Skip to content

Main change is to the uncommon processes query. - #2

Closed
timbMSFT wants to merge 3 commits into
masterfrom
RareProcessQ-Nov
Closed

Main change is to the uncommon processes query.#2
timbMSFT wants to merge 3 commits into
masterfrom
RareProcessQ-Nov

Conversation

@timbMSFT

Copy link
Copy Markdown
Contributor

Multiple queries update to use split instead of the convoluted reverse() to extract filename.
Copied all queries to Deployed - on the basis that the PR for this in ASI-portal repo has been completed already.

Multiple queries update to use split instead of the convoluted reverse() to extract filename.
Copied all queries to Deployed - on the basis that the PR for this in ASI-portal repo has been completed already.
…ies update to use split instead of the convoluted reverse() to extract filename. Copied all queries to Deployed - on the basis that the PR for this in ASI-portal repo has been completed already."

This reverts commit 63b4b2e.
…I-portal repo.

As well as that query the convoluted reverse() mechanism for extracting Filename is replaced with simpler split() approach.
@juliango2100

Copy link
Copy Markdown
Contributor

There are conflicting changes. These need to be merged.

@timbMSFT

timbMSFT commented Dec 3, 2018

Copy link
Copy Markdown
Contributor Author

abandoning this PR

@timbMSFT timbMSFT closed this Dec 3, 2018
Shain (shainw) pushed a commit that referenced this pull request Jul 31, 2019
Added in filters for block events
Shain (shainw) pushed a commit that referenced this pull request May 14, 2020
@ghost ghost mentioned this pull request Jul 22, 2020
Shain (shainw) pushed a commit that referenced this pull request Oct 27, 2020
Vani Asawa (vaniMSTIC) added a commit to vaniMSTIC/Azure-Sentinel that referenced this pull request Nov 23, 2020
Shain (shainw) pushed a commit that referenced this pull request Dec 14, 2020
Removing special character
v-jayakal pushed a commit that referenced this pull request Jan 21, 2021
Sarah Young (sarah-yo) pushed a commit that referenced this pull request Feb 2, 2021
Pull request from johnbilliris/Azure-Sentinel:master to johnbilliris/Azure-Sentinel:GuardicoreThreatIntelImprovements
@shainw
Shain (shainw) deleted the RareProcessQ-Nov branch March 16, 2021 16:07
v-jayakal pushed a commit that referenced this pull request Mar 30, 2021
v-jayakal pushed a commit that referenced this pull request May 26, 2021
Changed solution rule datatypes to ESETPROTECT
Yaniv Shasha (Yaniv-Shasha) added a commit that referenced this pull request Jun 1, 2021
v-maudan pushed a commit that referenced this pull request Sep 30, 2021
Add data connector for Armorblox solution
v-jayakal pushed a commit that referenced this pull request Nov 9, 2021
v-jayakal pushed a commit that referenced this pull request Dec 21, 2021
v-dvedak added a commit that referenced this pull request Mar 29, 2023
v-atulyadav pushed a commit that referenced this pull request Jun 13, 2023
Update AuthenticationAttemptfromNewCountry.yaml
v-dvedak pushed a commit that referenced this pull request Jul 4, 2023
…ovements

Callmegreg GitHub solution improvements
v-dvedak pushed a commit that referenced this pull request Aug 2, 2023
v-atulyadav pushed a commit that referenced this pull request Mar 12, 2024
…dpointconnector-ccp

Update Sophos Endpoint Data Connector - ccp
v-atulyadav pushed a commit that referenced this pull request Jul 22, 2024
…improvements

Users/vkorenkov/1643469 improvements
v-dvedak pushed a commit that referenced this pull request Aug 21, 2024
v-atulyadav pushed a commit that referenced this pull request Nov 27, 2024
v-atulyadav pushed a commit that referenced this pull request Dec 31, 2024
v-prasadboke (v-prasadboke) pushed a commit that referenced this pull request Mar 6, 2025
v-prasadboke (v-prasadboke) pushed a commit that referenced this pull request Mar 17, 2025
…readme-updates

docs: readme improvements
v-atulyadav pushed a commit that referenced this pull request Jan 15, 2026
Co-authored-by: v-shukore <159111145+v-shukore@users.noreply.github.com>
v-atulyadav pushed a commit that referenced this pull request Jan 15, 2026
v-dvedak pushed a commit that referenced this pull request Jan 22, 2026
Co-authored-by: RamboV <68921481+RamboV@users.noreply.github.com>
v-dvedak pushed a commit that referenced this pull request Jan 22, 2026
Derrick Lee (yummyblabla) added a commit that referenced this pull request Feb 4, 2026
* Redo

