Skip to content

Commit 69e8e7f

Browse files
nitsiNitsan Bracha
andauthored
New API version to Microsoft.Security 2021-11-01 (#18045)
* Adds base for updating Microsoft.Security from version stable/2021-01-01 to version 2021-11-01 * Updates readme * Updates API version in new specs and examples * New API version to Microsoft.Security pick 5459ef18a7 New API version to Microsoft.Security pick c8462f9c60 [Microsoft.Security alerts] fix examples/Alerts/SimulateAlerts_example.json pick b5f4550d6b [Microsoft.Security alerts] add missing API to readme.md * [Microsoft.Security alerts] fix examples/Alerts/SimulateAlerts_example.json * [Microsoft.Security alerts] add missing API to readme.md * Fix readme.md file after rebase * Removing "x-ms-long-running-operation" header * Setting target package back to package-composite-v3 * Updating securityContacts.json to the latest version * Reverting securityContacts.json to equal main, should be updated by the relevant team Co-authored-by: Nitsan Bracha <[email protected]>
1 parent 2fbe567 commit 69e8e7f

13 files changed

+1909
-3
lines changed

specification/security/resource-manager/Microsoft.Security/stable/2021-11-01/alerts.json

Lines changed: 1116 additions & 0 deletions
Large diffs are not rendered by default.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,79 @@
1+
{
2+
"parameters": {
3+
"api-version": "2021-11-01",
4+
"subscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
5+
"resourceGroupName": "myRg1",
6+
"ascLocation": "westeurope",
7+
"alertName": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a"
8+
},
9+
"responses": {
10+
"200": {
11+
"body": {
12+
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Security/locations/westeurope/alerts/2518770965529163669_F144EE95-A3E5-42DA-A279-967D115809AA",
13+
"name": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
14+
"type": "Microsoft.Security/Locations/alerts",
15+
"properties": {
16+
"alertType": "VM_EICAR",
17+
"systemAlertId": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
18+
"productComponentName": "",
19+
"alertDisplayName": "Azure Security Center test alert (not a threat)",
20+
"description": "This is a test alert generated by Azure Security Center. No further action is needed.",
21+
"severity": "High",
22+
"intent": "Execution",
23+
"startTimeUtc": "2020-02-22T00:00:00.0000000Z",
24+
"endTimeUtc": "2020-02-22T00:00:00.0000000Z",
25+
"resourceIdentifiers": [
26+
{
27+
"azureResourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Compute/virtualMachines/vm1",
28+
"type": "AzureResource"
29+
},
30+
{
31+
"workspaceId": "f419f624-acad-4d89-b86d-f62fa387f019",
32+
"workspaceSubscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
33+
"workspaceResourceGroup": "myRg1",
34+
"agentId": "75724a01-f021-4aa8-9ec2-329792373e6e",
35+
"type": "LogAnalytics"
36+
}
37+
],
38+
"remediationSteps": [
39+
"No further action is needed."
40+
],
41+
"vendorName": "Microsoft",
42+
"status": "New",
43+
"extendedLinks": [
44+
{
45+
"Category": "threat_reports",
46+
"Label": "Report: RDP Brute Forcing",
47+
"Href": "https://contoso.com/reports/DisplayReport",
48+
"Type": "webLink"
49+
}
50+
],
51+
"alertUri": "https://portal.azure.com/#blade/Microsoft_Azure_Security/AlertBlade/alertId/2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a/subscriptionId/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroup/myRg1/referencedFrom/alertDeepLink/location/westeurope",
52+
"timeGeneratedUtc": "2020-02-23T13:47:58.0000000Z",
53+
"productName": "Azure Security Center",
54+
"processingEndTimeUtc": "2020-02-23T13:47:58.9205584Z",
55+
"entities": [
56+
{
57+
"address": "192.0.2.1",
58+
"location": {
59+
"countryCode": "gb",
60+
"state": "wokingham",
61+
"city": "sonning",
62+
"longitude": -0.909,
63+
"latitude": 51.468,
64+
"asn": 6584
65+
},
66+
"type": "ip"
67+
}
68+
],
69+
"isIncident": true,
70+
"correlationKey": "kso0LFWxzCll5tqrk5hmrBJ+MY1BX806W6q6+0s9Lk=",
71+
"extendedProperties": {
72+
"Property1": "Property1 information"
73+
},
74+
"compromisedEntity": "vm1"
75+
}
76+
}
77+
}
78+
}
79+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
{
2+
