Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Intermittent Entity mapping from Defender Incidents

Open ish-rafaeldamiani opened this issue 10 months ago • 1 comments

Describe the bug Incidents created in Microsoft Defender will not always have their entities mapped in Sentinel. Entities don't appear on the incident analysis screen or via KQL query.

To Reproduce Steps to reproduce the behavior:

  1. Click on the Incidents menu and select an incident originating from Defender
  2. When previewing the incident or clicking View Full Details, entities aren't displayed

Expected behavior The entities (user, ip, host, etc.) will be displayed in all incidents.

Screenshots Prints of incidents without entities and executing the query by clicking on the System Alert ID link

Suspected brute-force attack attempt involving one user query security alert

Email messages containing malicious file removed after delivery involving one user query security alert 2

Additional context As shown in the prints, some incidents originating from Defender are sent via data connector without the entities. Even running a query searching for the title or system alert id, the information is not found.

ish-rafaeldamiani avatar Apr 23 '24 17:04 ish-rafaeldamiani

Hi @ish-rafaeldamiani, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 01 May 2024. Thanks!

v-rusraut avatar Apr 24 '24 11:04 v-rusraut

Hi @ish-rafaeldamiani,

  • Please help us to understand from which source you are getting incident - Sentinel or Defender portal

  • If from sentinel then which Analytical Rule you are using here and also confirm that in Entity mapping section have you added any entity, please refer below screen shot. image

  • If from defender endpoint please check entities are already available in defender portal itself.

Thanks

v-rusraut avatar Apr 29 '24 14:04 v-rusraut

Hi, @v-rusraut

If you look at the first print it has Alert products names: Microsoft Defender for Cloud. This behavior occurs with incidents originating from Defender (for cloud, endpoint, office365).

There is no occurrence with incidents originating from Analytics Rules.

Entities can be located in the Defender portal. But the problem in this case is that some SOC analysts are not allowed access to the Defender portal.

What do I need to know if this behavior of entities is not sent from the Defender portal to Sentinel. Is it normal or possible bug?

ish-rafaeldamiani avatar Apr 29 '24 15:04 ish-rafaeldamiani

Hi @ish-rafaeldamiani, We are working with respective team, we will update you. Thanks

v-rusraut avatar May 10 '24 12:05 v-rusraut

Hi @ish-rafaeldamiani, We are waiting for response from respective team, we will update you. Thanks

v-rusraut avatar May 14 '24 04:05 v-rusraut

Hi @ish-rafaeldamiani, Still waiting for response from respective team, we will update you. Thanks

v-rusraut avatar May 20 '24 10:05 v-rusraut

Hi, @v-rusraut

I still awaiting feedback about this issue.

ish-rafaeldamiani avatar Jun 10 '24 12:06 ish-rafaeldamiani

Hi @ish-rafaeldamiani, We are waiting for response from respective team, if we receive any update, we will update you.

v-rusraut avatar Jun 13 '24 14:06 v-rusraut

Hi @ish-rafaeldamiani, We have received response from receptive team, please use the new Tenant-based Microsoft Defender for Cloud connector, which is in currently PREVIEW state, which allows you to collect Defender for Cloud alerts over your entire tenant, without having to enable each subscription separately. (The connector is highlighted into below screenshot.) image

After using above mentioned connector if you still face any issue, kindly raise support ticket in azure portal, so our concern team will check on this and connect with you if required.

Please let us know once if you raise support ticket case so we can close this issue from GitHub.

Thanks

v-rusraut avatar Jun 28 '24 06:06 v-rusraut

Hi @ish-rafaeldamiani, We are waiting for response from you. Thanks

v-rusraut avatar Jul 01 '24 08:07 v-rusraut

Hi @ish-rafaeldamiani, Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 05-07-2024 date, we will be closing this issue. Thanks!

v-sudkharat avatar Jul 03 '24 08:07 v-sudkharat

Hi @ish-rafaeldamiani, since we have not received a response in the last 5 days, we are closing your issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-sudkharat avatar Jul 05 '24 10:07 v-sudkharat