* Manual lookover

* Remove nonascii chars

* Remove nonascii characters

---------

Co-authored-by: Derrick Lee <derricklee@microsoft.com>
v-atulyadav pushed a commit that referenced this pull request Feb 23, 2026
v-atulyadav pushed a commit that referenced this pull request Feb 24, 2026
Co-authored-by: gloo-shock <36697840+gloo-shock@users.noreply.github.com>
v-atulyadav pushed a commit that referenced this pull request Feb 24, 2026
v-atulyadav pushed a commit that referenced this pull request Feb 24, 2026
v-atulyadav pushed a commit that referenced this pull request Apr 30, 2026
Syncing my fork with the latest changes from main
Elakkuvan Rajamani (elakkuvan-r) added a commit to elakkuvan-r/Azure-Sentinel that referenced this pull request Jun 4, 2026
…zure#3, Azure#4)

Azure#2 — Renamed Whisper - BGP Anomaly Hunt → Whisper - ASN Reputation Score Hunt
to match the query's actual logic (compares ASN reputation scores across
24-hour windows, flags increases >20 points). Filename kept stable.

Azure#3 — Standardized the playbook parameter naming across all 10 playbooks
from `playbook-name` (kebab) to `PlaybookName` (PascalCase) per the
Azure-Sentinel repo convention. Updated both the parameter declaration
and every `parameters('playbook-name')` reference.

Azure#4 — Moved the Whisper Security custom API connector ARM template into
its own folder per repo convention:
  Solutions/Whisper/Playbooks/WhisperSecurityConnector.json
    → Solutions/Whisper/Playbooks/WhisperSecurityConnector/azuredeploy.json

Package regenerated to 3.0.29 via Create-Azure-Sentinel-Solution V3.

Azure#1 (parse_json on comma-separated strings) — replied on the thread
explaining deferral until we have live data to verify the actual
ingestion-pipeline output format; not changing code in this round.

Signed-off-by: Elakkuvan Rajamani <elakkuvan@whisper.security>
v-atulyadav pushed a commit that referenced this pull request Jul 2, 2026
Fix run-arm-ttk failure for SonraiSecurity mainTemplate
v-atulyadav pushed a commit that referenced this pull request Jul 21, 2026
Applies the same five CI-failure classes that hit PR #14253 to the
Tailscale branch up-front so PR #2 doesn't need a fix-up round:

1. ValidConnectorIds.json allowlist
   Appended TailscaleCCF + TailscalePremiumCCF, CRLF-preserving
   surgical edit so the diff is two new lines.

2. Duration short form
   Converted PT15M -> 15m, PT5H -> 5h, PT1H -> 1h on all 5 analytic
   rules. ScheduledTemplateTimeSpanConverter rejects ISO-8601.

3. CustomTables JSON schemas
   Added Tailscale_Configuration_CL.json + Tailscale_Network_CL.json
   to .script/tests/KqlvalidationsTests/CustomTables/. Required for
   KqlValidationTests to recognise the custom _CL table names in any
   detection / hunting / exploration query referencing them.

4. SVG sanitisation
   Tailscale.svg verified clean (no style= or <style>).

5. ASCII-only YAMLs and source files
   Replaced em-dashes, curly quotes, arrows, NBSP across:
   - Analytic Rules: 4 YAMLs cleaned
   - Hunting Queries: 1 YAML cleaned
   - Solution manifest: 1 file
   - README.md: 1 file
   - Connector definitions: 2 files
   YAML files are now strictly ASCII so NonAsciiValidations passes.

6. Package rebuild
   Bumped to 3.0.2; mainTemplate.json regenerated with the
   description-text changes propagated.

Testing: validated YAML parses (PyYAML), byte-level ASCII scan across
solution directory returns zero hits, surgical edit to
ValidConnectorIds.json produces a 3-line diff with no reformatting.
noodlemctwoodle (noodlemctwoodle) added a commit to noodlemctwoodle/Azure-Sentinel that referenced this pull request Jul 21, 2026
…#14726

Applies fixes for every Copilot inline comment on
Azure#14726, retaining the Logstash
container semantics that are already validated in production.

