-
Notifications
You must be signed in to change notification settings - Fork 603
Add rules for Azure Activity Logs/GCP Audit ML jobs #5191
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Rule: New - GuidelinesThese guidelines serve as a reminder set of considerations when proposing a new rule. Documentation and Context
Rule Metadata Checks
New BBR Rules
Testing and Validation
|
Hi @shashank-elastic 👋 I have a question on these, should we adapt the triage guide from the CloudWatch jobs (which these are very similar to), or can you generate new ones with your team's AI process? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@Mikaayenson question:
For AWS jobs - outside this PR, but we are using them as reference as they are cloud jobs - I noticed that the ML jobs example do not have [rule.treat.technique]
mapped but a few others do. - example
Is that something we should be adding in this PR?
interval = "15m" | ||
license = "Elastic License v2" | ||
machine_learning_job_id = "azure_activitylogs_rare_event_action_for_a_city" | ||
name = "Unusual City for an Azure Activity Logs Event" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should definitely have these for Entra ID Sign-In Logs. Happy to talk and discuss more!
@jmcarlock We can generate the investigation guides using our AI tool. 2 Things for the PR
|
Thanks @terrancedejesus and @shashank-elastic for the review!
@shashank-elastic I am fine making this change, but to be consistent then the AWS CloudTrail jobs (which these are most similar to) should also move, as they are under |
One other question here, the jobs themselves are present in the main branch, which serverless releases weekly. I'm not sure if we will request this, but is there a way to release them earlier for serverless? |
|
Thanks @shashank-elastic, I just have a couple more questions. First can you correct the date? Also, if we merge these rules in your next release, would they get picked up on Serverless if we keep the |
Oh @jmcarlock Apologies, we have the release prep and release in week of Oct 20. I see the next steps as follows.
|
Pull Request
Issue link(s):
Summary - What I changed
Add detection rules for the new Azure Activity Logs/GCP Audit logs jobs.
These jobs will be released with 9.3.0.
How To Test
Checklist
bug
,enhancement
,schema
,maintenance
,Rule: New
,Rule: Deprecation
,Rule: Tuning
,Hunt: New
, orHunt: Tuning
so guidelines can be generatedmeta:rapid-merge
label if planning to merge within 24 hoursContributor checklist