"parameters": {
3+
"api-version": "2021-11-01",
4+
"subscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
5+
"ascLocation": "westeurope",
6+
"alertName": "2518770965529163669_F144EE95-A3E5-42DA-A279-967D115809AA"
7+
},
8+
"responses": {
9+
"200": {
10+
"body": {
11+
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Security/locations/westeurope/alerts/2518770965529163669_F144EE95-A3E5-42DA-A279-967D115809AA",
12+
"name": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
13+
"type": "Microsoft.Security/Locations/alerts",
14+
"properties": {
15+
"alertType": "VM_EICAR",
16+
"systemAlertId": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
17+
"productComponentName": "",
18+
"alertDisplayName": "Azure Security Center test alert (not a threat)",
19+
"description": "This is a test alert generated by Azure Security Center. No further action is needed.",
20+
"severity": "High",
21+
"intent": "Execution",
22+
"startTimeUtc": "2020-02-22T00:00:00.0000000Z",
23+
"endTimeUtc": "2020-02-22T00:00:00.0000000Z",
24+
"resourceIdentifiers": [
25+
{
26+
"azureResourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Compute/virtualMachines/vm1",
27+
"type": "AzureResource"
28+
},
29+
{
30+
"workspaceId": "f419f624-acad-4d89-b86d-f62fa387f019",
31+
"workspaceSubscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
32+
"workspaceResourceGroup": "myRg1",
33+
"agentId": "75724a01-f021-4aa8-9ec2-329792373e6e",
34+
"type": "LogAnalytics"
35+
}
36+
],
37+
"remediationSteps": [
38+
"No further action is needed."
39+
],
40+
"vendorName": "Microsoft",
41+
"status": "New",
42+
"extendedLinks": [
43+
{
44+
"Category": "threat_reports",
45+
"Label": "Report: RDP Brute Forcing",
46+
"Href": "https://contoso.com/reports/DisplayReport",
47+
"Type": "webLink"
48+
}
49+
],
50+
"alertUri": "https://portal.azure.com/#blade/Microsoft_Azure_Security/AlertBlade/alertId/2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a/subscriptionId/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroup/myRg1/referencedFrom/alertDeepLink/location/westeurope",
51+
"timeGeneratedUtc": "2020-02-23T13:47:58.0000000Z",
52+
"productName": "Azure Security Center",
53+
"processingEndTimeUtc": "2020-02-23T13:47:58.9205584Z",
54+
"entities": [
55+
{
56+
"address": "192.0.2.1",
57+
"location": {
58+
"countryCode": "gb",
59+
"state": "wokingham",
60+
"city": "sonning",
61+
"longitude": -0.909,
62+
"latitude": 51.468,
63+
"asn": 6584
64+
},
65+
"type": "ip"
66+
}
67+
],
68+
"isIncident": true,
69+
"correlationKey": "kso0LFWxzCll5tqrk5hmrBJ+MY1BX806W6q6+0s9Lk=",
70+
"extendedProperties": {
71+
"Property1": "Property1 information"
72+
},
73+
"compromisedEntity": "vm1"
74+
}
75+
}
76+
}
77+
}
78+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,82 @@
1+
{
2+
"parameters": {
3+
"api-version": "2021-11-01",
4+
"subscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
5+
"resourceGroupName": "myRg1",
6+
"ascLocation": "westeurope"
7+
},
8+
"responses": {
9+
"200": {
10+
"body": {
11+
"value": [
12+
{
13+
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Security/locations/westeurope/alerts/2518770965529163669_F144EE95-A3E5-42DA-A279-967D115809AA",
14+
"name": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
15+
"type": "Microsoft.Security/Locations/alerts",
16+
"properties": {
17+
"alertType": "VM_EICAR",
18+
"systemAlertId": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
19+
"productComponentName": "",
20+
"alertDisplayName": "Azure Security Center test alert (not a threat)",
21+
"description": "This is a test alert generated by Azure Security Center. No further action is needed.",
22+
"severity": "High",
23+
"intent": "Execution",
24+
"startTimeUtc": "2020-02-22T00:00:00.0000000Z",
25+
"endTimeUtc": "2020-02-22T00:00:00.0000000Z",
26+
"resourceIdentifiers": [
27+
{
28+
"azureResourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Compute/virtualMachines/vm1",
29+
"type": "AzureResource"
30+
},
31+
{
32+
"workspaceId": "f419f624-acad-4d89-b86d-f62fa387f019",
33+
"workspaceSubscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
34+
"workspaceResourceGroup": "myRg1",
35+
