Skip to content

Commit de6ebc5

Browse files
authored
Merge branch 'Azure:master' into Keshavm021/Netskopewebtx
2 parents 76ffbd3 + 02e9afb commit de6ebc5

File tree

89 files changed

+5159
-2049
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

89 files changed

+5159
-2049
lines changed

ASIM/dev/ASimTester/ASimTester.csv

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -727,7 +727,7 @@ EventProduct,string,Mandatory,FileEvent,Enumerated,Security Events|Sysmon for Li
727727
EventProduct,string,Mandatory,NetworkSession,Enumerated,Fortigate|IOS|ISE|SDP|Vectra Stream|NSGFlow|Fireware|VPC|Azure Defender for IoT|Azure Firewall|M365 Defender for Endpoint|Sysmon|Sysmon for Linux|Windows Firewall|WireData|ZIA Firewall|CDL|PanOS|VMConnection|Meraki|Zeek|Firewall|ASA|Cynerio|SentinelOne|WAF|Firepower|FalconHost|Carbon Black Cloud|Cortex Data Lake|Core|Azure NSG flows,
728728
EventProduct,string,Mandatory,ProcessEvent,Enumerated,M365 Defender for Endpoint|Sysmon for Linux|Sysmon|Azure Defender for IoT|Security Events|SentinelOne|Carbon Black Cloud|Vision One,
729729
EventProduct,string,Mandatory,RegistryEvent,Enumerated,M365 Defender for Endpoint|Security Events|Sysmon|Windows Event|SentinelOne|Carbon Black Cloud|Vision One,
730-
EventProduct,string,Mandatory,UserManagement,Enumerated,Security Events|Authpriv|ISE|SentinelOne,
730+
EventProduct,string,Mandatory,UserManagement,Enumerated,Security Events|Authpriv|ISE|SentinelOne|CloudTrail,
731731
EventProduct,string,Mandatory,WebSession,Enumerated,IIS|Squid Proxy|ZIA Proxy|Vectra Stream|PanOS|CDL|Fireware|Meraki|Web Security Gateway|Zeek|Dataminr Pulse|HTTP Server|Fortigate|WAF|ASM|NetScaler|Firepower|Cortex Data Lake|Firewall|Azure Firewall,
732732
EventProductVersion,string,Optional,AlertEvent,,,
733733
EventProductVersion,string,Optional,AuditEvent,,,
@@ -825,7 +825,7 @@ EventStartTime,datetime,Mandatory,RegistryEvent,,,
825825
EventStartTime,datetime,Mandatory,UserManagement,,,
826826
EventStartTime,datetime,Mandatory,WebSession,,,
827827
EventSubType,string,Optional,AuditEvent,,,
828-
EventSubType,string,Optional,Authentication,Enumerated,System|Interactive|RemoteInteractive|Service|RemoteService|Remote|AssumeRole,
828+
EventSubType,string,Optional,Authentication,Enumerated,System|Interactive|RemoteInteractive|Service|RemoteService|Remote|AssumeRole|NetworkCleartext,
829829
EventSubType,string,Optional,Common,Enumerated,Placeholder,
830830
EventSubType,string,Optional,DhcpEvent,,,
831831
EventSubType,string,Optional,Dns,Enumerated,request|response,
@@ -870,7 +870,7 @@ EventVendor,string,Mandatory,FileEvent,Enumerated,Microsoft|SentinelOne|VMware|G
870870
EventVendor,string,Mandatory,NetworkSession,Enumerated,Fortinet|AppGate|Barracuda|Palo Alto|Microsoft|Zscaler|AWS|Vectra AI|WatchGuard|Cisco|Corelight|Check Point|Forcepoint|Cynerio|SentinelOne|CrowdStrike|VMware|SonicWall|Illumio,
871871
EventVendor,string,Mandatory,ProcessEvent,Enumerated,Microsoft|SentinelOne|VMware|TrendMicro,
872872
EventVendor,string,Mandatory,RegistryEvent,Enumerated,Microsoft|SentinelOne|VMware|Trend Micro,
873-
EventVendor,string,Mandatory,UserManagement,Enumerated,Microsoft|Linux|Cisco|SentinelOne,
873+
EventVendor,string,Mandatory,UserManagement,Enumerated,Microsoft|Linux|Cisco|SentinelOne|AWS,
874874
EventVendor,string,Mandatory,WebSession,Enumerated,Apache|Barracuda|Fortinet|Microsoft|Squid|Zscaler|Vectra AI|Palo Alto|WatchGuard|Cisco|Forcepoint|Corelight|Dataminr|Citrix|F5|SonicWall,
875875
FileContentType,string,Optional,WebSession,,,
876876
FileMD5,string,Optional,AlertEvent,,,
@@ -888,7 +888,7 @@ FileSHA512,string,Optional,WebSession,SHA512,,
888888
FileSize,long,Optional,AlertEvent,,,
889889
FileSize,long,Optional,WebSession,,,
890890
GroupId,string,Optional,UserManagement,,,
891-
GroupIdType,string,Optional,UserManagement,Enumerated,SID|UID,
891+
GroupIdType,string,Optional,UserManagement,Enumerated,SID|UID|Simple,
892892
GroupName,string,Optional,UserManagement,,,
893893
GroupNameType,string,Optional,UserManagement,Enumerated,UPN|Windows|DN|Simple,
894894
GroupOriginalType,string,Optional,UserManagement,,,
@@ -1460,7 +1460,7 @@ TargetUserId,string,Optional,UserManagement,,,
14601460
TargetUserId,string,Recommended,ProcessEvent,,,
14611461
TargetUserIdType,string,Conditional,Authentication,Enumerated,SID|UID|AADID|OktaId|AWSId|PUID|SalesforceId|VectraUserId|MD4IoTid|GWorkspaceProfileID|Other,TargetUserId
14621462
TargetUserIdType,string,Conditional,ProcessEvent,Enumerated,SID|UID|AADID|OktaId|AWSId|PUID|SalesforceId|VectraUserId|MD4IoTid|Other,TargetUserId
1463-
TargetUserIdType,string,Conditional,UserManagement,Enumerated,SID|UID|AADID|OktaId|AWSId|PUID|SalesforceId|VectraUserId|MD4IoTid|Other,TargetUserId
1463+
TargetUserIdType,string,Conditional,UserManagement,Enumerated,SID|UID|AADID|OktaId|AWSId|PUID|SalesforceId|VectraUserId|MD4IoTid|AWSIAMUserId|AWSIAMRoleId|Other,TargetUserId
14641464
TargetUsername,string,Mandatory,ProcessEvent,,,
14651465
TargetUsername,string,Optional,Authentication,,,
14661466
TargetUsername,string,Optional,UserManagement,,,

