diff --git a/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL.json b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL.json new file mode 100644 index 00000000000..dee0e4a8cb2 --- /dev/null +++ b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL.json @@ -0,0 +1,105 @@ +{ + "Name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "Properties": [ + { + "Name": "TenantId", + "Type": "string" + }, + { + "Name": "TimeGenerated", + "Type": "datetime" + }, + { + "Name": "Time", + "Type": "string" + }, + { + "Name": "abx_body", + "Type": "string" + }, + { + "Name": "abx_metadata", + "Type": "string" + }, + { + "Name": "abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_metadata_trace_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_not_analyzed_b", + "Type": "bool" + }, + { + "Name": "abx_body_abx_body_reason_for_no_analysis_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_campaign_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_abnormal_message_id_d", + "Type": "real" + }, + { + "Name": "abx_body_abx_body_subject_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_reported_b", + "Type": "bool" + }, + { + "Name": "abx_body_abx_body_message_reported_time_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_reporter_name_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_reporter_address_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_judgement_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_recipient_name_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_recipient_address_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_internet_message_id_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_email_label_or_location_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_trace_id_g", + "Type": "guid" + } + ] +} diff --git a/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ATO_CASE_V2_CL.json b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ATO_CASE_V2_CL.json new file mode 100644 index 00000000000..670d85b8ef5 --- /dev/null +++ b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_ATO_CASE_V2_CL.json @@ -0,0 +1,73 @@ +{ + "Name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "Properties": [ + { + "Name": "TenantId", + "Type": "string" + }, + { + "Name": "TimeGenerated", + "Type": "datetime" + }, + { + "Name": "Time", + "Type": "string" + }, + { + "Name": "abx_body", + "Type": "string" + }, + { + "Name": "abx_metadata", + "Type": "string" + }, + { + "Name": "abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_metadata_trace_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_ato_case_id_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_severity_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_status_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_compromised_account_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_first_detected_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_indicators_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_trace_id_g", + "Type": "guid" + } + ] +} diff --git a/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_THREAT_LOG_V2_CL.json b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_THREAT_LOG_V2_CL.json new file mode 100644 index 00000000000..0c0547cb216 --- /dev/null +++ b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_THREAT_LOG_V2_CL.json @@ -0,0 +1,221 @@ +{ + "Name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "Properties": [ + { + "Name": "TenantId", + "Type": "string" + }, + { + "Name": "TimeGenerated", + "Type": "datetime" + }, + { + "Name": "Time", + "Type": "string" + }, + { + "Name": "abx_body", + "Type": "string" + }, + { + "Name": "abx_metadata", + "Type": "string" + }, + { + "Name": "abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_metadata_trace_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_abx_message_id_d", + "Type": "real" + }, + { + "Name": "abx_body_abx_body_abx_message_id_str_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_abx_portal_url_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_threat_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_subject_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_from_name_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_from_address_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_to_addresses_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_recipient_address_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_received_time_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_sent_time_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_internet_message_id_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_auto_remediated_b", + "Type": "bool" + }, + { + "Name": "abx_body_abx_body_post_remediated_b", + "Type": "bool" + }, + { + "Name": "abx_body_abx_body_remediation_status_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_remediation_timestamp_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_attack_type_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_attack_strategy_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_attack_vector_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_attack_score_d", + "Type": "real" + }, + { + "Name": "abx_body_abx_body_attacked_party_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_return_path_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_reply_to_emails_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_cc_emails_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_bcc_emails_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_sender_ip_address_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_sender_domain_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_sender_auth_results_spf_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_sender_auth_results_dkim_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_sender_auth_results_dmarc_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_impersonated_party_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_attachment_names_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_attachment_count_d", + "Type": "real" + }, + { + "Name": "abx_body_abx_body_attachment_analysis_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_urls_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_url_count_d", + "Type": "real" + }, + { + "Name": "abx_body_abx_body_summary_insights_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_is_read_b", + "Type": "bool" + }, + { + "Name": "abx_body_abx_body_folder_locations_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_message_sources_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_message_engagement_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_source_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_tenant_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_trace_id_g", + "Type": "guid" + } + ] +} diff --git a/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_VENDOR_CASE_V2_CL.json b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_VENDOR_CASE_V2_CL.json new file mode 100644 index 00000000000..3dbd7cd4b02 --- /dev/null +++ b/.script/tests/KqlvalidationsTests/CustomTables/ABNORMAL_SECURITY_VENDOR_CASE_V2_CL.json @@ -0,0 +1,73 @@ +{ + "Name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "Properties": [ + { + "Name": "TenantId", + "Type": "string" + }, + { + "Name": "TimeGenerated", + "Type": "datetime" + }, + { + "Name": "Time", + "Type": "string" + }, + { + "Name": "abx_body", + "Type": "string" + }, + { + "Name": "abx_metadata", + "Type": "string" + }, + { + "Name": "abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_metadata_trace_id_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_vendorCaseId_g", + "Type": "guid" + }, + { + "Name": "abx_body_abx_body_firstObservedTime_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_lastModifiedTime_t", + "Type": "datetime" + }, + { + "Name": "abx_body_abx_body_vendorDomain_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_insights_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_body_timeline_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_event_type_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_timestamp_s", + "Type": "string" + }, + { + "Name": "abx_body_abx_metadata_trace_id_g", + "Type": "guid" + } + ] +} diff --git a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AbuseMailboxMalicious.yaml b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AbuseMailboxMalicious.yaml index 511f45a06c7..e6699df2b39 100644 --- a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AbuseMailboxMalicious.yaml +++ b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AbuseMailboxMalicious.yaml @@ -10,7 +10,7 @@ status: Available requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_ABUSE_MAILBOX_CL + - ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL queryFrequency: 1h queryPeriod: 1h triggerOperator: gt @@ -20,7 +20,7 @@ tactics: relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_ABUSE_MAILBOX_CL + ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL | where abx_body_abx_body_reported_b == true | where tolower(abx_body_abx_body_judgement_s) == "malicious" | extend @@ -61,5 +61,5 @@ eventGroupingSettings: aggregationKind: AlertPerResult suppressionDuration: PT5H suppressionEnabled: false -version: 1.0.0 +version: 1.0.1 kind: Scheduled diff --git a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AccountTakeover.yaml b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AccountTakeover.yaml index 47644662ce0..0fcaf1c4cde 100644 --- a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AccountTakeover.yaml +++ b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_AccountTakeover.yaml @@ -9,7 +9,7 @@ status: Available requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_ATO_CASE_CL + - ABNORMAL_SECURITY_ATO_CASE_V2_CL queryFrequency: 1h queryPeriod: 1h triggerOperator: gt @@ -21,7 +21,7 @@ relevantTechniques: - T1078 - T1110 query: | - ABNORMAL_SECURITY_ATO_CASE_CL + ABNORMAL_SECURITY_ATO_CASE_V2_CL | where isnotempty(abx_body_abx_body_ato_case_id_s) // Collapse to one row per ATO case (earliest event in the window) so repeated // events for the same case do not raise duplicate alerts. @@ -56,5 +56,5 @@ eventGroupingSettings: aggregationKind: AlertPerResult suppressionDuration: PT5H suppressionEnabled: false -version: 1.0.0 +version: 1.0.1 kind: Scheduled diff --git a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_HighRiskEmailAttack.yaml b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_HighRiskEmailAttack.yaml index 88c73afdf49..44821e3535e 100644 --- a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_HighRiskEmailAttack.yaml +++ b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_HighRiskEmailAttack.yaml @@ -11,7 +11,7 @@ status: Available requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_THREAT_LOG_CL + - ABNORMAL_SECURITY_THREAT_LOG_V2_CL queryFrequency: 1h queryPeriod: 1h triggerOperator: gt @@ -21,7 +21,7 @@ tactics: relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_THREAT_LOG_CL + ABNORMAL_SECURITY_THREAT_LOG_V2_CL | where abx_body_abx_body_attack_type_s in~ ( "Phishing: Credential", "Social Engineering (BEC)", @@ -79,5 +79,5 @@ eventGroupingSettings: aggregationKind: AlertPerResult suppressionDuration: PT5H suppressionEnabled: false -version: 1.0.0 +version: 1.0.1 kind: Scheduled diff --git a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_VendorCompromise.yaml b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_VendorCompromise.yaml index 288a3dfa908..fc6ffaa1abc 100644 --- a/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_VendorCompromise.yaml +++ b/Solutions/AbnormalSecurity/Analytic Rules/AbnormalSecurity_VendorCompromise.yaml @@ -9,7 +9,7 @@ status: Available requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_VENDOR_CASE_CL + - ABNORMAL_SECURITY_VENDOR_CASE_V2_CL queryFrequency: 1h queryPeriod: 1h triggerOperator: gt @@ -19,8 +19,8 @@ tactics: relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_VENDOR_CASE_CL - | where isnotempty(abx_body_abx_body_vendorCaseId_g) + ABNORMAL_SECURITY_VENDOR_CASE_V2_CL + | where isnotnull(abx_body_abx_body_vendorCaseId_g) // Collapse to one row per vendor case (earliest event in the window) so repeated // events for the same case do not raise duplicate alerts. | summarize arg_min(TimeGenerated, *) by CaseId = abx_body_abx_body_vendorCaseId_g @@ -51,5 +51,5 @@ eventGroupingSettings: aggregationKind: AlertPerResult suppressionDuration: PT5H suppressionEnabled: false -version: 1.0.0 +version: 1.0.1 kind: Scheduled diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_DCR.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_DCR.json index cbdcb292844..cc74093a2e8 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_DCR.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_DCR.json @@ -167,8 +167,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_LOGS_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_LOGS_V2_CL" }, { "streams": [ @@ -177,8 +177,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_abx_message_id_d = toreal(abx_body.abx_body.abx_message_id)\n| extend abx_body_abx_body_abx_message_id_str_s = tostring(abx_body.abx_body.abx_message_id_str)\n| extend abx_body_abx_body_abx_portal_url_s = tostring(abx_body.abx_body.abx_portal_url)\n| extend abx_body_abx_body_threat_id_g = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_from_name_s = tostring(abx_body.abx_body.from_name)\n| extend abx_body_abx_body_from_address_s = tostring(abx_body.abx_body.from_address)\n| extend abx_body_abx_body_to_addresses_s = tostring(abx_body.abx_body.to_addresses)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_received_time_t = todatetime(abx_body.abx_body.received_time)\n| extend abx_body_abx_body_sent_time_t = todatetime(abx_body.abx_body.sent_time)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_auto_remediated_b = tobool(abx_body.abx_body.auto_remediated)\n| extend abx_body_abx_body_post_remediated_b = tobool(abx_body.abx_body.post_remediated)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_remediation_timestamp_t = todatetime(abx_body.abx_body.remediation_timestamp)\n| extend abx_body_abx_body_attack_type_s = tostring(abx_body.abx_body.attack_type)\n| extend abx_body_abx_body_attack_strategy_s = tostring(abx_body.abx_body.attack_strategy)\n| extend abx_body_abx_body_attack_vector_s = tostring(abx_body.abx_body.attack_vector)\n| extend abx_body_abx_body_attack_score_d = toreal(abx_body.abx_body.attack_score)\n| extend abx_body_abx_body_attacked_party_s = tostring(abx_body.abx_body.attacked_party)\n| extend abx_body_abx_body_return_path_s = tostring(abx_body.abx_body.return_path)\n| extend abx_body_abx_body_reply_to_emails_s = tostring(abx_body.abx_body.reply_to_emails)\n| extend abx_body_abx_body_cc_emails_s = tostring(abx_body.abx_body.cc_emails)\n| extend abx_body_abx_body_bcc_emails_s = tostring(abx_body.abx_body.bcc_emails)\n| extend abx_body_abx_body_sender_ip_address_s = tostring(abx_body.abx_body.sender_ip_address)\n| extend abx_body_abx_body_sender_domain_s = tostring(abx_body.abx_body.sender_domain)\n| extend abx_body_abx_body_sender_auth_results_spf_s = tostring(abx_body.abx_body.sender_auth_results.spf)\n| extend abx_body_abx_body_sender_auth_results_dkim_s = tostring(abx_body.abx_body.sender_auth_results.dkim)\n| extend abx_body_abx_body_sender_auth_results_dmarc_s = tostring(abx_body.abx_body.sender_auth_results.dmarc)\n| extend abx_body_abx_body_impersonated_party_s = tostring(abx_body.abx_body.impersonated_party)\n| extend abx_body_abx_body_attachment_names_s = tostring(abx_body.abx_body.attachment_names)\n| extend abx_body_abx_body_attachment_count_d = toreal(abx_body.abx_body.attachment_count)\n| extend abx_body_abx_body_attachment_analysis_s = tostring(abx_body.abx_body.attachment_analysis)\n| extend abx_body_abx_body_urls_s = tostring(abx_body.abx_body.urls)\n| extend abx_body_abx_body_url_count_d = toreal(abx_body.abx_body.url_count)\n| extend abx_body_abx_body_summary_insights_s = tostring(abx_body.abx_body.summary_insights)\n| extend abx_body_abx_body_is_read_b = tobool(abx_body.abx_body.is_read)\n| extend abx_body_abx_body_folder_locations_s = tostring(abx_body.abx_body.folder_locations)\n| extend abx_body_abx_body_message_sources_s = tostring(abx_body.abx_body.message_sources)\n| extend abx_body_abx_body_message_engagement_s = tostring(abx_body.abx_body.message_engagement)\n| extend abx_body_abx_body_source_s = tostring(abx_body.abx_body.source)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_THREAT_LOG_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_abx_message_id_d = toreal(abx_body.abx_body.abx_message_id)\n| extend abx_body_abx_body_abx_message_id_str_s = tostring(abx_body.abx_body.abx_message_id_str)\n| extend abx_body_abx_body_abx_portal_url_s = tostring(abx_body.abx_body.abx_portal_url)\n| extend abx_body_abx_body_threat_id_g = toguid(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_from_name_s = tostring(abx_body.abx_body.from_name)\n| extend abx_body_abx_body_from_address_s = tostring(abx_body.abx_body.from_address)\n| extend abx_body_abx_body_to_addresses_s = tostring(abx_body.abx_body.to_addresses)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_received_time_t = todatetime(abx_body.abx_body.received_time)\n| extend abx_body_abx_body_sent_time_t = todatetime(abx_body.abx_body.sent_time)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_auto_remediated_b = tobool(abx_body.abx_body.auto_remediated)\n| extend abx_body_abx_body_post_remediated_b = tobool(abx_body.abx_body.post_remediated)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_remediation_timestamp_t = todatetime(abx_body.abx_body.remediation_timestamp)\n| extend abx_body_abx_body_attack_type_s = tostring(abx_body.abx_body.attack_type)\n| extend abx_body_abx_body_attack_strategy_s = tostring(abx_body.abx_body.attack_strategy)\n| extend abx_body_abx_body_attack_vector_s = tostring(abx_body.abx_body.attack_vector)\n| extend abx_body_abx_body_attack_score_d = toreal(abx_body.abx_body.attack_score)\n| extend abx_body_abx_body_attacked_party_s = tostring(abx_body.abx_body.attacked_party)\n| extend abx_body_abx_body_return_path_s = tostring(abx_body.abx_body.return_path)\n| extend abx_body_abx_body_reply_to_emails_s = tostring(abx_body.abx_body.reply_to_emails)\n| extend abx_body_abx_body_cc_emails_s = tostring(abx_body.abx_body.cc_emails)\n| extend abx_body_abx_body_bcc_emails_s = tostring(abx_body.abx_body.bcc_emails)\n| extend abx_body_abx_body_sender_ip_address_s = tostring(abx_body.abx_body.sender_ip_address)\n| extend abx_body_abx_body_sender_domain_s = tostring(abx_body.abx_body.sender_domain)\n| extend abx_body_abx_body_sender_auth_results_spf_s = tostring(abx_body.abx_body.sender_auth_results.spf)\n| extend abx_body_abx_body_sender_auth_results_dkim_s = tostring(abx_body.abx_body.sender_auth_results.dkim)\n| extend abx_body_abx_body_sender_auth_results_dmarc_s = tostring(abx_body.abx_body.sender_auth_results.dmarc)\n| extend abx_body_abx_body_impersonated_party_s = tostring(abx_body.abx_body.impersonated_party)\n| extend abx_body_abx_body_attachment_names_s = tostring(abx_body.abx_body.attachment_names)\n| extend abx_body_abx_body_attachment_count_d = toreal(abx_body.abx_body.attachment_count)\n| extend abx_body_abx_body_attachment_analysis_s = tostring(abx_body.abx_body.attachment_analysis)\n| extend abx_body_abx_body_urls_s = tostring(abx_body.abx_body.urls)\n| extend abx_body_abx_body_url_count_d = toreal(abx_body.abx_body.url_count)\n| extend abx_body_abx_body_summary_insights_s = tostring(abx_body.abx_body.summary_insights)\n| extend abx_body_abx_body_is_read_b = tobool(abx_body.abx_body.is_read)\n| extend abx_body_abx_body_folder_locations_s = tostring(abx_body.abx_body.folder_locations)\n| extend abx_body_abx_body_message_sources_s = tostring(abx_body.abx_body.message_sources)\n| extend abx_body_abx_body_message_engagement_s = tostring(abx_body.abx_body.message_engagement)\n| extend abx_body_abx_body_source_s = tostring(abx_body.abx_body.source)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_THREAT_LOG_V2_CL" }, { "streams": [ @@ -187,8 +187,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_schema_version_s = tostring(abx_body.abx_body.schema_version)\n| extend abx_body_abx_body_case_id_d = toreal(abx_body.abx_body.case_id)\n| extend abx_body_abx_body_customer_d = toreal(abx_body.abx_body.customer)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_body_first_observed_t = todatetime(abx_body.abx_body.first_observed)\n| extend abx_body_abx_body_date_created_t = todatetime(abx_body.abx_body.date_created)\n| extend abx_body_abx_body_first_customer_visible_time_t = todatetime(abx_body.abx_body.first_customer_visible_time)\n| extend abx_body_abx_body_trigger_event_s = tostring(abx_body.abx_body.trigger_event)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_confidence_s = tostring(abx_body.abx_body.confidence)\n| extend abx_body_abx_body_case_status_s = tostring(abx_body.abx_body.case_status)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_entity_entity_type_s = tostring(abx_body.abx_body.entity.entity_type)\n| extend abx_body_abx_body_entity_identifier_s = tostring(abx_body.abx_body.entity.identifier)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_genai_summary_s = tostring(abx_body.abx_body.genai_summary)\n| extend abx_body_abx_body_event_timeline_s = tostring(abx_body.abx_body.event_timeline)\n| extend abx_body_abx_body_platforms_s = tostring(abx_body.abx_body.platforms)\n| extend