Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Cyware Solution - Initial Addition

Open AashiqRamachandran opened this issue 1 year ago • 63 comments

Change(s):

  • Initial addition of Cyware Labs connectors

Reason for Change(s):

  • Initial addition

Version Updated:

  • Initial 1.0.0 version

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Need assistance (Can I get additional clarification around packaging the solutions if further packaging is needed?)

Thanks!

AashiqRamachandran avatar Mar 03 '24 04:03 AashiqRamachandran

@microsoft-github-policy-service agree company="Cyware Labs"

AashiqRamachandran avatar Mar 04 '24 10:03 AashiqRamachandran

Hi @AashiqRamachandran,

  1. Playbook file azuredeploy.json has missing metadata, please add, below playbook sample is for your reference. https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Playbooks/ThreatHunting/RecordedFuture-ActorThreatHunt-IndicatorImport/azuredeploy.json
  2. Also Images folder missing in playbook please add working png images into that. Below for your reference https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/ADX-Health-Playbook

v-atulyadav avatar Mar 05 '24 06:03 v-atulyadav

Hi @v-atulyadav,

Many thanks for the prompt review! I've added all the changes requested

  • Removed Metadata in hunting queries
  • Fix tactics and techniques referenced in hunting queries
  • Fix azuredeploy.json with metadata
  • Add images to README.md file for the Sentinel playbooks

Please do let me know any other changes that may be required!

AashiqRamachandran avatar Mar 05 '24 09:03 AashiqRamachandran

Hi @AashiqRamachandran, I have resolved the validations by modifying the files. Please find the attached zip files and follow the guidelines below. Playbook.zip Hunting.zip

  1. Extract Hunting.zip and replace these files into hunting folder
  2. Extract playbook.zip and replace this file into below location. image

v-atulyadav avatar Mar 06 '24 14:03 v-atulyadav

Hi @v-atulyadav ,

Many thanks for the assistance and guidance! As guided, I have updated the files in their respective folder locations!

On a similar line, I also noticed there was a SolutionMetadata.json file included. Is that something we need to add, or is that something that gets added at a later point in time?

Please do let me know the following due process for submitting the Cyware solution to Microsoft Sentinel!

Looking forward to hearing back, Aashiq

AashiqRamachandran avatar Mar 06 '24 15:03 AashiqRamachandran

Hi @AashiqRamachandran,

  1. Please repackage this solution with the help of below mentioned link. https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md
  2. Also check below link to add Release Notes in solution https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ReleaseNotesGuidance.md
  3. Please provide me an access to your branch so I will be able to commit if required.

v-atulyadav avatar Mar 07 '24 05:03 v-atulyadav

Hi @AashiqRamachandran, We are waiting for your updates. Thanks

v-atulyadav avatar Mar 12 '24 05:03 v-atulyadav

Hi @v-atulyadav ,

Yes. We are currently packaging the solution as per the document attached above. We are expecting to push the updated code in the next few hours. Will let you know once pushed

AashiqRamachandran avatar Mar 13 '24 11:03 AashiqRamachandran

Thanks @AashiqRamachandran for confirmation.

v-atulyadav avatar Mar 14 '24 09:03 v-atulyadav

Hi @v-atulyadav,

We have implemented all the required changes, and the content has also been pushed. Please let me know any additional fixes to implement.

Looking forward to hearing back

AashiqRamachandran avatar Mar 18 '24 10:03 AashiqRamachandran

Hi @AashiqRamachandran, Thank you for repackaging this solution, I will review this again. Could you please modify release note version it should be 3.0.0 instead of 1.0.0.

v-atulyadav avatar Mar 18 '24 10:03 v-atulyadav

Hi @AashiqRamachandran,

  1. Logo validations are failing. I have modified the logo. Please extract the below file and replace. cyware-logo.zip

  2. Also modify RelaseNote version to 3.0.0 image

  3. The playbook path is wrongly mentioned, hence the playbook is not visible. image image

Please repackage this solution again once you are done with all the suggested changes.

v-atulyadav avatar Mar 19 '24 06:03 v-atulyadav

Hi @v-atulyadav ,

I've added the fixes. A small doubt on the version tho. This is the first time we are developing a sentinel integration. Will the version still be 3.0.0? (The changes are pushed regardless)

Looking forward to hearing back!