CODEOWNERS

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
# This is copied from here: https://help.github.com/en/github/creating-cloning-and-archiving-repositories/about-code-owners
1111

1212
/.script/ @Azure/sentinel-repo-admins @Azure/sentinel-repo-reviewers
13+
/ASIM/ @Azure/sentinel-repo-admins @Azure/sentinel-repo-reviewers @Azure/sentinel-repo-parser-reviewers
1314
/DataConnectors/ @Azure/sentinel-repo-connectors-reviewers @Azure/sentinel-repo-admins @Azure/sentinel-repo-reviewers
1415
/Detections/ @Azure/sentinel-repo-hunt-detection-reviewers @Azure/sentinel-repo-admins @Azure/sentinel-repo-reviewers
1516
/Hunting\ Queries/ @Azure/sentinel-repo-hunt-detection-reviewers @Azure/sentinel-repo-admins @Azure/sentinel-repo-reviewers

Parsers/ASimProcessEvent/Parsers/ASimProcessTerminateVMwareCarbonBlackCloud.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ References:
1919
Description: |
2020
This ASIM parser supports normalizing VMware Carbon Black Cloud logs to the ASIM Process Terminate normalized schema. VMware Carbon Black Cloud events are captured through VMware Carbon Black Cloud data connector which ingests Carbon Black Audit, Notification and Event data into Microsoft Sentinel through the REST API.
2121
ParserName: ASimProcessTerminateVMwareCarbonBlackCloud
22-
EquivalentBuiltInParser: ASim_ProcessEvent_TerminateVMwareCarbonBlackCloud
22+
EquivalentBuiltInParser: _ASim_ProcessEvent_TerminateVMwareCarbonBlackCloud
2323
ParserParams:
2424
- Name: disabled
2525
Type: bool