"agentId": "75724a01-f021-4aa8-9ec2-329792373e6e",
36+
"type": "LogAnalytics"
37+
}
38+
],
39+
"remediationSteps": [
40+
"No further action is needed."
41+
],
42+
"vendorName": "Microsoft",
43+
"status": "New",
44+
"extendedLinks": [
45+
{
46+
"Category": "threat_reports",
47+
"Label": "Report: RDP Brute Forcing",
48+
"Href": "https://contoso.com/reports/DisplayReport",
49+
"Type": "webLink"
50+
}
51+
],
52+
"alertUri": "https://portal.azure.com/#blade/Microsoft_Azure_Security/AlertBlade/alertId/2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a/subscriptionId/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroup/myRg1/referencedFrom/alertDeepLink/location/westeurope",
53+
"timeGeneratedUtc": "2020-02-23T13:47:58.0000000Z",
54+
"productName": "Azure Security Center",
55+
"processingEndTimeUtc": "2020-02-23T13:47:58.9205584Z",
56+
"entities": [
57+
{
58+
"address": "192.0.2.1",
59+
"location": {
60+
"countryCode": "gb",
61+
"state": "wokingham",
62+
"city": "sonning",
63+
"longitude": -0.909,
64+
"latitude": 51.468,
65+
"asn": 6584
66+
},
67+
"type": "ip"
68+
}
69+
],
70+
"isIncident": true,
71+
"correlationKey": "kso0LFWxzCll5tqrk5hmrBJ+MY1BX806W6q6+0s9Lk=",
72+
"extendedProperties": {
73+
"Property1": "Property1 information"
74+
},
75+
"compromisedEntity": "vm1"
76+
}
77+
}
78+
]
79+
}
80+
}
81+
}
82+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,81 @@
1+
{
2+
"parameters": {
3+
"api-version": "2021-11-01",
4+
"subscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
5+
"resourceGroupName": "myRg1"
6+
},
7+
"responses": {
8+
"200": {
9+
"body": {
10+
"value": [
11+
{
12+
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Security/locations/westeurope/alerts/2518770965529163669_F144EE95-A3E5-42DA-A279-967D115809AA",
13+
"name": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
14+
"type": "Microsoft.Security/Locations/alerts",
15+
"properties": {
16+
"alertType": "VM_EICAR",
17+
"systemAlertId": "2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a",
18+
"productComponentName": "",
19+
"alertDisplayName": "Azure Security Center test alert (not a threat)",
20+
"description": "This is a test alert generated by Azure Security Center. No further action is needed.",
21+
"severity": "High",
22+
"intent": "Execution",
23+
"startTimeUtc": "2020-02-22T00:00:00.0000000Z",
24+
"endTimeUtc": "2020-02-22T00:00:00.0000000Z",
25+
"resourceIdentifiers": [
26+
{
27+
"azureResourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroups/myRg1/providers/Microsoft.Compute/virtualMachines/vm1",
28+
"type": "AzureResource"
29+
},
30+
{
31+
"workspaceId": "f419f624-acad-4d89-b86d-f62fa387f019",
32+
"workspaceSubscriptionId": "20ff7fc3-e762-44dd-bd96-b71116dcdc23",
33+
"workspaceResourceGroup": "myRg1",
34+
"agentId": "75724a01-f021-4aa8-9ec2-329792373e6e",
35+
"type": "LogAnalytics"
36+
}
37+
],
38+
"remediationSteps": [
39+
"No further action is needed."
40+
],
41+
"vendorName": "Microsoft",
42+
"status": "New",
43+
"extendedLinks": [
44+
{
45+
"Category": "threat_reports",
46+
"Label": "Report: RDP Brute Forcing",
47+
"Href": "https://contoso.com/reports/DisplayReport",
48+
"Type": "webLink"
49+
}
50+
],
51+
"alertUri": "https://portal.azure.com/#blade/Microsoft_Azure_Security/AlertBlade/alertId/2518298467986649999_4d25bfef-2d77-4a08-adc0-3e35715cc92a/subscriptionId/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourceGroup/myRg1/referencedFrom/alertDeepLink/location/westeurope",
52+
"timeGeneratedUtc": "2020-02-23T13:47:58.0000000Z",
53+
"productName": "Azure Security Center",
54+
"processingEndTimeUtc": "2020-02-23T13:47:58.9205584Z",
55+
"entities": [
56+
{
57+
"address": "192.0.2.1",
58+
"location": {
59+
"countryCode": "gb",
60+
"state": "wokingham",
61+
"city": "sonning",
62+
"longitude": -0.909,
63+
"latitude": 51.468,
64+
"asn": 6584
65+
},
66+
"type": "ip"
67+
}
68+
],
69+
"isIncident": true,
70+
"correlationKey": "kso0LFWxzCll5tqrk5hmrBJ+MY1BX806W6q6+0s9Lk=",
71+
"extendedProperties": {
72+
"Property1": "Property1 information"
73+
},
74+
"compromisedEntity": "vm1"
75+
}
76+
}
77+
]
78+
}
79+
}
80+
}
81+
}

0 commit comments

Comments
 (0)