Commit a616da1
committed
File tree
- .github
- instructions
- workflows
- .script/tests
- KqlvalidationsTests
- CustomFunctions
- CustomTables
- FunctionSchemasLoaders
- detectionTemplateSchemaValidation
- ASIM/dev/ASimTester
- DataConnectors
- AWS-CloudTrail-AzureFunction
- AzFunAWSCloudTrailLogsIngestion
- AWS-S3-AzureFunction
- AzFun-AWS-S3-Ingestion
- AWS-SecurityHubFindings
- CEF
- microsoft-sentinel-log-analytics-logstash-output-plugin
- Hunting Queries/AI Agents
- A365 Connector
- Copilot Studio Connector
- Logos
- Parsers
- ASimAuthentication
- ARM
- ASimAuthenticationCiscoIOS
- ASimAuthenticationCiscoISEAdministrator
- ASimAuthenticationPaloAltoGlobalProtect
- ASimAuthenticationVMwareVCenter
- ASimAuthentication
- imAuthentication
- vimAuthenticationCiscoIOS
- vimAuthenticationCiscoISEAdministrator
- vimAuthenticationEmpty
- vimAuthenticationPaloAltoGlobalProtect
- vimAuthenticationVMwareVCenter
- CHANGELOG
- Parsers
- ASimProcessEvent
- ARM
- imProcessCreate
- imProcessEvent
- imProcessTerminate
- vimProcessCreateLinuxSysmon
- vimProcessCreateMD4IoT
- vimProcessEventMD4IoT
- vimProcessTerminateLinuxSysmon
- vimProcessTerminateMD4IoT
- vimProcessTerminateMicrosoftSecurityEvents
- Parsers
- ASimWebSession
- ARM/vimWebSessionCiscoUmbrella
- CHANGELOG
- Parsers
- Sample Data
- ASIM
- Custom
- Solutions
- AbnormalSecurity
- Data Connectors/AbnormalSecurity_CCF
- Sample Data
- Data
- Package
- AtlassianConfluenceAudit
- Data Connectors/AtlassianConfluenceAuditLogs_CCP
- Data
- Package
- AtlassianJiraAudit
- Data Connectors
- Data
- Package
- Auth0
- Data Connectors
- Data
- Package
- Azure Resource Graph
- Data Connectors
- Data
- Package
- AzureSecurityBenchmark
- Package
- Workbooks
- BeyondTrustPMCloud/Data Connectors
- AzureFunctionBeyondTrustPMCloud/Services
- Blacklens
- Data Connectors/deployment
- Data
- Package
- BloodHound Enterprise/Data Connectors/BloodHoundDataConnector
- Box
- Data Connectors
- Data
- Package
- Censys
- Data
- Package
- Playbooks
- CensysAddIncidentComment
- CensysAlertEnrichment
- CensysAlertRescan
- CensysEntityEnrichmentCertificate
- CensysEntityEnrichmentHost
- CensysEntityEnrichmentWebProperty
- CensysHostHistory
- CensysIOCLookup
- CensysIncidentEnrichment
- CensysRelatedInfrastructure
- CensysRescan
- Workbooks
- Check Point Cyberint Alerts
- Analytic Rules
- Data Connectors/CyberintArgosAlertsLogs_ccp
- Data
- Package
- Parsers
- Playbooks
- Enrichment
- CPEM_FetchAttachments
- CPEM_IOCEnrichment
- Response
- CPEM_CredentialLeakResponse
- CPEM_PhishingTakedown
- CPEM_VulnerabilityMonitoring
- Sync
- CPEM_AutomationRules
- CPEM_InboundSync
- CPEM_ManualStatusUpdate
- CPEM_OutboundSync
- Workbooks
- Images/Preview
- docs
- Check Point Cyberint IOC
- Data Connectors/CyberintArgosIOCLogs_ccp
- Data
- Package
- CiscoDuoSecurity/Data Connectors
- AzureFunctionCiscoDuo
- Citrix Analytics CCF
- Data Connectors/CitrixAnalytics_CCF
- Data
- Package
- Workbooks
- Images/Preview
- Commvault Security IQ
- Data Connectors
- ContrastADR
- Analytic Rules
- Data Connectors
- AzureFunctionContrastADR
- ContrastADRCCF
- Data
- Package
- Parsers
- Workbooks
- CrowdStrike Falcon Endpoint Protection
- Data Connectors/CrowdstrikeReplicatorCLv2
- Package
- Cyjax
- Data Connectors
- CyjaxIOCIngestion
- Data
- Package
- Parsers
- Playbooks
- CyjaxAdHocEnrichment
- CyjaxAddCommentToIncident
- CyjaxDataBreaches
- CyjaxDomainMonitor
- CyjaxIncidentEnrichment
- Workbooks
- Cyren-SentinelOne-ThreatIntelligence
- Data
- Package
- Playbooks
- D3SmartSOAR
- Analytic Rules
- Data
- Package
- Dataminr Pulse/Data Connectors/DataminrPulseAlerts
- Dynatrace
- Data Connectors
- DynatraceAttacksV1
- DynatraceAttacksV2
- DynatraceAuditLogsV1
- DynatraceAuditLogsV2
- DynatraceProblemsV1
- DynatraceProblemsV2
- DynatraceRuntimeVulnerabilitiesV1
- DynatraceRuntimeVulnerabilitiesV2
- Data
- Package
- Parsers
- ESET Protect Platform/Data Connectors
- ExtraHop
- Data Connectors/ExtraHopDataConnector
- ExtraHopSentinelActivity
- Data
- Package
- Parsers
- Global Secure Access
- Analytic Rules
- Data
- Package
- Workbooks
- Google Cloud Platform Cloud Monitoring/Data Connectors
- ImpervaCloudWAF
- Data Connectors/ImpervaCloudWAFLogs_ccf
- Data
- Package
- Island
- Data Connectors
- IslandV2_CCP
- Data
- Package
- Lookout Cloud Security Platform for Microsoft Sentinel/Data Connectors/LookoutCSConnector
- Lookout/Package
- Microsoft Entra ID
- Analytic Rules
- Data
- Package
- Watchlists
- Okta Single Sign-On
- Data Connectors/OktaSingleSign-On
- Package
- data
- Open Systems/DataConnectors
- PaloAltoPrismaCloud/Data Connectors
- Proofpoint On demand(POD) Email Security
- Data Connectors/ProofPointEmailSecurity_CCP
- Data
- Package
- Qualys VM Knowledgebase
- Data
- Package
- Rapid7InsightVM/Data Connectors
- Recorded Future Identity
- Analytic Rules/IncidentCreation
- Data
- Package
- Playbooks
- RFI-Playbook-Alert-Importer-LAW-Sentinel
- RFI-Playbook-Alert-Importer-LAW
- Recorded Future
- Data
- Package
- Playbooks
- IndicatorImport
- RecordedFuture-Domain-IndicatorImport
- RecordedFuture-Hash-IndicatorImport
- RecordedFuture-IP-IndicatorImport
- RecordedFuture-URL-IndicatorImport
- Sandboxing
- RecordedFuture-Sandbox_Enrichment-Url
- RecordedFuture-Sandbox_Outlook_Attachment
- RecordedFuture-Sandbox_StorageAccount
- SAP ETD Cloud
- Analytic Rules
- Data Connectors/SAPETD_PUSH_CCP
- Data
- Package
- SAP LogServ
- Data Connectors
- SAPLogServ_PUSH_CCP
- Package
- SAP S4 Cloud Public Edition
- Data Connectors/SAPS4PublicPollerConnector
- Package
- SAP
- Agentless
- Playbooks
- Basic-SAPLockUser
- Sample Authorizations Role File
- SOC Prime CCF
- Analytic Rules
- Data Connectors/SOCPrime_ccp
- Data
- Package
- SailPointIdentityNow/Data Connectors
- SentinelOne
- Data Connectors
- Data
- Package
- Sophos Endpoint Protection
- Data Connectors
- Data
- Package
- Tanium
- Data Connectors
- Data
- Package
- Workbooks
- ci
- Tenable App
- Data Connectors/TenableVM
- TenableStartVulnExportJob
- TheHive
- Data Connectors/CCF
- Package
- Threat Intelligence (NEW)
- Analytic Rules
- Package
- Trend Micro Vision One/Data Connectors
- AzureFunctionTrendMicroXDR
- timer_trigger_oat
- timer_trigger
- Upwind
- Data
- Package
- VMware Carbon Black Cloud
- Data Connectors
- Data
- Package
- Vectra XDR/Data Connectors/VectraDataConnector/Detections
- Visa Threat Intelligence (VTI)
- Data
- Package
- ZeroFox/Data Connectors/CTI
- AzureFunctionZeroFoxCTI
- meshStack
- Data
- Package
- Tools
- Microsoft-Sentinel-Classic-CLv1-Tables-Impact-Assessment
- .github
- agents
- instructions
- Templates
- Microsoft-Sentinel-Training-Lab
- Artifacts
- DetectionRules
- Federation
- LinkedTemplates
- Scripts
- Telemetry
- BuildIn
- Custom
- Exercises
- Images
- MCP
- Notebook
- Package
- Tools
- Watchlists
- QRadarMigration
- Solutions Analyzer
- Workbooks
- Images
- Logos
- Preview
- cspell-dictionaries
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
42 | 56 | | |
43 | 57 | | |
44 | 58 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | | - | |
62 | 61 | | |
63 | 62 | | |
64 | 63 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
78 | 96 | | |
79 | 97 | | |
80 | 98 | | |
| |||
0 commit comments