abx_body_abx_body_event_type_s = tostring(abx_body.abx_body.event_type)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_schema_version_s = tostring(abx_body.abx_body.schema_version)\n| extend abx_body_abx_body_case_id_d = toreal(abx_body.abx_body.case_id)\n| extend abx_body_abx_body_customer_d = toreal(abx_body.abx_body.customer)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_body_first_observed_t = todatetime(abx_body.abx_body.first_observed)\n| extend abx_body_abx_body_date_created_t = todatetime(abx_body.abx_body.date_created)\n| extend abx_body_abx_body_first_customer_visible_time_t = todatetime(abx_body.abx_body.first_customer_visible_time)\n| extend abx_body_abx_body_trigger_event_s = tostring(abx_body.abx_body.trigger_event)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_confidence_s = tostring(abx_body.abx_body.confidence)\n| extend abx_body_abx_body_case_status_s = tostring(abx_body.abx_body.case_status)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_entity_entity_type_s = tostring(abx_body.abx_body.entity.entity_type)\n| extend abx_body_abx_body_entity_identifier_s = tostring(abx_body.abx_body.entity.identifier)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_genai_summary_s = tostring(abx_body.abx_body.genai_summary)\n| extend abx_body_abx_body_event_timeline_s = tostring(abx_body.abx_body.event_timeline)\n| extend abx_body_abx_body_platforms_s = tostring(abx_body.abx_body.platforms)\n| extend abx_body_abx_body_event_type_s = tostring(abx_body.abx_body.event_type)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_CASE_V2_CL" }, { "streams": [ @@ -197,8 +197,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_audit_type_s = tostring(abx_body.abx_body.audit_type)\n| extend abx_body_abx_body_audit_subtype_s = tostring(abx_body.abx_body.audit_subtype)\n| extend abx_body_abx_body_category_s = tostring(abx_body.abx_body.category)\n| extend abx_body_abx_body_details_s = tostring(abx_body.abx_body.details)\n| extend abx_body_abx_body_source_ip_s = tostring(abx_body.abx_body.source_ip)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_tenant_name_s = tostring(abx_body.abx_body.tenant_name)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_user_email_s = tostring(abx_body.abx_body.user.email)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_AUDIT_LOG_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_audit_type_s = tostring(abx_body.abx_body.audit_type)\n| extend abx_body_abx_body_audit_subtype_s = tostring(abx_body.abx_body.audit_subtype)\n| extend abx_body_abx_body_category_s = tostring(abx_body.abx_body.category)\n| extend abx_body_abx_body_details_s = tostring(abx_body.abx_body.details)\n| extend abx_body_abx_body_source_ip_s = tostring(abx_body.abx_body.source_ip)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_tenant_name_s = tostring(abx_body.abx_body.tenant_name)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_user_email_s = tostring(abx_body.abx_body.user.email)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_AUDIT_LOG_V2_CL" }, { "streams": [ @@ -207,8 +207,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_not_analyzed_b = tobool(abx_body.abx_body.not_analyzed)\n| extend abx_body_abx_body_reason_for_no_analysis_s = tostring(abx_body.abx_body.reason_for_no_analysis)\n| extend abx_body_abx_body_campaign_id_g = tostring(abx_body.abx_body.campaign_id)\n| extend abx_body_abx_body_abnormal_message_id_d = toreal(abx_body.abx_body.abnormal_message_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_reported_b = tobool(abx_body.abx_body.reported)\n| extend abx_body_abx_body_message_reported_time_s = tostring(abx_body.abx_body.message_reported_time)\n| extend abx_body_abx_body_reporter_name_s = tostring(abx_body.abx_body.reporter_name)\n| extend abx_body_abx_body_reporter_address_s = tostring(abx_body.abx_body.reporter_address)\n| extend abx_body_abx_body_judgement_s = tostring(abx_body.abx_body.judgement)\n| extend abx_body_abx_body_recipient_name_s = tostring(abx_body.abx_body.recipient_name)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_email_label_or_location_s = tostring(abx_body.abx_body.email_label_or_location)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_not_analyzed_b = tobool(abx_body.abx_body.not_analyzed)\n| extend abx_body_abx_body_reason_for_no_analysis_s = tostring(abx_body.abx_body.reason_for_no_analysis)\n| extend abx_body_abx_body_campaign_id_g = toguid(abx_body.abx_body.campaign_id)\n| extend abx_body_abx_body_abnormal_message_id_d = toreal(abx_body.abx_body.abnormal_message_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_reported_b = tobool(abx_body.abx_body.reported)\n| extend abx_body_abx_body_message_reported_time_s = tostring(abx_body.abx_body.message_reported_time)\n| extend abx_body_abx_body_reporter_name_s = tostring(abx_body.abx_body.reporter_name)\n| extend abx_body_abx_body_reporter_address_s = tostring(abx_body.abx_body.reporter_address)\n| extend abx_body_abx_body_judgement_s = tostring(abx_body.abx_body.judgement)\n| extend abx_body_abx_body_recipient_name_s = tostring(abx_body.abx_body.recipient_name)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_email_label_or_location_s = tostring(abx_body.abx_body.email_label_or_location)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" }, { "streams": [ @@ -217,8 +217,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_type_s = tostring(abx_body.abx_body.type)\n| extend abx_body_abx_body_event_id_s = tostring(abx_body.abx_body.event_id)\n| extend abx_body_abx_body_tenant_id_d = toreal(abx_body.abx_body.tenant_id)\n| extend abx_body_abx_body_posture_id_s = tostring(abx_body.abx_body.posture_id)\n| extend abx_body_abx_body_posture_name_s = tostring(abx_body.abx_body.posture_name)\n| extend abx_body_abx_body_posture_category_s = tostring(abx_body.abx_body.posture_category)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_workflow_status_s = tostring(abx_body.abx_body.workflow_status)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_platform_type_s = tostring(abx_body.abx_body.platform_type)\n| extend abx_body_abx_body_posture_area_s = tostring(abx_body.abx_body.posture_area)\n| extend abx_body_abx_body_tags_s = tostring(abx_body.abx_body.tags)\n| extend abx_body_abx_body_benchmarks_s = tostring(abx_body.abx_body.benchmarks)\n| extend abx_body_abx_body_raw_event_s = tostring(abx_body.abx_body.raw_event)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_POSTURE_CHANGE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_type_s = tostring(abx_body.abx_body.type)\n| extend abx_body_abx_body_event_id_s = tostring(abx_body.abx_body.event_id)\n| extend abx_body_abx_body_tenant_id_d = toreal(abx_body.abx_body.tenant_id)\n| extend abx_body_abx_body_posture_id_s = tostring(abx_body.abx_body.posture_id)\n| extend abx_body_abx_body_posture_name_s = tostring(abx_body.abx_body.posture_name)\n| extend abx_body_abx_body_posture_category_s = tostring(abx_body.abx_body.posture_category)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_workflow_status_s = tostring(abx_body.abx_body.workflow_status)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_platform_type_s = tostring(abx_body.abx_body.platform_type)\n| extend abx_body_abx_body_posture_area_s = tostring(abx_body.abx_body.posture_area)\n| extend abx_body_abx_body_tags_s = tostring(abx_body.abx_body.tags)\n| extend abx_body_abx_body_benchmarks_s = tostring(abx_body.abx_body.benchmarks)\n| extend abx_body_abx_body_raw_event_s = tostring(abx_body.abx_body.raw_event)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL" }, { "streams": [ @@ -227,8 +227,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_ato_case_id_s = tostring(abx_body.abx_body.ato_case_id)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_compromised_account_s = tostring(abx_body.abx_body.compromised_account)\n| extend abx_body_abx_body_first_detected_t = todatetime(abx_body.abx_body.first_detected)\n| extend abx_body_abx_body_indicators_s = tostring(abx_body.abx_body.indicators)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_ATO_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_ato_case_id_s = tostring(abx_body.abx_body.ato_case_id)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_compromised_account_s = tostring(abx_body.abx_body.compromised_account)\n| extend abx_body_abx_body_first_detected_t = todatetime(abx_body.abx_body.first_detected)\n| extend abx_body_abx_body_indicators_s = tostring(abx_body.abx_body.indicators)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_ATO_CASE_V2_CL" }, { "streams": [ @@ -237,8 +237,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_remediation_id_s = tostring(abx_body.abx_body.remediation_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_threat_id_s = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_recipient_s = tostring(abx_body.abx_body.recipient)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_initiated_by_s = tostring(abx_body.abx_body.initiated_by)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_REMEDIATION_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_remediation_id_s = tostring(abx_body.abx_body.remediation_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_threat_id_s = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_recipient_s = tostring(abx_body.abx_body.recipient)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_initiated_by_s = tostring(abx_body.abx_body.initiated_by)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_REMEDIATION_V2_CL" }, { "streams": [ @@ -247,8 +247,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_vendorCaseId_g = tostring(abx_body.abx_body.vendorCaseId)\n| extend abx_body_abx_body_firstObservedTime_t = todatetime(abx_body.abx_body.firstObservedTime)\n| extend abx_body_abx_body_lastModifiedTime_t = todatetime(abx_body.abx_body.lastModifiedTime)\n| extend abx_body_abx_body_vendorDomain_s = tostring(abx_body.abx_body.vendorDomain)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_timeline_s = tostring(abx_body.abx_body.timeline)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_VENDOR_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_vendorCaseId_g = toguid(abx_body.abx_body.vendorCaseId)\n| extend abx_body_abx_body_firstObservedTime_t = todatetime(abx_body.abx_body.firstObservedTime)\n| extend abx_body_abx_body_lastModifiedTime_t = todatetime(abx_body.abx_body.lastModifiedTime)\n| extend abx_body_abx_body_vendorDomain_s = tostring(abx_body.abx_body.vendorDomain)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_timeline_s = tostring(abx_body.abx_body.timeline)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" } ] } diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_connectorDefinition.