3/30/2022, 10:52:35.857 AM",
"DeviceVendor": "Fortinet",
"DeviceProduct": "Fortigate",
"DeviceEventClassID": 28704,
"LogSeverity": 2,
"Computer": "Contoso-MainFW",
"CommunicationDirection": 1,
"DestinationPort": 3389,
"DestinationIP": "192.168.20.58",
"Message": "Remote.Access: RDP,",
"Protocol": 6,
"SourcePort": 15577,
"SourceIP": "213.252.245.73",
"RemoteIP": 0,
"RemotePort": 3389,
"DeviceVersion": "v6.4.7",
"Activity": "utm:app-ctrl signature pass",
"AdditionalExtensions": "FortinetFortiGateeventtime=1647873918304240923;FortinetFortiGatetz=-0700;FortinetFortiGatelogid=1059028704;cat=utm:app-ctrl;FortinetFortiGatesubtype=app-ctrl;FortinetFortiGateeventtype=signature;FortinetFortiGatelevel=information;FortinetFortiGatevd=root;FortinetFortiGateappid=15511;FortinetFortiGatesrcintfrole=wan;FortinetFortiGatedstintfrole=lan;FortinetFortiGatepolicyid=3;FortinetFortiGateapplist=default;FortinetFortiGateaction=pass;FortinetFortiGateappcat=Remote.Access;FortinetFortiGateapp=RDP;FortinetFortiGateincidentserialno=212209995;FortinetFortiGateapprisk=high",
"ApplicationProtocol": "RDP",
"DeviceExternalID": "FGVM4VTM21000724",
"DeviceInboundInterface": "port1",
"DeviceOutboundInterface": "port2",
"ExternalID": 14430578,
"Type": "CommonSecurityLog"
},
{
"TimeGenerated": "3/31/2022, 08:18:20.276 AM",
"DeviceVendor": "Zscaler",
"DeviceProduct": "NSSWeblog",
"DeviceEventClassID": "Allowed",
"LogSeverity": 3,
"DeviceAction": "Allowed",
"SimplifiedDeviceAction": "Allowed",
"Computer": "zscaler-nss-Contoso",
"CommunicationDirection": 1,
"DestinationIP": "108.167.132.213",
"SourceIP": "192.168.20.44",
"DeviceVersion": 5.7,
"Activity": "Allowed",
"AdditionalExtensions": "reason=Allowed;outcome=200;cat=Internet Services;rulelabel=None;ruletype=None;urlclass=Business Use;devicemodel=Virtual Machine",
"ApplicationProtocol": "HTTP",
"DestinationServiceName": "General Browsing",
"DestinationDnsDomain": "dayvidmarketingdireto.com.br",
"FileType": "None",
"ReceivedBytes": 550,
"SentBytes": 307,
"RequestURL": "http://dayvidmarketingdireto.com.br/shii/office-RD117/",
"SourceUserName": "benjamin@contoso.com"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @Yaniv-Shasha , email must be sanitized@sanitized.com rather than "benjamin@contoso.com", please check and update.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@v-sabiraj this email is used for use case that relay on this entity, it must be on this format

}
]
52 changes: 52 additions & 0 deletions Sample Data/CEF/ZScaler.json.bak
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
[
{
"TimeGenerated": "3/30/2022, 10:52:35.857 AM",
"DeviceVendor": "Fortinet",
"DeviceProduct": "Fortigate",
"DeviceEventClassID": 28704,
"LogSeverity": 2,
"Computer": "Contoso-MainFW",
"CommunicationDirection": 1,
"DestinationPort": 3389,
"DestinationIP": "192.168.20.58",
"Message": "Remote.Access: RDP,",
"Protocol": 6,
"SourcePort": 15577,
"SourceIP": "213.252.245.73",
"RemoteIP": 0,
"RemotePort": 3389,
"DeviceVersion": "v6.4.7",
"Activity": "utm:app-ctrl signature pass",
"AdditionalExtensions": "FortinetFortiGateeventtime=1647873918304240923;FortinetFortiGatetz=-0700;FortinetFortiGatelogid=1059028704;cat=utm:app-ctrl;FortinetFortiGatesubtype=app-ctrl;FortinetFortiGateeventtype=signature;FortinetFortiGatelevel=information;FortinetFortiGatevd=root;FortinetFortiGateappid=15511;FortinetFortiGatesrcintfrole=wan;FortinetFortiGatedstintfrole=lan;FortinetFortiGatepolicyid=3;FortinetFortiGateapplist=default;FortinetFortiGateaction=pass;FortinetFortiGateappcat=Remote.Access;FortinetFortiGateapp=RDP;FortinetFortiGateincidentserialno=212209995;FortinetFortiGateapprisk=high",