Logstash pipeline (deployed to prod, verified end-to-end):

- Solutions/UniFi Syslog (CCF)/Logstash/logstash.conf
  - Azure#2/Azure#3: Section 0's ruby PRI decoder now also maps facility/severity
    integer codes to their RFC 5424 name strings (kern/user/mail/... and
    emergency/alert/critical/error/warning/notice/informational/debug).
    Without this, section 6's rename filter (`syslog_facility -> Facility`,
    `syslog_severity -> SyslogSeverity`) was a silent no-op and every
    row landed with null Facility/SyslogSeverity. Consequence in prod:
    `UnifiSyslogCriticalSeverityEvent` never matched an event since the
    solution's initial commit — its `where SyslogSeverity in~ ("critical")`
    predicate could never be true. Confirmed post-fix: 100% of events
    populate both fields.
  - Azure#2/Azure#3 extended: added a CEF-without-syslog-header fallback right
    before section 6's rename. Raw CEF sent by the UDM cloud-key API
    direct to UDP/TCP 514 bypasses the syslog header parse (no <pri>
    prefix), so section 0's ruby decode skips them. New block:
      * if EventFormat == "cef": derive Facility=daemon (network daemon
        origin) + SyslogSeverity from CEF LogSeverity range mapping
        (0-3=informational, 4-5=notice, 6=warning, 7-8=error, 9-10=critical)
      * otherwise: default to "unknown"/"unknown"
    Confirmed post-fix: 0/157 recent fresh events land with a null.
  - Azure#4: replaced always-on `stdout { codec => rubydebug }` with a
    conditional gated on ENABLE_STDOUT_RUBYDEBUG env var (default
    "false"). Logstash env-var interpolation syntax
    `"${ENABLE_STDOUT_RUBYDEBUG:false}" == "true"` means production
    containers never dump per-event debug to `docker logs` unless the
    operator explicitly opts in via .env. Confirmed post-fix: log
    volume dropped from thousands of lines/min to 39 lines / 3min
    (startup only, zero rubydebug event blocks).
  - Azure#12: typo `slient` -> `silent` in a code comment (line 583).

- Solutions/UniFi Syslog (CCF)/Logstash/.env.example
  - Documented the new ENABLE_STDOUT_RUBYDEBUG env var with a warning
    about production log volume.

- Solutions/UniFi Syslog (CCF)/Logstash/docker-compose.yml
  - Azure#9/Azure#10: rewrote for portability. Old file required an external
    `syslog-net` macvlan network + hardcoded `10.0.0.21` IP that would
    fail immediately for anyone else. New default publishes 514/udp +
    514/tcp from the host via `ports:`, which works out of the box on
    any Docker host. The macvlan pattern is documented as a commented
    optional section at the bottom of the file for advanced users who
    need a dedicated LAN IP (e.g. hosts already running rsyslog on 514,
    or UniFi devices that prefer target-discovery on-LAN). Also passes
    ENABLE_STDOUT_RUBYDEBUG through with a `:-false` default so the
    guard evaluates correctly even if the env var is unset.

DCR / mainTemplate:

- Solutions/UniFi Syslog (CCF)/Data Connectors/UnifiSyslog_ccf/UnifiSyslog_DCR.json
  - Azure#5: added isnotempty() guards on the CEF transformKql's SourcePort
    and DestinationPort projections. Before: `SourcePort = toint(SourcePort)`
    which converts an empty string ('') to `0`, meaning downstream
    queries filtering `where SourcePort > 0` silently drop rows that
    genuinely had no source port emitted by CEF (e.g. ICMP flows). After:
    `SourcePort = iff(isnotempty(SourcePort), toint(SourcePort), int(null))`.
    Matches the guard pattern already used elsewhere in the same
    transformKql for DeviceCustomNumber1 / ThreatSeverity /
    MaliciousIPLatitude / MaliciousIPLongitude. Same fix applied to
    DestinationPort.