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_connectorDefinition.json index 49b87d26e5e..03198892065 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_connectorDefinition.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_connectorDefinition.json @@ -13,111 +13,111 @@ "graphQueries": [ { "metricName": "Threat Logs", - "legend": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL" + "legend": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL" }, { "metricName": "Cases", - "legend": "ABNORMAL_SECURITY_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_CASE_CL" + "legend": "ABNORMAL_SECURITY_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_CASE_V2_CL" }, { "metricName": "Audit Logs", - "legend": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL" + "legend": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL" }, { "metricName": "Abuse Mailbox", - "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" }, { "metricName": "Posture Changes", - "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL" + "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL" }, { "metricName": "ATO Cases", - "legend": "ABNORMAL_SECURITY_ATO_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_CL" + "legend": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL" }, { "metricName": "Remediations", - "legend": "ABNORMAL_SECURITY_REMEDIATION_CL", - "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_CL" + "legend": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL" }, { "metricName": "Vendor Cases", - "legend": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL" + "legend": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" }, { "metricName": "Other Events (Fallback)", - "legend": "ABNORMAL_SECURITY_LOGS_CL", - "baseQuery": "ABNORMAL_SECURITY_LOGS_CL" + "legend": "ABNORMAL_SECURITY_LOGS_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_LOGS_V2_CL" } ], "sampleQueries": [ { "description": "All Abnormal Security events across all tables", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | sort by TimeGenerated desc\n | take 100" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | sort by TimeGenerated desc\n | take 100" }, { - "description": "Threat logs by severity", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n | extend severity = tostring(abx_body.severity)\n | summarize count() by severity\n | sort by count_ desc" + "description": "Threat logs by attack type", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n | summarize count() by AttackType = abx_body_abx_body_attack_type_s\n | sort by count_ desc" }, { "description": "Cases by status (last 7 days)", - "query": "ABNORMAL_SECURITY_CASE_CL\n | where TimeGenerated > ago(7d)\n | extend status = tostring(abx_body.status)\n | summarize count() by status\n | sort by count_ desc" + "query": "ABNORMAL_SECURITY_CASE_V2_CL\n | where TimeGenerated > ago(7d)\n | summarize count() by CaseStatus = abx_body_abx_body_case_status_s\n | sort by count_ desc" }, { "description": "Event volume by type (last 24h)", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | where TimeGenerated > ago(24h)\n | extend event_type = tostring(abx_metadata.event_type)\n | summarize count() by event_type\n | order by count_ desc" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | where TimeGenerated > ago(24h)\n | summarize count() by event_type = abx_metadata_event_type_s\n | order by count_ desc" } ], "dataTypes": [ { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_LOGS_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" } ], "connectivityCriteria": [ { "type": "IsConnectedQuery", "value": [ - "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" + "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" ] } ], @@ -229,7 +229,7 @@ { "type": "Markdown", "parameters": { - "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs \u2192 `ABNORMAL_SECURITY_THREAT_LOG_CL`, cases \u2192 `ABNORMAL_SECURITY_CASE_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_CL`." + "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs \u2192 `ABNORMAL_SECURITY_THREAT_LOG_V2_CL`, cases \u2192 `ABNORMAL_SECURITY_CASE_V2_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_V2_CL`." } } ] @@ -241,7 +241,7 @@ { "type": "Markdown", "parameters": { - "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL | where TimeGenerated > ago(1h) | extend event_type = tostring(abx_metadata.event_type) | summarize count() by event_type | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." + "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL | where TimeGenerated > ago(1h) | summarize count() by event_type = abx_metadata_event_type_s | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." } } ] diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbnormalSecurityLogs.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbnormalSecurityLogs.json index 4432e42f559..20861f1ded2 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbnormalSecurityLogs.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbnormalSecurityLogs.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_LOGS_CL", + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_LOGS_CL", + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -57,7 +57,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -65,4 +65,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbuseMailbox.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbuseMailbox.json index 55d6620d28b..27d193354b5 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbuseMailbox.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AbuseMailbox.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -53,7 +53,7 @@ }, { "name": "abx_body_abx_body_campaign_id_g", - "type": "string", + "type": "guid", "description": "Abuse campaign UUID" }, { @@ -127,7 +127,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -135,4 +135,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AtoCase.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AtoCase.json index 296eac07c61..67c0df7578f 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AtoCase.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AtoCase.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -87,7 +87,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -95,4 +95,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AuditLog.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AuditLog.json index 5db0d0c8ce7..cac7bb32f4c 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AuditLog.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_AuditLog.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -107,7 +107,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -115,4 +115,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Case.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Case.json index 5aae88755cf..287ce94ffb7 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Case.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Case.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_CASE_CL", + "name": "ABNORMAL_SECURITY_CASE_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_CASE_CL", + "name": "ABNORMAL_SECURITY_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -157,7 +157,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -165,4 +165,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_PostureChange.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_PostureChange.json index 37de9202d31..156c8f5e0e6 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_PostureChange.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_PostureChange.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -132,7 +132,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -140,4 +140,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Remediation.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Remediation.json index f8f5cdc70ae..c3229232826 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Remediation.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_Remediation.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -87,7 +87,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -95,4 +95,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_ThreatLog.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_ThreatLog.json index 2a1c1820211..c3ae98acfd7 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_ThreatLog.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_ThreatLog.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,7 +38,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -58,7 +58,7 @@ }, { "name": "abx_body_abx_body_threat_id_g", - "type": "string", + "type": "guid", "description": "Threat group UUID" }, { @@ -272,7 +272,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -280,4 +280,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_VendorCase.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_VendorCase.json index 1ba9838811b..9e5939622bc 100644 --- a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_VendorCase.json +++ b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/AbnormalSecurity_table_VendorCase.json @@ -1,10 +1,10 @@ { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", "type": "Microsoft.OperationalInsights/workspaces/tables", "apiVersion": "2022-10-01", "properties": { "schema": { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -38,12 +38,12 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { "name": "abx_body_abx_body_vendorCaseId_g", - "type": "string", + "type": "guid", "description": "Vendor case UUID" }, { @@ -87,7 +87,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -95,4 +95,4 @@ ] } } -} \ No newline at end of file +} diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ABUSE_MAILBOX_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ABUSE_MAILBOX_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ATO_CASE_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ATO_CASE_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ATO_CASE_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_ATO_CASE_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_AUDIT_LOG_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_AUDIT_LOG_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_AUDIT_LOG_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_AUDIT_LOG_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_CASE_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_CASE_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_CASE_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_CASE_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_POSTURE_CHANGE_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_POSTURE_CHANGE_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_REMEDIATION_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_REMEDIATION_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_REMEDIATION_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_REMEDIATION_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_THREAT_LOG_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_THREAT_LOG_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_THREAT_LOG_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_THREAT_LOG_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_VENDOR_CASE_CL.json