"ApplicationProtocol": "RDP",
"DeviceExternalID": "FGVM4VTM21000724",
"DeviceInboundInterface": "port1",
"DeviceOutboundInterface": "port2",
"ExternalID": 14430578,
"Type": "CommonSecurityLog",
},
{
"TimeGenerated": "3/31/2022, 08:18:20.276 AM",
"DeviceVendor": "Zscaler",
"DeviceProduct": "NSSWeblog",
"DeviceEventClassID": "Allowed",
"LogSeverity": 3,
"DeviceAction": "Allowed",
"SimplifiedDeviceAction": "Allowed",
"Computer": "zscaler-nss-Contoso",
"CommunicationDirection": 1,
"DestinationIP": "108.167.132.213",
"SourceIP": "192.168.20.44",
"DeviceVersion": 5.7,
"Activity": "Allowed",
"AdditionalExtensions": "reason=Allowed;outcome=200;cat=Internet Services;rulelabel=None;ruletype=None;urlclass=Business Use;devicemodel=Virtual Machine",
"ApplicationProtocol": "HTTP",
"DestinationServiceName": "General Browsing",
"DestinationDnsDomain": "dayvidmarketingdireto.com.br",
"FileType": "None",
"ReceivedBytes": 550,
"SentBytes": 307,
"RequestURL": "http://dayvidmarketingdireto.com.br/shii/office-RD117/",
"SourceUserName": "benjamin@contoso.com"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @Yaniv-Shasha , email must be sanitized@sanitized.com rather than "benjamin@contoso.com", please check and update.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@v-sabiraj same as above

}
]
191 changes: 191 additions & 0 deletions Sample Data/SecurityEvent/RiskIQ_scenrio.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,191 @@
[
{
"TimeGenerated": "3/31/2022, 10:51:35.857 AM",
"Account": "contoso\\benjamin",
"AccountType": "User",
"Computer": "benjamin-pc",
"EventSourceName": "Microsoft-Windows-Security-Auditing",
"Channel": "Security",
"Task": 1,
"Level": 0,
"EventData": "",
"EventID": 4624,
"Activity": "4624 - An account was successfully logged on.",
"SourceComputerId": "4f09bae2-4803-4aa4-8b80-0e2ea66218d2",
"EventOriginId": "4f09bae2-4803-4aa4-8b80-0e2ea66218d3",
"ManagementGroupName": "AOI-8ecf8077-cf51-4820-aadd-14040956f35d",
"AccessList": "",
"AccessMask": "",
"AccessReason": "",
"AuthenticationLevel": "",
"AuthenticationPackageName": "NTLM",
"ElevatedToken": "%%1842",
"ImpersonationLevel": "%%1833",
"IpAddress": "104.168.141.190",
"IpPort": 0,
"KeyLength": 128,
"LmPackageName": "NTLM V2",
"LogonGuid": "00000000-0000-0000-0000-000000000000",
"LogonHours": "",
"LogonID": "",
"LogonProcessName": "NtLmSsp",
"LogonType": 3,
"LogonTypeName": "3 - Network",
"Process": "-",
"ProcessId": "0x0",
"ProcessName": "-",
"SubjectAccount": "-\\-",
"SubjectDomainName": "-",
"SubjectLogonId": "0x0",
"SubjectUserName": "-",
"SubjectUserSid": "S-1-0-0",
"TargetAccount": "contoso\\benjamin",
"TargetDomainName": "contoso",
"TargetInfo": "",
"TargetLinkedLogonId": "0x0",
"TargetLogonGuid": "",
"TargetLogonId": "0xb627c",
"TargetOutboundDomainName": "-",
"TargetOutboundUserName": "-",
"TargetUserName": "benjamin",
"TargetUserSid": "S-1-5-21-2769934187-2433420870-601450644-3108",
"TemplateContent": "",
"TemplateDSObjectFQDN": "",
"TemplateInternalName": "",
"TemplateOID": "",
"TransmittedServices": "-",
"VirtualAccount": "%%1843",
"WorkstationName": "benjamin-pc",
"PartitionKey": ""
},
{
"TimeGenerated": "3/31/2022, 14:51:35.857 PM",
"Account": "contoso\\benjamin",
"AccountType": "User",
"Computer": "benjamin-pc",
"EventSourceName": "Microsoft-Windows-Security-Auditing",
"Channel": "Security",
"Task": 13312,
"Level": 8,
"EventID": 4688,
"Activity": "4688 - A new process has been created.",
"EventOriginId": "69324c1a-22a9-43b9-afde-b582e4ef00d5",
"ManagementGroupName": "AOI-8ecf8077-cf51-4820-aadd-14040956f35d",
"CommandLine": "sekurlsa::pth /user:Administrateur //domain:contoso//ntlm:f193d757b4d487ab7e5a3743f038f713 //run:cmd",
"MandatoryLabel": "S-1-16-8192",
"NewProcessId": "0x14cc",
"NewProcessName": "C:\\tools\\mimikatz_trunk\\x64\\mimikatz.exe",
"ParentProcessName": "C:\\Windows\\System32\\cmd.exe",
"Process": "mimikatz.exe",
"ProcessId": "0x1a50",
"SubjectAccount": "contoso\\benjamin",
"SubjectDomainName": "contoso",
"SubjectLogonId": "0xc4eda",
"SubjectUserName": "benjamin",
"SubjectUserSid": "S-1-5-21-2769934187-2433420870-601450555-3108",
"SubStatus": "",
"TableId": "",
"TargetAccount": "-\\-",
"TargetDomainName": "-",
"TargetLogonId": "0x0",
"TargetUserName": "-",
"TargetUserSid": "S-1-5-21-2769934187-2433420870-601450555-3108",
"TokenElevationType": "%%1938",
"Type": "SecurityEvent"
},
{
"TimeGenerated": "3/31/2022, 10:51:35.857 AM",
"Account": "contoso\\kdickens",
"AccountType": "User",
"Computer": "karla-pc",
"EventSourceName": "Microsoft-Windows-Security-Auditing",
"Channel": "Security",
"Task": 1,
"Level": 0,
"EventData": "",
"EventID": 4624,
"Activity": "4624 - An account was successfully logged on.",
"SourceComputerId": "4f09bae2-4803-4aa4-8b80-0e2ea66218d2",
"EventOriginId": "4f09bae2-4803-4aa4-8b80-0e2ea66218d3",
"ManagementGroupName": "AOI-8ecf8077-cf51-4820-aadd-14040956f35d",
"AccessList": "",
"AccessMask": "",
"AccessReason": "",
"AuthenticationLevel": "",
"AuthenticationPackageName": "NTLM",
"ElevatedToken": "%%1842",
"ImpersonationLevel": "%%1833",
"IpAddress": "213.252.245.73",
"IpPort": 0,
"KeyLength": 128,
"LmPackageName": "NTLM V2",
"LogonGuid": "00000000-0000-0000-0000-000000000000",
"LogonHours": "",
"LogonID": "",
"LogonProcessName": "NtLmSsp",
"LogonType": 3,
"LogonTypeName": "3 - Network",
"Process": "-",
"ProcessId": "0x0",
"ProcessName": "-",
"SubjectAccount": "-\\-",
"SubjectDomainName": "-",
"SubjectLogonId": "0x0",
"SubjectUserName": "-",
"SubjectUserSid": "S-1-0-0",
"TargetAccount": "contoso\\kdickens",
"TargetDomainName": "contoso",
"TargetInfo": "",
"TargetLinkedLogonId": "0x0",
"TargetLogonGuid": "",
"TargetLogonId": "0xb627c",
"TargetOutboundDomainName": "-",
"TargetOutboundUserName": "-",
"TargetUserName": "kdickens",
"TargetUserSid": "S-1-5-21-2769934187-2433420870-601450644-3108",
"TemplateContent": "",
"TemplateDSObjectFQDN": "",
"TemplateInternalName": "",
"TemplateOID": "",
"TransmittedServices": "-",
"VirtualAccount": "%%1843",
"WorkstationName": "karla-pc",
"PartitionKey": ""
},
{
"TimeGenerated": "3/31/2022, 14:51:35.857 PM",
"Account": "contoso\\kdickens",
"AccountType": "User",
"Computer": "karla-pc",
"EventSourceName": "Microsoft-Windows-Security-Auditing",
"Channel": "Security",
"Task": 13312,
"Level": 8,
"EventID": 4688,
"Activity": "4688 - A new process has been created.",
"EventOriginId": "69324c1a-22a9-43b9-afde-b582e4ef00d5",
"ManagementGroupName": "AOI-8ecf8077-cf51-4820-aadd-14040956f35d",
"CommandLine": "nmap -T4 -A -v -oX c:\\users\\kdickens\\appdata\\local\\temp\\zenmap-qvrzjk.xml 192.168.50.22",
"MandatoryLabel": "S-1-16-8192",
"NewProcessId": "0x14cc",
"NewProcessName": "C:\\Program Files (x86)\\Nmap\\nmap.exe",
"ParentProcessName": "C:\\Program Files (x86)\\Nmap\\zenmap.exe",
"Process": "nmap.exe",
"ProcessId": "0x1a50",
"SubjectAccount": "contoso\\kdickens",
"SubjectDomainName": "contoso",
"SubjectLogonId": "0xc4eda",
"SubjectUserName": "kdickens",
"SubjectUserSid": "S-1-5-21-2769934187-2433420870-601450644-3108",
"SubStatus": "",
"TableId": "",
"TargetAccount": "-\\-",
"TargetDomainName": "-",
"TargetLogonId": "0x0",
"TargetUserName": "-",
"TargetUserSid": "S-1-5-21-2769934187-2433420870-601450644-3108",
"TokenElevationType": "%%1938",
"Type": "SecurityEvent"
}
]

Loading