AashiqRamachandran avatar Mar 19 '24 09:03 AashiqRamachandran

Hi @v-atulyadav ,

I've added the fixes. A small doubt on the version tho. This is the first time we are developing a sentinel integration. Will the version still be 3.0.0? (The changes are pushed regardless)

Looking forward to hearing back!

Yes, we are using v3 tool for repackaging hence initial version should be 3.0.0.

v-atulyadav avatar Mar 19 '24 09:03 v-atulyadav

Understood @v-atulyadav.

Please let me know any additional changes

AashiqRamachandran avatar Mar 19 '24 11:03 AashiqRamachandran

Hi @AashiqRamachandran, Also rename data file as Solution_Cyware image Also provide me a contributor access of your branch so I can commit few changes if needed. Thanks

v-atulyadav avatar Mar 19 '24 12:03 v-atulyadav

Hi @v-atulyadav ,

I've renamed the files as recommended. Also checking on adding you as a contributor to our repo to enable you to make edits.

Do let me know if anything else is needed!

AashiqRamachandran avatar Mar 19 '24 14:03 AashiqRamachandran

Hi @v-atulyadav ,

I see that the Pipeline checks have all passed (17/17). Please do let us know of next steps and changes that may be required!

Looking forward to hearing back

AashiqRamachandran avatar Mar 19 '24 15:03 AashiqRamachandran

Hi @AashiqRamachandran, We still need a few changes, as we are unable to view the playbook after deployment. I am working on this issue. Meanwhile, could you please provide me with access so that I can commit a few changes and investigate the issue?. Thanks

v-atulyadav avatar Mar 22 '24 12:03 v-atulyadav

Hi @AashiqRamachandran, A. Please provide me an access for your branch. B. 2 hunting queries have the same GUID, which you need to update for 1 file and repackage. Thanks image

v-atulyadav avatar Mar 27 '24 08:03 v-atulyadav

Hi @AashiqRamachandran, We are waiting for your response on above. Thanks

v-atulyadav avatar Apr 04 '24 09:04 v-atulyadav

Hi @v-atulyadav ,

Sorry for the late reply. Was OOO due to an emergency. Yes. Will add the changes, and let will keep you posted on the repo access ASAP!

AashiqRamachandran avatar Apr 08 '24 09:04 AashiqRamachandran

Hi @AashiqRamachandran, We are waiting for your response on above. Thanks

Hi Atul, I added you as a collaborator on the repo. If you need further access let me know.

ashwinkarkalahegde avatar Apr 09 '24 06:04 ashwinkarkalahegde

Sure @AashiqRamachandran, Thanks.

v-atulyadav avatar Apr 11 '24 14:04 v-atulyadav

Hi @AashiqRamachandran, I am still not able to push anything into your branch. The below screenshot is for your reference. So, I am requesting that please check the above comments and act accordingly. Thanks image

v-atulyadav avatar Apr 16 '24 09:04 v-atulyadav

Hi @v-atulyadav - Looking into this.

@ashwinkarkalahegde FYI

AashiqRamachandran avatar Apr 16 '24 09:04 AashiqRamachandran

Hi @v-atulyadav ,

From investigating the issue, looks like your invite had expired. Resent the invite as well! Please let us know any additional changes required!

Screenshot 2024-04-19 at 12 28 32 PM Screenshot 2024-04-19 at 12 29 37 PM

AashiqRamachandran avatar Apr 19 '24 07:04 AashiqRamachandran

Thanks @AashiqRamachandran.

v-atulyadav avatar Apr 19 '24 07:04 v-atulyadav

Hi @v-atulyadav ,

Please let me know if any other action items are needed!

AashiqRamachandran avatar Apr 29 '24 10:04 AashiqRamachandran

Sure @AashiqRamachandran. Thanks

v-atulyadav avatar May 03 '24 10:05 v-atulyadav