b/Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_VENDOR_CASE_V2_CL.json similarity index 100% rename from Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_VENDOR_CASE_CL.json rename to Solutions/AbnormalSecurity/Data Connectors/AbnormalSecurity_CCF/Sample Data/ABNORMAL_SECURITY_VENDOR_CASE_V2_CL.json diff --git a/Solutions/AbnormalSecurity/Data/Solution_AbnormalSecurity.json b/Solutions/AbnormalSecurity/Data/Solution_AbnormalSecurity.json index 2751537cd05..b95afb26344 100644 --- a/Solutions/AbnormalSecurity/Data/Solution_AbnormalSecurity.json +++ b/Solutions/AbnormalSecurity/Data/Solution_AbnormalSecurity.json @@ -41,7 +41,7 @@ "HuntingQueryBladeDescription": "This solution installs the following hunting queries. After installing the solution, run these hunting queries to hunt for threats in Manage solution view.", "PlaybooksBladeDescription": "This solution installs the following Playbook templates. After installing the solution, playbooks can be managed in the Manage solution view.", "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\AbnormalSecurity", - "Version": "3.1.0", + "Version": "3.2.0", "Metadata": "SolutionMetadata.json", "TemplateSpec": true, "Is1PConnector": false diff --git a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_AbuseMailboxCampaigns.yaml b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_AbuseMailboxCampaigns.yaml index 395c6fb75f2..b72665b0f3f 100644 --- a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_AbuseMailboxCampaigns.yaml +++ b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_AbuseMailboxCampaigns.yaml @@ -7,13 +7,13 @@ description: | requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_ABUSE_MAILBOX_CL + - ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL tactics: - InitialAccess relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_ABUSE_MAILBOX_CL + ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL | where abx_body_abx_body_reported_b == true | extend CampaignId = abx_body_abx_body_campaign_id_g, diff --git a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_NewVendorDomains.yaml b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_NewVendorDomains.yaml index d423cd3bb74..1a4b8a1e74b 100644 --- a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_NewVendorDomains.yaml +++ b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_NewVendorDomains.yaml @@ -7,13 +7,13 @@ description: | requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_VENDOR_CASE_CL + - ABNORMAL_SECURITY_VENDOR_CASE_V2_CL tactics: - InitialAccess relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_VENDOR_CASE_CL + ABNORMAL_SECURITY_VENDOR_CASE_V2_CL | extend VendorDomain = abx_body_abx_body_vendorDomain_s, VendorCaseId = abx_body_abx_body_vendorCaseId_g, diff --git a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_TopAttackTargets.yaml b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_TopAttackTargets.yaml index 01c5303e800..bd324075d66 100644 --- a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_TopAttackTargets.yaml +++ b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_TopAttackTargets.yaml @@ -7,14 +7,14 @@ description: | requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_THREAT_LOG_CL + - ABNORMAL_SECURITY_THREAT_LOG_V2_CL tactics: - InitialAccess - Reconnaissance relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_THREAT_LOG_CL + ABNORMAL_SECURITY_THREAT_LOG_V2_CL | extend RecipientEmail = abx_body_abx_body_recipient_address_s | where isnotempty(RecipientEmail) | summarize diff --git a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_UnremediatedThreats.yaml b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_UnremediatedThreats.yaml index 4be1415fcdb..a54ce93b088 100644 --- a/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_UnremediatedThreats.yaml +++ b/Solutions/AbnormalSecurity/Hunting Queries/AbnormalSecurity_UnremediatedThreats.yaml @@ -7,13 +7,13 @@ description: | requiredDataConnectors: - connectorId: AbnormalSecurityPush dataTypes: - - ABNORMAL_SECURITY_THREAT_LOG_CL + - ABNORMAL_SECURITY_THREAT_LOG_V2_CL tactics: - InitialAccess relevantTechniques: - T1566 query: | - ABNORMAL_SECURITY_THREAT_LOG_CL + ABNORMAL_SECURITY_THREAT_LOG_V2_CL | where abx_body_abx_body_auto_remediated_b == false and abx_body_abx_body_post_remediated_b == false | extend diff --git a/Solutions/AbnormalSecurity/Package/3.2.0.zip b/Solutions/AbnormalSecurity/Package/3.2.0.zip new file mode 100644 index 00000000000..5e9749b6cfa Binary files /dev/null and b/Solutions/AbnormalSecurity/Package/3.2.0.zip differ diff --git a/Solutions/AbnormalSecurity/Package/createUiDefinition.json b/Solutions/AbnormalSecurity/Package/createUiDefinition.json index 9a8878b7041..c3a766ce593 100644 --- a/Solutions/AbnormalSecurity/Package/createUiDefinition.json +++ b/Solutions/AbnormalSecurity/Package/createUiDefinition.json @@ -256,7 +256,7 @@ "name": "huntingquery1-text", "type": "Microsoft.Common.TextBlock", "options": { - "text": "Surfaces Abnormal Security threats whose remediation status indicates the message\nhas not been removed from the mailbox (not auto-remediated and not post-remediated).\nHunt for attacks that may still be reachable by recipients. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_THREAT_LOG_CL Parser or Table)" + "text": "Surfaces Abnormal Security threats whose remediation status indicates the message\nhas not been removed from the mailbox (not auto-remediated and not post-remediated).\nHunt for attacks that may still be reachable by recipients. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_THREAT_LOG_V2_CL Parser or Table)" } } ] @@ -270,7 +270,7 @@ "name": "huntingquery2-text", "type": "Microsoft.Common.TextBlock", "options": { - "text": "Aggregates Abnormal Security threats by recipient to reveal the most-targeted\nusers over the hunting window. A spike for a single recipient can indicate a\nfocused campaign against a high-value target. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_THREAT_LOG_CL Parser or Table)" + "text": "Aggregates Abnormal Security threats by recipient to reveal the most-targeted\nusers over the hunting window. A spike for a single recipient can indicate a\nfocused campaign against a high-value target. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_THREAT_LOG_V2_CL Parser or Table)" } } ] @@ -284,7 +284,7 @@ "name": "huntingquery3-text", "type": "Microsoft.Common.TextBlock", "options": { - "text": "Groups user-reported Abuse Mailbox submissions by campaign to show which reported\ncampaigns affected the most recipients. Useful to gauge the spread of a phishing\ncampaign that employees flagged. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_ABUSE_MAILBOX_CL Parser or Table)" + "text": "Groups user-reported Abuse Mailbox submissions by campaign to show which reported\ncampaigns affected the most recipients. Useful to gauge the spread of a phishing\ncampaign that employees flagged. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL Parser or Table)" } } ] @@ -298,7 +298,7 @@ "name": "huntingquery4-text", "type": "Microsoft.Common.TextBlock", "options": { - "text": "Lists vendor domains that first appear in Abnormal Security vendor cases within the\nhunting window. A newly observed vendor domain tied to a case can be an early signal\nof vendor email compromise or impersonation. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_VENDOR_CASE_CL Parser or Table)" + "text": "Lists vendor domains that first appear in Abnormal Security vendor cases within the\nhunting window. A newly observed vendor domain tied to a case can be an early signal\nof vendor email compromise or impersonation. This hunting query depends on AbnormalSecurityPush data connector (ABNORMAL_SECURITY_VENDOR_CASE_V2_CL Parser or Table)" } } ] diff --git a/Solutions/AbnormalSecurity/Package/mainTemplate.json b/Solutions/AbnormalSecurity/Package/mainTemplate.json index bac1d6fdf3e..327727ced74 100644 --- a/Solutions/AbnormalSecurity/Package/mainTemplate.json +++ b/Solutions/AbnormalSecurity/Package/mainTemplate.json @@ -55,11 +55,11 @@ "email": "support@abnormalsecurity.com", "_email": "[variables('email')]", "_solutionName": "AbnormalSecurity", - "_solutionVersion": "3.1.0", + "_solutionVersion": "3.2.0", "solutionId": "abnormalsecuritycorporation1593011233180.fe1b4806-215b-4610-bf95-965a7a65579c", "_solutionId": "[variables('solutionId')]", "workspaceResourceId": "[resourceId('microsoft.OperationalInsights/Workspaces', parameters('workspace'))]", - "dataConnectorCCPVersion": "3.1.0", + "dataConnectorCCPVersion": "3.2.0", "_dataConnectorContentIdConnectorDefinition1": "AbnormalSecurityPush", "dataConnectorTemplateNameConnectorDefinition1": "[concat(parameters('workspace'),'-dc-',uniquestring(variables('_dataConnectorContentIdConnectorDefinition1')))]", "_dataConnectorContentIdConnections1": "AbnormalSecurityPushConnections", @@ -103,32 +103,32 @@ "parserContentId4": "AbnormalSecurityVendorCases-Parser" }, "analyticRuleObject1": { - "analyticRuleVersion1": "1.0.0", + "analyticRuleVersion1": "1.0.1", "_analyticRulecontentId1": "8effd19a-abab-433a-9184-ae67ac51e6d0", "analyticRuleId1": "[resourceId('Microsoft.SecurityInsights/AlertRuleTemplates', '8effd19a-abab-433a-9184-ae67ac51e6d0')]", "analyticRuleTemplateSpecName1": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-ar-',uniquestring('8effd19a-abab-433a-9184-ae67ac51e6d0')))]", - "_analyticRulecontentProductId1": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','8effd19a-abab-433a-9184-ae67ac51e6d0','-', '1.0.0')))]" + "_analyticRulecontentProductId1": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','8effd19a-abab-433a-9184-ae67ac51e6d0','-', '1.0.1')))]" }, "analyticRuleObject2": { - "analyticRuleVersion2": "1.0.0", + "analyticRuleVersion2": "1.0.1", "_analyticRulecontentId2": "da243bf4-382b-46b9-9b4d-ce6ffe9e7beb", "analyticRuleId2": "[resourceId('Microsoft.SecurityInsights/AlertRuleTemplates', 