Azure-Sentinel
Azure-Sentinel copied to clipboard
Updating the Analytics Rules and Hunting Queries for Azure Firewall Solution to support Resource Specific logs.
Required items, please complete
Change(s):
- Updated the below Hunting Queries to support Resource Specific Logs: - Azure Firewall - First Time Source IP to Destination Using Port.yml - Azure Firewall - First time source IP to Destination.yml - Azure Firewall - Source IP Abnormally Connects to Multiple Destinations.yml - Azure Firewall - Uncommon Port for Organization.yml - Azure Firewall - Uncommon Port to IP
- Updated the below Analytic Rules to support Resource Specific Logs: - Azure Firewall - Abnormal Deny Rate for Source IP.yml - Azure Firewall - Abnormal Port to Protocol.yml - Azure Firewall - Multiple Sources Affected by the Same TI Destination.yml - Azure Firewall - Port Scan.yml - Azure Firewall - Port Sweep.yml - SeveralDenyActionsRegistered.yml
- Added a new workbook for Azure Firewall Solution to support Resource Specific Logs
Reason for Change(s):
- To support the resource specific logs
Version Updated:
- Yes
Testing Completed:
- Yes
Checked that the validations are passing and have addressed any issues that are present:
- Yes
Hi @shabaz-github, please check the above comments. Thanks
@v-atulyadav Metadata has been added for both the templates. Please help merging this PR. Thank you.
Hi @shabaz-github, please take a look at @devikamehra's comments. Thanks
Hi @devikamehra, please check fixes from @shabaz-github. Thanks
@devikamehra All the comments are addressed. Please help with merging. Thanks