Skip to content

Isolate-AzVM - Automated VM isolation with snapshots in support of digital forensics incident response (DFIR)#11919

Merged
v-atulyadav merged 4 commits intoAzure:masterfrom
R4NG51:AS-Isolate-AzVM
Mar 25, 2025
Merged

Isolate-AzVM - Automated VM isolation with snapshots in support of digital forensics incident response (DFIR)#11919
v-atulyadav merged 4 commits intoAzure:masterfrom
R4NG51:AS-Isolate-AzVM

Conversation

@R4NG51
Copy link
Contributor

@R4NG51 R4NG51 commented Mar 16, 2025

Isolate-AzVM - Automated VM isolation with snapshots in support of digital forensics incident response (DFIR)

The playbook isolates Azure VM(s) and snapshot the VM(s) to a DFIR environment. Two PS scripts are included for RBAC configuration and converting the snapshots to VHDs for forensic analysis.

Tested on multiple Azure fabrics and Microsoft Sentinel in support of Contoso's reference architecture.

@microsoft-github-policy-service agree company="Microsoft"

@R4NG51 R4NG51 requested review from a team as code owners March 16, 2025 23:21
@R4NG51
Copy link
Contributor Author

R4NG51 commented Mar 17, 2025 via email

@v-prasadboke
Copy link
Contributor

Hello @R4NG51, I noticed you mentioned "Solution" in the PR name, but you added this playbook in the Standalone folder. If you want this playbook to be part of a Solution, please refer one of the Solutions from this folder: https://github.com/Azure/Azure-Sentinel/tree/master/Solutions.

Additionally, a data file and solution metadata are required to package the Solution. The Solution folder should contain a playbook, data/input file, and solution metadata, which will generate the main template and create UI after packaging.

@v-atulyadav v-atulyadav added the Playbook Playbook specialty review needed label Mar 17, 2025
@R4NG51 R4NG51 changed the title Digital Forensics Incident Response (DFIR) solution Isolate-AzVM - Automated VM isolation with snapshots in support of digital forensics incident response (DFIR) Mar 17, 2025
@v-prasadboke
Copy link
Contributor

Hello @R4NG51,
The Playbook is missing with some required metadata.
postdeployment steps and prerequisites and all. You can refer this playbook for more clarification.
https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Playbooks/Enrichment/RecordedFuture-IOC_Enrichment/azuredeploy.json

If this fields are missing from playbook metadata, playbook wont be visible in the automation blade

@R4NG51
Copy link
Contributor Author

R4NG51 commented Mar 22, 2025 via email

@v-atulyadav v-atulyadav merged commit cf837de into Azure:master Mar 25, 2025
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Playbook Playbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants