Skip to content

Commit 03fc30d

Browse files
authored
Merge pull request Azure#12760 from Samsung/master
Samsung Knox Asset Intelligence -Update DCR & remove one analytics rule
2 parents a7e36a0 + 023c719 commit 03fc30d

File tree

6 files changed

+131
-289
lines changed

6 files changed

+131
-289
lines changed

Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxKeyguardDisabledFeatureSet.yaml

Lines changed: 0 additions & 30 deletions
This file was deleted.

Solutions/Samsung Knox Asset Intelligence/Data Connectors/azuredeploy_SamsungDataConnectorDefinition.json

Lines changed: 5 additions & 5 deletions
Large diffs are not rendered by default.

Solutions/Samsung Knox Asset Intelligence/Data/Solution_Samsung.json

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,6 @@
1111
"AnalyticalRuleBladeDescription": "This solution comes with the following analytic rule templates, based on critical mobile security event data captured from Samsung Knox devices. You can also customize these analytic rule templates based on your organization’s needs.",
1212
"Analytic Rules": [
1313
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxApplicationPrivilegeEscalationOrChange.yaml",
14-
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxKeyguardDisabledFeatureSet.yaml",
1514
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxMobileDeviceBootCompromise.yaml",
1615
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxPasswordLockout.yaml",
1716
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxPeripheralAccessDetectionWithCamera.yaml",
@@ -20,7 +19,7 @@
2019
"Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxSecurityLogFull.yaml"
2120
],
2221
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Samsung Knox Asset Intelligence",
23-
"Version": "3.0.1",
22+
"Version": "3.0.3",
2423
"Metadata": "SolutionMetadata.json",
2524
"TemplateSpec": true,
2625
"Is1PConnector": false
13.4 KB
Binary file not shown.

Solutions/Samsung Knox Asset Intelligence/Package/createUiDefinition.json

Lines changed: 12 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"config": {
77
"isWizard": false,
88
"basics": {
9-
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Samsung_Knox_Asset_Intelligence.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Samsung%20Knox%20Asset%20Intelligence/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Knox Asset Intelligence for Microsoft Sentinel solution enables enterprise IT and SecOps (Security Operations) administrators to view and manage security threats to their Samsung Knox mobile devices. By integrating security events and logs from Knox Asset Intelligence with the Azure Monitor Log Ingestion API, the solution lets enterprise organizations easily view, identify and investigate security threats in near-real-time with Microsoft Sentinel.\n\n**Data Connectors:** 1, **Workbooks:** 1, **Analytic Rules:** 8\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
9+
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Samsung_Knox_Asset_Intelligence.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Samsung%20Knox%20Asset%20Intelligence/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Knox Asset Intelligence for Microsoft Sentinel solution enables enterprise IT and SecOps (Security Operations) administrators to view and manage security threats to their Samsung Knox mobile devices. By integrating security events and logs from Knox Asset Intelligence with the Azure Monitor Log Ingestion API, the solution lets enterprise organizations easily view, identify and investigate security threats in near-real-time with Microsoft Sentinel.\n\n**Data Connectors:** 1, **Workbooks:** 1, **Analytic Rules:** 7\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
1010
"subscription": {
1111
"resourceProviders": [
1212
"Microsoft.OperationsManagement/solutions",
@@ -160,24 +160,10 @@
160160
{
161161
"name": "analytic2",
162162
"type": "Microsoft.Common.Section",
163-
"label": "Samsung Knox - Keyguard Disabled Feature Set Events",
164-
"elements": [
165-
{
166-
"name": "analytic2-text",
167-
"type": "Microsoft.Common.TextBlock",
168-
"options": {
169-
"text": "When an admin has set disabled keyguard features on a Knox device."
170-
}
171-
}
172-
]
173-
},
174-
{
175-
"name": "analytic3",
176-
"type": "Microsoft.Common.Section",
177163
"label": "Samsung Knox - Mobile Device Boot Compromise Events",
178164
"elements": [
179165
{
180-
"name": "analytic3-text",
166+
"name": "analytic2-text",
181167
"type": "Microsoft.Common.TextBlock",
182168
"options": {
183169
"text": "When a Knox device boot binary is at risk of compromise."
@@ -186,12 +172,12 @@
186172
]
187173
},
188174
{
189-
"name": "analytic4",
175+
"name": "analytic3",
190176
"type": "Microsoft.Common.Section",
191177
"label": "Samsung Knox - Password Lockout Events",
192178
"elements": [
193179
{
194-
"name": "analytic4-text",
180+
"name": "analytic3-text",
195181
"type": "Microsoft.Common.TextBlock",
196182
"options": {
197183
"text": "When maximum password attempts have been reached, and the Knox device is locked out. This is based on a threshold set in the MDM device policy"
@@ -200,12 +186,12 @@
200186
]
201187
},
202188
{
203-
"name": "analytic5",
189+
"name": "analytic4",
204190
"type": "Microsoft.Common.Section",
205191
"label": "Samsung Knox - Peripheral Access Detection with Camera Events",
206192
"elements": [
207193
{
208-
"name": "analytic5-text",
194+
"name": "analytic4-text",
209195
"type": "Microsoft.Common.TextBlock",
210196
"options": {
211197
"text": "When camera access has been detected on a Knox device, even though such access is disabled through an MDM device policy."
@@ -214,12 +200,12 @@
214200
]
215201
},
216202
{
217-
"name": "analytic6",
203+
"name": "analytic5",
218204
"type": "Microsoft.Common.Section",
219205
"label": "Samsung Knox - Peripheral Access Detection with Mic Events",
220206
"elements": [
221207
{
222-
"name": "analytic6-text",
208+
"name": "analytic5-text",
223209
"type": "Microsoft.Common.TextBlock",
224210
"options": {
225211
"text": "When microphone access has been detected on a Knox device, even though such access is disabled through an MDM device policy."
@@ -228,12 +214,12 @@
228214
]
229215
},
230216
{
231-
"name": "analytic7",
217+
"name": "analytic6",
232218
"type": "Microsoft.Common.Section",
233219
"label": "Samsung Knox - Suspicious URL Accessed Events",
234220
"elements": [
235221
{
236-
"name": "analytic7-text",
222+
"name": "analytic6-text",
237223
"type": "Microsoft.Common.TextBlock",
238224
"options": {
239225
"text": "When a Knox device user clicks on URLs or links detected as suspicious (potentially phishing or malicious) with a high degree of confidence."
@@ -242,12 +228,12 @@
242228
]
243229
},
244230
{
245-
"name": "analytic8",
231+
"name": "analytic7",
246232
"type": "Microsoft.Common.Section",
247233
"label": "Samsung Knox - Security Log Full Events",
248234
"elements": [
249235
{
250-
"name": "analytic8-text",
236+
"name": "analytic7-text",
251237
"type": "Microsoft.Common.TextBlock",
252238
"options": {
253239
"text": "When the Knox Security Log is full on a device."

0 commit comments

Comments
 (0)