Parsers/ASimProcessEvent/Parsers/vimProcessTerminateVMwareCarbonBlackCloud.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ References:
1919
Description: |
2020
This ASIM parser supports normalizing VMware Carbon Black Cloud logs to the ASIM Process Terminate normalized schema. VMware Carbon Black Cloud events are captured through VMware Carbon Black Cloud data connector which ingests Carbon Black Audit, Notification and Event data into Microsoft Sentinel through the REST API.
2121
ParserName: vimProcessTerminateVMwareCarbonBlackCloud
22-
EquivalentBuiltInParser: Im_ProcessTerminate_VMwareCarbonBlackCloud
22+
EquivalentBuiltInParser: _Im_ProcessTerminate_VMwareCarbonBlackCloud
2323
ParserParams:
2424
- Name: starttime
2525
Type: datetime

Parsers/ASimUserManagement/ARM/ASimUserManagement/ASimUserManagement.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@
2727
"displayName": "User Management ASIM parser",
2828
"category": "ASIM",
2929
"FunctionAlias": "ASimUserManagement",
30-
"query": "let DisabledParsers=materialize(_GetWatchlist('ASimDisabledParsers')\n | where SearchKey in ('Any', 'ExcludeASimUserManagement')\n | extend SourceSpecificParser=column_ifexists('SourceSpecificParser', '')\n | distinct SourceSpecificParser);\nlet ASimBuiltInDisabled=toscalar('ExcludeASimUserManagement' in (DisabledParsers) or 'Any' in (DisabledParsers)); \nlet parser=(\n pack: bool=false\n ) {\n union isfuzzy=true\n vimUserManagementEmpty,\n ASimUserManagementMicrosoftSecurityEvent (ASimBuiltInDisabled or ('ExcludeASimUserManagementMicrosoftSecurityEvent' in (DisabledParsers))),\n ASimUserManagementMicrosoftWindowsEvent (ASimBuiltInDisabled or ('ExcludeASimUserManagementMicrosoftWindowsEvent' in (DisabledParsers))),\n ASimUserManagementCiscoISE (ASimBuiltInDisabled or ('ExcludeASimUserManagementCiscoISE' in (DisabledParsers))),\n ASimUserManagementSentinelOne (ASimBuiltInDisabled or ('ExcludeASimUserManagementSentinelOne' in (DisabledParsers))),\n ASimUserManagementLinuxAuthpriv (ASimBuiltInDisabled or ('ExcludeASimUserManagementLinuxAuthpriv' in (DisabledParsers))),\n ASimUserManagementNative (ASimBuiltInDisabled or ('ExcludeASimUserManagementNative' in (DisabledParsers)))\n}; \nparser (\n pack=pack\n)",
30+
"query": "let DisabledParsers=materialize(_GetWatchlist('ASimDisabledParsers')\n | where SearchKey in ('Any', 'ExcludeASimUserManagement')\n | extend SourceSpecificParser=column_ifexists('SourceSpecificParser', '')\n | distinct SourceSpecificParser);\nlet ASimBuiltInDisabled=toscalar('ExcludeASimUserManagement' in (DisabledParsers) or 'Any' in (DisabledParsers)); \nlet parser=(\n pack: bool=false\n ) {\n union isfuzzy=true\n vimUserManagementEmpty,\n ASimUserManagementMicrosoftSecurityEvent (ASimBuiltInDisabled or ('ExcludeASimUserManagementMicrosoftSecurityEvent' in (DisabledParsers))),\n ASimUserManagementMicrosoftWindowsEvent (ASimBuiltInDisabled or ('ExcludeASimUserManagementMicrosoftWindowsEvent' in (DisabledParsers))),\n ASimUserManagementCiscoISE (ASimBuiltInDisabled or ('ExcludeASimUserManagementCiscoISE' in (DisabledParsers))),\n ASimUserManagementSentinelOne (ASimBuiltInDisabled or ('ExcludeASimUserManagementSentinelOne' in (DisabledParsers))),\n ASimUserManagementLinuxAuthpriv (ASimBuiltInDisabled or ('ExcludeASimUserManagementLinuxAuthpriv' in (DisabledParsers))),\n ASimUserManagementNative (ASimBuiltInDisabled or ('ExcludeASimUserManagementNative' in (DisabledParsers))),\n ASimUserManagementAWSCloudTrail (ASimBuiltInDisabled or ('ExcludeASimUserManagementAWSCloudTrail' in (DisabledParsers)), pack=pack)\n}; \nparser (\n pack=pack\n)",
3131
"version": 1,
3232
"functionParameters": "pack:bool=False"
3333
}

0 commit comments

Comments
 (0)