Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Added new Playbooks, Fixed issue in VmRecovery playbook and updated version of cryptography to fix vulnerability in python packages

Open niralishah-crest opened this issue 1 year ago • 33 comments

Change(s):

  • Added 3 new Playbooks(RubrikFileObjectContextAnalysis, RubrikUserAccessAnalysis, RubrikUserRiskPolicyDetails) for FileObject and User
  • Fixed clusterLocation issue of Collect_IOC_Scan_Data adaptive card in RubrikRansomwareDiscoveryAndVmRecovery playbook
  • Updated Anomaly Analysis playboook and added new playbook(RubrikAnomalyGenerateDownloadableLink) to enrich anomaly incident with Suspicious filePath(s) details and it's downloadable link.

Reason for Change(s):

  • New Feature requirement of new playbooks
  • Fix Issue in popuating adaptive card

Version Updated:

  • Updated to 3.2.0

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

niralishah-crest avatar Feb 26 '24 07:02 niralishah-crest

Hello @niralishah-crest, Please try to resolve arm ttk failures.

v-prasadboke avatar Feb 28 '24 12:02 v-prasadboke

Hi @niralishah-crest, Any updates on above

v-prasadboke avatar Mar 01 '24 06:03 v-prasadboke

@v-prasadboke We are working on it. Will update the PR as soon as possible.

niralishah-crest avatar Mar 01 '24 09:03 niralishah-crest

Thanks for resolving the validation failure. continuing to investigate the PR

v-prasadboke avatar Mar 05 '24 12:03 v-prasadboke

Thanks for resolving the validation failure. continuing to investigate the PR

Sorry for the misunderstanding @niralishah-crest, There are still arm-ttk failures. Please try to resolve them

v-prasadboke avatar Mar 07 '24 09:03 v-prasadboke

@v-prasadboke We have tried from our side to fix the arm-ttk validation error. But we are unable to find the cause of it. Can you please help us out on that?

niralishah-crest avatar Mar 07 '24 10:03 niralishah-crest

Hello @niralishah-crest, I'll try from my side. I'll get back to you by 14 March, 2024

v-prasadboke avatar Mar 11 '24 12:03 v-prasadboke

Hello @niralishah-crest, Unable to pull latest changes. Can you provide write access to the branch.

v-prasadboke avatar Mar 12 '24 10:03 v-prasadboke

Hello @niralishah-crest, Unable to pull latest changes. Can you provide write access to the branch.

@v-prasadboke I have already added you as a collaborator to my forked repository.

niralishah-crest avatar Mar 12 '24 17:03 niralishah-crest

Hello @niralishah-crest, I'll take a look at it.

v-prasadboke avatar Mar 18 '24 09:03 v-prasadboke

Hello @niralishah-crest, We are still trying to figure out the issue. Will get back to you by 28 March, 2024.

v-prasadboke avatar Mar 21 '24 10:03 v-prasadboke

Hello @niralishah-crest, Im unable to pull latest changes can you please update your branch from master.

v-prasadboke avatar Mar 27 '24 08:03 v-prasadboke

Hello @niralishah-crest, Im unable to pull latest changes can you please update your branch from master.

@v-prasadboke Merged master branch in this branch

niralishah-crest avatar Mar 27 '24 10:03 niralishah-crest

Hello @niralishah-crest, We are still trying to figure out the issue. Will get back to you by 28 March, 2024.

@v-prasadboke Any updates on the PR?

niralishah-crest avatar Apr 01 '24 06:04 niralishah-crest

Hi @niralishah-crest, Sorry for the inconvenience. We are trying to find the cause for ARM ttk failure. Will get back to you as soon as we have some updates

v-prasadboke avatar Apr 01 '24 06:04 v-prasadboke

Hello @niralishah-crest, We are trying to find the cause but havent found anything yet. Taking this matter to team.

Will get back to you as soon as I have an update on this. Thanks and sorry for the delay.

v-prasadboke avatar Apr 01 '24 11:04 v-prasadboke

Hello @niralishah-crest, We are trying to find the cause but havent found anything yet. Taking this matter to team.

Will get back to you as soon as I have an update on this. Thanks and sorry for the delay.

@v-prasadboke Any updates on this?

niralishah-crest avatar Apr 10 '24 05:04 niralishah-crest

Hello @niralishah-crest, Sorry for the inconvenience we are still working on the issue.

v-prasadboke avatar Apr 11 '24 06:04 v-prasadboke

I see still arm ttk is failing

I'll check it out

v-prasadboke avatar Apr 23 '24 12:04 v-prasadboke

can you update the branch from master once again

I'm unable to pull changes to my local

v-prasadboke avatar Apr 24 '24 09:04 v-prasadboke

can you update the branch from master once again

I'm unable to pull changes to my local

Done

niralishah-crest avatar Apr 24 '24 09:04 niralishah-crest

@v-prasadboke Any updates for this?

niralishah-crest avatar May 06 '24 09:05 niralishah-crest

Hello @niralishah-crest, Sorry for the delay in this issue. We are still working on this issue to get resolve.

Will update as soon as possible on this

v-prasadboke avatar May 08 '24 10:05 v-prasadboke