Analytic rules + hunting queries (11 files):

- Azure#7: added `| where DeviceVendor =~ "Ubiquiti"` scope filter right after
  the `CommonSecurityLog` table reference on every rule/hunt whose query
  starts with CommonSecurityLog. Without this scope, the rules/hunts
  would fire on any TI match / SSH brute force / Tor exit hit / port
  scan / etc. from any Sentinel data source that lands in
  CommonSecurityLog (Fortinet, Cisco, Palo Alto, etc.) — creating
  cross-solution false positives with generic "UniFi:" alert titles.
  Files updated:
    Analytic Rules/UnifiSyslogSshBruteForce.yaml
    Analytic Rules/UnifiSyslogThreatIntelMatch.yaml
    Analytic Rules/UnifiSyslogTorExitTraffic.yaml
    Hunting Queries/UnifiSyslogApplicationPortScanners.yaml
    Hunting Queries/UnifiSyslogDhcpNakDecline.yaml
    Hunting Queries/UnifiSyslogFirstSeenExternalSources.yaml
    Hunting Queries/UnifiSyslogPortScannerSweep.yaml
    Hunting Queries/UnifiSyslogSshTargetUsers.yaml
    Hunting Queries/UnifiSyslogSudoActivityAudit.yaml
    Hunting Queries/UnifiSyslogTiFeedEffectiveness.yaml
    Hunting Queries/UnifiSyslogTopExternalAttackers.yaml
    Hunting Queries/UnifiSyslogWifiDeauthFlood.yaml
  Post-audit: `grep DeviceVendor` confirms all 11 files now have
  `DeviceVendor =~ "Ubiquiti"` filter; audit script exits clean.

- Solutions/UniFi Syslog (CCF)/Hunting Queries/UnifiSyslogDhcpNakDecline.yaml
  - Azure#8: entityMappings block was declaring a Host entity with HostName
    mapped to `SampleClient`, but `SampleClient = take_any(SourceMACAddress)`
    is a MAC address, not a hostname. Sentinel would try to resolve the
    Host entity against something like "aa:bb:cc:dd:ee:ff" — invalid
    entity resolution. Fix: added `SampleHost = take_any(SourceHostName)`
    and `SampleIP = take_any(SourceIP)` to the summarize output; entity
    mappings now declare an IP entity (Address -> SampleIP) and a Host
    entity (HostName -> SampleHost). Real hostnames + real IPs, valid
    Sentinel entity resolution.

Workbook:

- Solutions/UniFi Syslog (CCF)/Workbooks/UnifiSyslog.json
  - Azure#6: the "Rows landing per 5-min bucket" timechart on the Pipeline
    Health tab had TWO `union` clauses of the same `CommonSecurityLog`
    CEF count query. Result: the CEF series was double-counted and the
    timechart under-represented Unifi_Syslog_CL's share of ingestion.
    Removed the trailing `| union (...)` block.

Not changed (Copilot false positive):

- Azure#1: Copilot flagged doubled `||` in ReleaseNotes.md line 3. Confirmed
  by byte inspection — file has clean single `|` pipes throughout. Will
  reply to the comment marking as invalid.

Package regenerated:

- Solutions/UniFi Syslog (CCF)/Package/mainTemplate.json
- Solutions/UniFi Syslog (CCF)/Package/3.0.0.zip
  - Rebuilt via createSolutionV3.ps1. Version reset 3.0.1 -> 3.0.0
    (script always auto-bumps; post-process restores). Byte-parity
    verified: disk mainTemplate.json and inside-zip mainTemplate.json
    both sha256=237b8b91d947c246..., both 249,625 bytes. Explicitly
    prevents the "outside and inside zip file mainTemplates are
    different" finding that hit PR Azure#14253.

Validation:

- KQL validation: PASS (22 files)
- ARM-TTK: PASS 48/48
- Field Types: PASS
- Classic App Insights: PASS
- Hyperlink Validation: PASS
- (Skipped: .NET Core 3.1 detection-schema + non-ASCII + TruffleHog —
  local tooling not installed, upstream CI covers these.)

End-to-end prod verification (Logstash relay on 10.0.10.2):

- Container: healthy (Up 37 seconds after last rebuild)
- Pipeline: in=3 filtered=3 out=3 (clean 1:1 processing)
- Docker log volume: 39 lines / 3min (was thousands/min pre-Azure#4-fix)
- Facility/SyslogSeverity population: 157/157 fresh events (0 nulls)

Breaking changes: none.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants