Skip to content

Commit 4b201e5

Browse files
authored
Merge pull request #11628 from Azure/v-rusraut/InfobloxCloud,InfobloxSOC-DCRemove
Repackaged - Infoblox Cloud Data Connector
2 parents e8a87ea + 4072b6e commit 4b201e5

File tree

27 files changed

+186
-1600
lines changed

27 files changed

+186
-1600
lines changed

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-DataExfiltrationAttack.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
11-
- connectorId: InfobloxCloudDataConnectorAma
12-
dataTypes:
13-
- CommonSecurityLog (InfobloxCDC)
148
- connectorId: CefAma
159
dataTypes:
1610
- CommonSecurityLog
@@ -68,5 +62,5 @@ incidentConfiguration:
6862
reopenClosedIncident: true
6963
lookbackDuration: 7d
7064
matchingMethod: AllEntities
71-
version: 1.0.2
65+
version: 1.0.3
7266
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-HighThreatLevelQueryNotBlockedDetected.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
11-
- connectorId: InfobloxCloudDataConnectorAma
12-
dataTypes:
13-
- CommonSecurityLog (InfobloxCDC)
148
- connectorId: CefAma
159
dataTypes:
1610
- CommonSecurityLog
@@ -69,5 +63,5 @@ eventGroupingSettings:
6963
aggregationKind: SingleAlert
7064
incidentConfiguration:
7165
createIncident: true
72-
version: 1.0.3
66+
version: 1.0.4
7367
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-ManyHighThreatLevelQueriesFromSingleHostDetected.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
11-
- connectorId: InfobloxCloudDataConnectorAma
12-
dataTypes:
13-
- CommonSecurityLog (InfobloxCDC)
148
- connectorId: CefAma
159
dataTypes:
1610
- CommonSecurityLog
@@ -53,5 +47,5 @@ eventGroupingSettings:
5347
aggregationKind: SingleAlert
5448
incidentConfiguration:
5549
createIncident: true
56-
version: 1.0.2
50+
version: 1.0.3
5751
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-ManyHighThreatLevelSingleQueryDetected.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
11-
- connectorId: InfobloxCloudDataConnectorAma
12-
dataTypes:
13-
- CommonSecurityLog (InfobloxCDC)
148
- connectorId: CefAma
159
dataTypes:
1610
- CommonSecurityLog
@@ -53,5 +47,5 @@ eventGroupingSettings:
5347
aggregationKind: SingleAlert
5448
incidentConfiguration:
5549
createIncident: true
56-
version: 1.0.3
50+
version: 1.0.4
5751
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-ManyNXDOMAINDNSResponsesDetected.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
11-
- connectorId: InfobloxCloudDataConnectorAma
12-
dataTypes:
13-
- CommonSecurityLog (InfobloxCDC)
148
- connectorId: CefAma
159
dataTypes:
1610
- CommonSecurityLog
@@ -53,5 +47,5 @@ eventGroupingSettings:
5347
aggregationKind: SingleAlert
5448
incidentConfiguration:
5549
createIncident: true
56-
version: 1.0.2
50+
version: 1.0.3
5751
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-TI-CommonSecurityLogMatchFound-MalwareC2.yaml

Lines changed: 1 addition & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -5,18 +5,9 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CEF
9-
dataTypes:
10-
- CommonSecurityLog
118
- connectorId: ThreatIntelligence
129
dataTypes:
1310
- ThreatIntelligenceIndicator
14-
- connectorId: InfobloxCloudDataConnectorAma
15-
dataTypes:
16-
- CommonSecurityLog (InfobloxCDC)
17-
- connectorId: InfobloxCloudDataConnector
18-
dataTypes:
19-
- CommonSecurityLog (InfobloxCDC)
2011
- connectorId: CefAma
2112
dataTypes:
2213
- CommonSecurityLog
@@ -72,5 +63,5 @@ eventGroupingSettings:
7263
aggregationKind: SingleAlert
7364
incidentConfiguration:
7465
createIncident: true
75-
version: 1.0.2
66+
version: 1.0.3
7667
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-TI-InfobloxCDCMatchFound-LookalikeDomains.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,15 +5,9 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: InfobloxCloudDataConnector
9-
dataTypes:
10-
- CommonSecurityLog (InfobloxCDC)
118
- connectorId: ThreatIntelligence
129
dataTypes:
1310
- ThreatIntelligenceIndicator
14-
- connectorId: InfobloxCloudDataConnectorAma
15-
dataTypes:
16-
- CommonSecurityLog (InfobloxCDC)
1711
- connectorId: CefAma
1812
dataTypes:
1913
- CommonSecurityLog
@@ -81,5 +75,5 @@ eventGroupingSettings:
8175
aggregationKind: SingleAlert
8276
incidentConfiguration:
8377
createIncident: true
84-
version: 1.0.3
78+
version: 1.0.4
8579
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Analytic Rules/Infoblox-TI-SyslogMatchFound-URL.yaml

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -11,12 +11,6 @@ requiredDataConnectors:
1111
- connectorId: ThreatIntelligence
1212
dataTypes:
1313
- ThreatIntelligenceIndicator
14-
- connectorId: InfobloxCloudDataConnectorAma
15-
dataTypes:
16-
- CommonSecurityLog (InfobloxCDC)
17-
- connectorId: InfobloxCloudDataConnector
18-
dataTypes:
19-
- CommonSecurityLog (InfobloxCDC)
2014
- connectorId: CefAma
2115
dataTypes:
2216
- CommonSecurityLog
@@ -71,5 +65,5 @@ eventGroupingSettings:
7165
aggregationKind: SingleAlert
7266
incidentConfiguration:
7367
createIncident: true
74-
version: 1.0.2
68+
version: 1.0.3
7569
kind: Scheduled

Solutions/Infoblox Cloud Data Connector/Data/Solution_Infoblox.json

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"Name": "Infoblox Cloud Data Connector",
33
"Author": "Microsoft - [email protected]",
44
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/infoblox_logo.svg\" width=\"75px\" height=\"75px\">",
5-
"Description": "The [Infoblox](https://www.infoblox.com/) Cloud solution allows you to easily connect your Infoblox BloxOne data with Microsoft Sentinel. By connecting your logs to Microsoft Sentinel, you can take advantage of search & correlation, alerting, and threat intelligence enrichment for each log.\n\n This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.\n\n**NOTE:** Microsoft recommends installation of CEF via AMA Connector. The existing connectors are about to be deprecated by **Aug 31, 2024.**",
5+
"Description": "The [Infoblox](https://www.infoblox.com/) Cloud solution allows you to easily connect your Infoblox BloxOne data with Microsoft Sentinel. By connecting your logs to Microsoft Sentinel, you can take advantage of search & correlation, alerting, and threat intelligence enrichment for each log.\n\n This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.\n\n**NOTE:** Microsoft recommends installation of CEF via AMA Connector. The existing connectors were deprecated on **Aug 31, 2024.**",
66
"Workbooks": [
77
"Workbooks/InfobloxCDCB1TDWorkbook.json"
88
],
@@ -16,10 +16,6 @@
1616
"Analytic Rules/Infoblox-TI-InfobloxCDCMatchFound-LookalikeDomains.yaml",
1717
"Analytic Rules/Infoblox-TI-SyslogMatchFound-URL.yaml"
1818
],
19-
"Data Connectors": [
20-
"Data Connectors/InfobloxCloudDataConnector.json",
21-
"Data Connectors/template_InfobloxCloudDataConnectorAMA.json"
22-
],
2319
"Parsers": [
2420
"Parsers/InfobloxCDC.yaml"
2521
],
37.3 KB
Binary file not shown.

0 commit comments

Comments
 (0)