'da243bf4-382b-46b9-9b4d-ce6ffe9e7beb')]", "analyticRuleTemplateSpecName2": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-ar-',uniquestring('da243bf4-382b-46b9-9b4d-ce6ffe9e7beb')))]", - "_analyticRulecontentProductId2": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','da243bf4-382b-46b9-9b4d-ce6ffe9e7beb','-', '1.0.0')))]" + "_analyticRulecontentProductId2": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','da243bf4-382b-46b9-9b4d-ce6ffe9e7beb','-', '1.0.1')))]" }, "analyticRuleObject3": { - "analyticRuleVersion3": "1.0.0", + "analyticRuleVersion3": "1.0.1", "_analyticRulecontentId3": "51c6ba55-fecd-4be0-9064-1aafc4d3e8d6", "analyticRuleId3": "[resourceId('Microsoft.SecurityInsights/AlertRuleTemplates', '51c6ba55-fecd-4be0-9064-1aafc4d3e8d6')]", "analyticRuleTemplateSpecName3": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-ar-',uniquestring('51c6ba55-fecd-4be0-9064-1aafc4d3e8d6')))]", - "_analyticRulecontentProductId3": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','51c6ba55-fecd-4be0-9064-1aafc4d3e8d6','-', '1.0.0')))]" + "_analyticRulecontentProductId3": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','51c6ba55-fecd-4be0-9064-1aafc4d3e8d6','-', '1.0.1')))]" }, "analyticRuleObject4": { - "analyticRuleVersion4": "1.0.0", + "analyticRuleVersion4": "1.0.1", "_analyticRulecontentId4": "b15ea4c9-58da-44d8-90e4-6591d947e7e3", "analyticRuleId4": "[resourceId('Microsoft.SecurityInsights/AlertRuleTemplates', 'b15ea4c9-58da-44d8-90e4-6591d947e7e3')]", "analyticRuleTemplateSpecName4": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-ar-',uniquestring('b15ea4c9-58da-44d8-90e4-6591d947e7e3')))]", - "_analyticRulecontentProductId4": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','b15ea4c9-58da-44d8-90e4-6591d947e7e3','-', '1.0.0')))]" + "_analyticRulecontentProductId4": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','b15ea4c9-58da-44d8-90e4-6591d947e7e3','-', '1.0.1')))]" }, "huntingQueryObject1": { "huntingQueryVersion1": "1.0.0", @@ -200,111 +200,111 @@ "graphQueries": [ { "metricName": "Threat Logs", - "legend": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL" + "legend": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL" }, { "metricName": "Cases", - "legend": "ABNORMAL_SECURITY_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_CASE_CL" + "legend": "ABNORMAL_SECURITY_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_CASE_V2_CL" }, { "metricName": "Audit Logs", - "legend": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL" + "legend": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL" }, { "metricName": "Abuse Mailbox", - "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" }, { "metricName": "Posture Changes", - "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL" + "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL" }, { "metricName": "ATO Cases", - "legend": "ABNORMAL_SECURITY_ATO_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_CL" + "legend": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL" }, { "metricName": "Remediations", - "legend": "ABNORMAL_SECURITY_REMEDIATION_CL", - "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_CL" + "legend": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL" }, { "metricName": "Vendor Cases", - "legend": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL" + "legend": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" }, { "metricName": "Other Events (Fallback)", - "legend": "ABNORMAL_SECURITY_LOGS_CL", - "baseQuery": "ABNORMAL_SECURITY_LOGS_CL" + "legend": "ABNORMAL_SECURITY_LOGS_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_LOGS_V2_CL" } ], "sampleQueries": [ { "description": "All Abnormal Security events across all tables", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | sort by TimeGenerated desc\n | take 100" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | sort by TimeGenerated desc\n | take 100" }, { - "description": "Threat logs by severity", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n | extend severity = tostring(abx_body.severity)\n | summarize count() by severity\n | sort by count_ desc" + "description": "Threat logs by attack type", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n | summarize count() by AttackType = abx_body_abx_body_attack_type_s\n | sort by count_ desc" }, { "description": "Cases by status (last 7 days)", - "query": "ABNORMAL_SECURITY_CASE_CL\n | where TimeGenerated > ago(7d)\n | extend status = tostring(abx_body.status)\n | summarize count() by status\n | sort by count_ desc" + "query": "ABNORMAL_SECURITY_CASE_V2_CL\n | where TimeGenerated > ago(7d)\n | summarize count() by CaseStatus = abx_body_abx_body_case_status_s\n | sort by count_ desc" }, { "description": "Event volume by type (last 24h)", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | where TimeGenerated > ago(24h)\n | extend event_type = tostring(abx_metadata.event_type)\n | summarize count() by event_type\n | order by count_ desc" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | where TimeGenerated > ago(24h)\n | summarize count() by event_type = abx_metadata_event_type_s\n | order by count_ desc" } ], "dataTypes": [ { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_LOGS_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" } ], "connectivityCriteria": [ { "type": "IsConnectedQuery", "value": [ - "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" + "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" ] } ], @@ -416,7 +416,7 @@ { "type": "Markdown", "parameters": { - "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs → `ABNORMAL_SECURITY_THREAT_LOG_CL`, cases → `ABNORMAL_SECURITY_CASE_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_CL`." + "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs → `ABNORMAL_SECURITY_THREAT_LOG_V2_CL`, cases → `ABNORMAL_SECURITY_CASE_V2_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_V2_CL`." } } ] @@ -428,7 +428,7 @@ { "type": "Markdown", "parameters": { - "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL | where TimeGenerated > ago(1h) | extend event_type = tostring(abx_metadata.event_type) | summarize count() by event_type | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." + "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL | where TimeGenerated > ago(1h) | summarize count() by event_type = abx_metadata_event_type_s | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." } } ] @@ -641,8 +641,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_LOGS_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_LOGS_V2_CL" }, { "streams": [ @@ -651,8 +651,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_abx_message_id_d = toreal(abx_body.abx_body.abx_message_id)\n| extend abx_body_abx_body_abx_message_id_str_s = tostring(abx_body.abx_body.abx_message_id_str)\n| extend abx_body_abx_body_abx_portal_url_s = tostring(abx_body.abx_body.abx_portal_url)\n| extend abx_body_abx_body_threat_id_g = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_from_name_s = tostring(abx_body.abx_body.from_name)\n| extend abx_body_abx_body_from_address_s = tostring(abx_body.abx_body.from_address)\n| extend abx_body_abx_body_to_addresses_s = tostring(abx_body.abx_body.to_addresses)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_received_time_t = todatetime(abx_body.abx_body.received_time)\n| extend abx_body_abx_body_sent_time_t = todatetime(abx_body.abx_body.sent_time)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_auto_remediated_b = tobool(abx_body.abx_body.auto_remediated)\n| extend abx_body_abx_body_post_remediated_b = tobool(abx_body.abx_body.post_remediated)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_remediation_timestamp_t = todatetime(abx_body.abx_body.remediation_timestamp)\n| extend abx_body_abx_body_attack_type_s = tostring(abx_body.abx_body.attack_type)\n| extend abx_body_abx_body_attack_strategy_s = tostring(abx_body.abx_body.attack_strategy)\n| extend abx_body_abx_body_attack_vector_s = tostring(abx_body.abx_body.attack_vector)\n| extend abx_body_abx_body_attack_score_d = toreal(abx_body.abx_body.attack_score)\n| extend abx_body_abx_body_attacked_party_s = tostring(abx_body.abx_body.attacked_party)\n| extend abx_body_abx_body_return_path_s = tostring(abx_body.abx_body.return_path)\n| extend abx_body_abx_body_reply_to_emails_s = tostring(abx_body.abx_body.reply_to_emails)\n| extend abx_body_abx_body_cc_emails_s = tostring(abx_body.abx_body.cc_emails)\n| extend abx_body_abx_body_bcc_emails_s = tostring(abx_body.abx_body.bcc_emails)\n| extend abx_body_abx_body_sender_ip_address_s = tostring(abx_body.abx_body.sender_ip_address)\n| extend abx_body_abx_body_sender_domain_s = tostring(abx_body.abx_body.sender_domain)\n| extend abx_body_abx_body_sender_auth_results_spf_s = tostring(abx_body.abx_body.sender_auth_results.spf)\n| extend abx_body_abx_body_sender_auth_results_dkim_s = tostring(abx_body.abx_body.sender_auth_results.dkim)\n| extend abx_body_abx_body_sender_auth_results_dmarc_s = tostring(abx_body.abx_body.sender_auth_results.dmarc)\n| extend abx_body_abx_body_impersonated_party_s = tostring(abx_body.abx_body.impersonated_party)\n| extend abx_body_abx_body_attachment_names_s = tostring(abx_body.abx_body.attachment_names)\n| extend abx_body_abx_body_attachment_count_d = toreal(abx_body.abx_body.attachment_count)\n| extend abx_body_abx_body_attachment_analysis_s = tostring(abx_body.abx_body.attachment_analysis)\n| extend abx_body_abx_body_urls_s = tostring(abx_body.abx_body.urls)\n| extend abx_body_abx_body_url_count_d = toreal(abx_body.abx_body.url_count)\n| extend abx_body_abx_body_summary_insights_s = tostring(abx_body.abx_body.summary_insights)\n| extend abx_body_abx_body_is_read_b = tobool(abx_body.abx_body.is_read)\n| extend abx_body_abx_body_folder_locations_s = tostring(abx_body.abx_body.folder_locations)\n| extend abx_body_abx_body_message_sources_s = tostring(abx_body.abx_body.message_sources)\n| extend abx_body_abx_body_message_engagement_s = tostring(abx_body.abx_body.message_engagement)\n| extend abx_body_abx_body_source_s = tostring(abx_body.abx_body.source)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_THREAT_LOG_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_abx_message_id_d = toreal(abx_body.abx_body.abx_message_id)\n| extend abx_body_abx_body_abx_message_id_str_s = tostring(abx_body.abx_body.abx_message_id_str)\n| extend abx_body_abx_body_abx_portal_url_s = tostring(abx_body.abx_body.abx_portal_url)\n| extend abx_body_abx_body_threat_id_g = toguid(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_from_name_s = tostring(abx_body.abx_body.from_name)\n| extend abx_body_abx_body_from_address_s = tostring(abx_body.abx_body.from_address)\n| extend abx_body_abx_body_to_addresses_s = tostring(abx_body.abx_body.to_addresses)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_received_time_t = todatetime(abx_body.abx_body.received_time)\n| extend abx_body_abx_body_sent_time_t = todatetime(abx_body.abx_body.sent_time)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_auto_remediated_b = tobool(abx_body.abx_body.auto_remediated)\n| extend abx_body_abx_body_post_remediated_b = tobool(abx_body.abx_body.post_remediated)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_remediation_timestamp_t = todatetime(abx_body.abx_body.remediation_timestamp)\n| extend abx_body_abx_body_attack_type_s = tostring(abx_body.abx_body.attack_type)\n| extend abx_body_abx_body_attack_strategy_s = tostring(abx_body.abx_body.attack_strategy)\n| extend abx_body_abx_body_attack_vector_s = tostring(abx_body.abx_body.attack_vector)\n| extend abx_body_abx_body_attack_score_d = toreal(abx_body.abx_body.attack_score)\n| extend abx_body_abx_body_attacked_party_s = tostring(abx_body.abx_body.attacked_party)\n| extend abx_body_abx_body_return_path_s = tostring(abx_body.abx_body.return_path)\n| extend abx_body_abx_body_reply_to_emails_s = tostring(abx_body.abx_body.reply_to_emails)\n| extend abx_body_abx_body_cc_emails_s = tostring(abx_body.abx_body.cc_emails)\n| extend abx_body_abx_body_bcc_emails_s = tostring(abx_body.abx_body.bcc_emails)\n| extend abx_body_abx_body_sender_ip_address_s = tostring(abx_body.abx_body.sender_ip_address)\n| extend abx_body_abx_body_sender_domain_s = tostring(abx_body.abx_body.sender_domain)\n| extend abx_body_abx_body_sender_auth_results_spf_s = tostring(abx_body.abx_body.sender_auth_results.spf)\n| extend abx_body_abx_body_sender_auth_results_dkim_s = tostring(abx_body.abx_body.sender_auth_results.dkim)\n| extend abx_body_abx_body_sender_auth_results_dmarc_s = tostring(abx_body.abx_body.sender_auth_results.dmarc)\n| extend abx_body_abx_body_impersonated_party_s = tostring(abx_body.abx_body.impersonated_party)\n| extend abx_body_abx_body_attachment_names_s = tostring(abx_body.abx_body.attachment_names)\n| extend abx_body_abx_body_attachment_count_d = toreal(abx_body.abx_body.attachment_count)\n| extend abx_body_abx_body_attachment_analysis_s = tostring(abx_body.abx_body.attachment_analysis)\n| extend abx_body_abx_body_urls_s = tostring(abx_body.abx_body.urls)\n| extend abx_body_abx_body_url_count_d = toreal(abx_body.abx_body.url_count)\n| extend abx_body_abx_body_summary_insights_s = tostring(abx_body.abx_body.summary_insights)\n| extend abx_body_abx_body_is_read_b = tobool(abx_body.abx_body.is_read)\n| extend abx_body_abx_body_folder_locations_s = tostring(abx_body.abx_body.folder_locations)\n| extend abx_body_abx_body_message_sources_s = tostring(abx_body.abx_body.message_sources)\n| extend abx_body_abx_body_message_engagement_s = tostring(abx_body.abx_body.message_engagement)\n| extend abx_body_abx_body_source_s = tostring(abx_body.abx_body.source)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_THREAT_LOG_V2_CL" }, { "streams": [ @@ -661,8 +661,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_schema_version_s = tostring(abx_body.abx_body.schema_version)\n| extend abx_body_abx_body_case_id_d = toreal(abx_body.abx_body.case_id)\n| extend abx_body_abx_body_customer_d = toreal(abx_body.abx_body.customer)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_body_first_observed_t = todatetime(abx_body.abx_body.first_observed)\n| extend abx_body_abx_body_date_created_t = todatetime(abx_body.abx_body.date_created)\n| extend abx_body_abx_body_first_customer_visible_time_t = todatetime(abx_body.abx_body.first_customer_visible_time)\n| extend abx_body_abx_body_trigger_event_s = tostring(abx_body.abx_body.trigger_event)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_confidence_s = tostring(abx_body.abx_body.confidence)\n| extend abx_body_abx_body_case_status_s = tostring(abx_body.abx_body.case_status)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_entity_entity_type_s = tostring(abx_body.abx_body.entity.entity_type)\n| extend abx_body_abx_body_entity_identifier_s = tostring(abx_body.abx_body.entity.identifier)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_genai_summary_s = tostring(abx_body.abx_body.genai_summary)\n| extend abx_body_abx_body_event_timeline_s = tostring(abx_body.abx_body.event_timeline)\n| extend abx_body_abx_body_platforms_s = tostring(abx_body.abx_body.platforms)\n| extend abx_body_abx_body_event_type_s = tostring(abx_body.abx_body.event_type)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_schema_version_s = tostring(abx_body.abx_body.schema_version)\n| extend abx_body_abx_body_case_id_d = toreal(abx_body.abx_body.case_id)\n| extend abx_body_abx_body_customer_d = toreal(abx_body.abx_body.customer)\n| extend abx_body_abx_body_tenant_s = tostring(abx_body.abx_body.tenant)\n| extend abx_body_abx_body_first_observed_t = todatetime(abx_body.abx_body.first_observed)\n| extend abx_body_abx_body_date_created_t = todatetime(abx_body.abx_body.date_created)\n| extend abx_body_abx_body_first_customer_visible_time_t = todatetime(abx_body.abx_body.first_customer_visible_time)\n| extend abx_body_abx_body_trigger_event_s = tostring(abx_body.abx_body.trigger_event)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_confidence_s = tostring(abx_body.abx_body.confidence)\n| extend abx_body_abx_body_case_status_s = tostring(abx_body.abx_body.case_status)\n| extend abx_body_abx_body_remediation_status_s = tostring(abx_body.abx_body.remediation_status)\n| extend abx_body_abx_body_entity_entity_type_s = tostring(abx_body.abx_body.entity.entity_type)\n| extend abx_body_abx_body_entity_identifier_s = tostring(abx_body.abx_body.entity.identifier)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_genai_summary_s = tostring(abx_body.abx_body.genai_summary)\n| extend abx_body_abx_body_event_timeline_s = tostring(abx_body.abx_body.event_timeline)\n| extend abx_body_abx_body_platforms_s = tostring(abx_body.abx_body.platforms)\n| extend abx_body_abx_body_event_type_s = tostring(abx_body.abx_body.event_type)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_CASE_V2_CL" }, { "streams": [ @@ -671,8 +671,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_audit_type_s = tostring(abx_body.abx_body.audit_type)\n| extend abx_body_abx_body_audit_subtype_s = tostring(abx_body.abx_body.audit_subtype)\n| extend abx_body_abx_body_category_s = tostring(abx_body.abx_body.category)\n| extend abx_body_abx_body_details_s = tostring(abx_body.abx_body.details)\n| extend abx_body_abx_body_source_ip_s = tostring(abx_body.abx_body.source_ip)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_tenant_name_s = tostring(abx_body.abx_body.tenant_name)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_user_email_s = tostring(abx_body.abx_body.user.email)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_AUDIT_LOG_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_audit_type_s = tostring(abx_body.abx_body.audit_type)\n| extend abx_body_abx_body_audit_subtype_s = tostring(abx_body.abx_body.audit_subtype)\n| extend abx_body_abx_body_category_s = tostring(abx_body.abx_body.category)\n| extend abx_body_abx_body_details_s = tostring(abx_body.abx_body.details)\n| extend abx_body_abx_body_source_ip_s = tostring(abx_body.abx_body.source_ip)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_tenant_name_s = tostring(abx_body.abx_body.tenant_name)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_user_email_s = tostring(abx_body.abx_body.user.email)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_AUDIT_LOG_V2_CL" }, { "streams": [ @@ -681,8 +681,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_not_analyzed_b = tobool(abx_body.abx_body.not_analyzed)\n| extend abx_body_abx_body_reason_for_no_analysis_s = tostring(abx_body.abx_body.reason_for_no_analysis)\n| extend abx_body_abx_body_campaign_id_g = tostring(abx_body.abx_body.campaign_id)\n| extend abx_body_abx_body_abnormal_message_id_d = toreal(abx_body.abx_body.abnormal_message_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_reported_b = tobool(abx_body.abx_body.reported)\n| extend abx_body_abx_body_message_reported_time_s = tostring(abx_body.abx_body.message_reported_time)\n| extend abx_body_abx_body_reporter_name_s = tostring(abx_body.abx_body.reporter_name)\n| extend abx_body_abx_body_reporter_address_s = tostring(abx_body.abx_body.reporter_address)\n| extend abx_body_abx_body_judgement_s = tostring(abx_body.abx_body.judgement)\n| extend abx_body_abx_body_recipient_name_s = tostring(abx_body.abx_body.recipient_name)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_email_label_or_location_s = tostring(abx_body.abx_body.email_label_or_location)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_not_analyzed_b = tobool(abx_body.abx_body.not_analyzed)\n| extend abx_body_abx_body_reason_for_no_analysis_s = tostring(abx_body.abx_body.reason_for_no_analysis)\n| extend abx_body_abx_body_campaign_id_g = toguid(abx_body.abx_body.campaign_id)\n| extend abx_body_abx_body_abnormal_message_id_d = toreal(abx_body.abx_body.abnormal_message_id)\n| extend abx_body_abx_body_subject_s = tostring(abx_body.abx_body.subject)\n| extend abx_body_abx_body_reported_b = tobool(abx_body.abx_body.reported)\n| extend abx_body_abx_body_message_reported_time_s = tostring(abx_body.abx_body.message_reported_time)\n| extend abx_body_abx_body_reporter_name_s = tostring(abx_body.abx_body.reporter_name)\n| extend abx_body_abx_body_reporter_address_s = tostring(abx_body.abx_body.reporter_address)\n| extend abx_body_abx_body_judgement_s = tostring(abx_body.abx_body.judgement)\n| extend abx_body_abx_body_recipient_name_s = tostring(abx_body.abx_body.recipient_name)\n| extend abx_body_abx_body_recipient_address_s = tostring(abx_body.abx_body.recipient_address)\n| extend abx_body_abx_body_internet_message_id_s = tostring(abx_body.abx_body.internet_message_id)\n| extend abx_body_abx_body_email_label_or_location_s = tostring(abx_body.abx_body.email_label_or_location)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" }, { "streams": [ @@ -691,8 +691,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_type_s = tostring(abx_body.abx_body.type)\n| extend abx_body_abx_body_event_id_s = tostring(abx_body.abx_body.event_id)\n| extend abx_body_abx_body_tenant_id_d = toreal(abx_body.abx_body.tenant_id)\n| extend abx_body_abx_body_posture_id_s = tostring(abx_body.abx_body.posture_id)\n| extend abx_body_abx_body_posture_name_s = tostring(abx_body.abx_body.posture_name)\n| extend abx_body_abx_body_posture_category_s = tostring(abx_body.abx_body.posture_category)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_workflow_status_s = tostring(abx_body.abx_body.workflow_status)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_platform_type_s = tostring(abx_body.abx_body.platform_type)\n| extend abx_body_abx_body_posture_area_s = tostring(abx_body.abx_body.posture_area)\n| extend abx_body_abx_body_tags_s = tostring(abx_body.abx_body.tags)\n| extend abx_body_abx_body_benchmarks_s = tostring(abx_body.abx_body.benchmarks)\n| extend abx_body_abx_body_raw_event_s = tostring(abx_body.abx_body.raw_event)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_POSTURE_CHANGE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_type_s = tostring(abx_body.abx_body.type)\n| extend abx_body_abx_body_event_id_s = tostring(abx_body.abx_body.event_id)\n| extend abx_body_abx_body_tenant_id_d = toreal(abx_body.abx_body.tenant_id)\n| extend abx_body_abx_body_posture_id_s = tostring(abx_body.abx_body.posture_id)\n| extend abx_body_abx_body_posture_name_s = tostring(abx_body.abx_body.posture_name)\n| extend abx_body_abx_body_posture_category_s = tostring(abx_body.abx_body.posture_category)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_workflow_status_s = tostring(abx_body.abx_body.workflow_status)\n| extend abx_body_abx_body_timestamp_t = todatetime(abx_body.abx_body.timestamp)\n| extend abx_body_abx_body_description_s = tostring(abx_body.abx_body.description)\n| extend abx_body_abx_body_platform_type_s = tostring(abx_body.abx_body.platform_type)\n| extend abx_body_abx_body_posture_area_s = tostring(abx_body.abx_body.posture_area)\n| extend abx_body_abx_body_tags_s = tostring(abx_body.abx_body.tags)\n| extend abx_body_abx_body_benchmarks_s = tostring(abx_body.abx_body.benchmarks)\n| extend abx_body_abx_body_raw_event_s = tostring(abx_body.abx_body.raw_event)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL" }, { "streams": [ @@ -701,8 +701,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_ato_case_id_s = tostring(abx_body.abx_body.ato_case_id)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_compromised_account_s = tostring(abx_body.abx_body.compromised_account)\n| extend abx_body_abx_body_first_detected_t = todatetime(abx_body.abx_body.first_detected)\n| extend abx_body_abx_body_indicators_s = tostring(abx_body.abx_body.indicators)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_ATO_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_ato_case_id_s = tostring(abx_body.abx_body.ato_case_id)\n| extend abx_body_abx_body_severity_s = tostring(abx_body.abx_body.severity)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_compromised_account_s = tostring(abx_body.abx_body.compromised_account)\n| extend abx_body_abx_body_first_detected_t = todatetime(abx_body.abx_body.first_detected)\n| extend abx_body_abx_body_indicators_s = tostring(abx_body.abx_body.indicators)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_ATO_CASE_V2_CL" }, { "streams": [ @@ -711,8 +711,8 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_remediation_id_s = tostring(abx_body.abx_body.remediation_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_threat_id_s = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_recipient_s = tostring(abx_body.abx_body.recipient)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_initiated_by_s = tostring(abx_body.abx_body.initiated_by)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_REMEDIATION_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_remediation_id_s = tostring(abx_body.abx_body.remediation_id)\n| extend abx_body_abx_body_action_s = tostring(abx_body.abx_body.action)\n| extend abx_body_abx_body_threat_id_s = tostring(abx_body.abx_body.threat_id)\n| extend abx_body_abx_body_recipient_s = tostring(abx_body.abx_body.recipient)\n| extend abx_body_abx_body_status_s = tostring(abx_body.abx_body.status)\n| extend abx_body_abx_body_initiated_by_s = tostring(abx_body.abx_body.initiated_by)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_REMEDIATION_V2_CL" }, { "streams": [ @@ -721,21 +721,21 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = tostring(abx_metadata.trace_id)\n| extend abx_body_abx_body_vendorCaseId_g = tostring(abx_body.abx_body.vendorCaseId)\n| extend abx_body_abx_body_firstObservedTime_t = todatetime(abx_body.abx_body.firstObservedTime)\n| extend abx_body_abx_body_lastModifiedTime_t = todatetime(abx_body.abx_body.lastModifiedTime)\n| extend abx_body_abx_body_vendorDomain_s = tostring(abx_body.abx_body.vendorDomain)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_timeline_s = tostring(abx_body.abx_body.timeline)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = tostring(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", - "outputStream": "Custom-ABNORMAL_SECURITY_VENDOR_CASE_CL" + "transformKql": "source | extend TimeGenerated = todatetime(Time)\n| extend abx_metadata_event_type_s = tostring(abx_metadata.event_type)\n| extend abx_metadata_timestamp_s = tostring(abx_metadata.timestamp)\n| extend abx_metadata_trace_id_g = toguid(abx_metadata.trace_id)\n| extend abx_body_abx_body_vendorCaseId_g = toguid(abx_body.abx_body.vendorCaseId)\n| extend abx_body_abx_body_firstObservedTime_t = todatetime(abx_body.abx_body.firstObservedTime)\n| extend abx_body_abx_body_lastModifiedTime_t = todatetime(abx_body.abx_body.lastModifiedTime)\n| extend abx_body_abx_body_vendorDomain_s = tostring(abx_body.abx_body.vendorDomain)\n| extend abx_body_abx_body_insights_s = tostring(abx_body.abx_body.insights)\n| extend abx_body_abx_body_timeline_s = tostring(abx_body.abx_body.timeline)\n| extend abx_body_abx_metadata_event_type_s = tostring(abx_body.abx_metadata.event_type)\n| extend abx_body_abx_metadata_timestamp_s = tostring(abx_body.abx_metadata.timestamp)\n| extend abx_body_abx_metadata_trace_id_g = toguid(abx_body.abx_metadata.trace_id)\n| extend abx_body = tostring(abx_body)\n| extend abx_metadata = tostring(abx_metadata)", + "outputStream": "Custom-ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" } ] } }, { - "name": "ABNORMAL_SECURITY_LOGS_CL", + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_LOGS_CL", + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -769,7 +769,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -788,7 +788,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -798,14 +798,14 @@ } }, { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -839,7 +839,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -854,7 +854,7 @@ }, { "name": "abx_body_abx_body_campaign_id_g", - "type": "string", + "type": "guid", "description": "Abuse campaign UUID" }, { @@ -928,7 +928,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -938,14 +938,14 @@ } }, { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -979,7 +979,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1028,7 +1028,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1038,14 +1038,14 @@ } }, { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1079,7 +1079,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1148,7 +1148,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1158,14 +1158,14 @@ } }, { - "name": "ABNORMAL_SECURITY_CASE_CL", + "name": "ABNORMAL_SECURITY_CASE_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_CASE_CL", + "name": "ABNORMAL_SECURITY_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1199,7 +1199,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1318,7 +1318,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1328,14 +1328,14 @@ } }, { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1369,7 +1369,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1463,7 +1463,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1473,14 +1473,14 @@ } }, { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1514,7 +1514,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1563,7 +1563,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1573,14 +1573,14 @@ } }, { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1614,7 +1614,7 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { @@ -1634,7 +1634,7 @@ }, { "name": "abx_body_abx_body_threat_id_g", - "type": "string", + "type": "guid", "description": "Threat group UUID" }, { @@ -1848,7 +1848,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1858,14 +1858,14 @@ } }, { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/tables", "location": "[parameters('workspace-location')]", "kind": null, "properties": { "schema": { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", "columns": [ { "name": "TimeGenerated", @@ -1899,12 +1899,12 @@ }, { "name": "abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "description": "Trace ID (GUID) from top-level abx_metadata" }, { "name": "abx_body_abx_body_vendorCaseId_g", - "type": "string", + "type": "guid", "description": "Vendor case UUID" }, { @@ -1948,7 +1948,7 @@ }, { "name": "abx_body_abx_metadata_trace_id_g", - "type": "string", + "type": "guid", "isDefaultDisplay": false, "isHidden": false, "description": "From abx_body.abx_metadata" @@ -1983,111 +1983,111 @@ "graphQueries": [ { "metricName": "Threat Logs", - "legend": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL" + "legend": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL" }, { "metricName": "Cases", - "legend": "ABNORMAL_SECURITY_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_CASE_CL" + "legend": "ABNORMAL_SECURITY_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_CASE_V2_CL" }, { "metricName": "Audit Logs", - "legend": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL" + "legend": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL" }, { "metricName": "Abuse Mailbox", - "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "legend": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" }, { "metricName": "Posture Changes", - "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL" + "legend": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL" }, { "metricName": "ATO Cases", - "legend": "ABNORMAL_SECURITY_ATO_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_CL" + "legend": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL" }, { "metricName": "Remediations", - "legend": "ABNORMAL_SECURITY_REMEDIATION_CL", - "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_CL" + "legend": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL" }, { "metricName": "Vendor Cases", - "legend": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL" + "legend": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" }, { "metricName": "Other Events (Fallback)", - "legend": "ABNORMAL_SECURITY_LOGS_CL", - "baseQuery": "ABNORMAL_SECURITY_LOGS_CL" + "legend": "ABNORMAL_SECURITY_LOGS_V2_CL", + "baseQuery": "ABNORMAL_SECURITY_LOGS_V2_CL" } ], "sampleQueries": [ { "description": "All Abnormal Security events across all tables", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | sort by TimeGenerated desc\n | take 100" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | sort by TimeGenerated desc\n | take 100" }, { - "description": "Threat logs by severity", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n | extend severity = tostring(abx_body.severity)\n | summarize count() by severity\n | sort by count_ desc" + "description": "Threat logs by attack type", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n | summarize count() by AttackType = abx_body_abx_body_attack_type_s\n | sort by count_ desc" }, { "description": "Cases by status (last 7 days)", - "query": "ABNORMAL_SECURITY_CASE_CL\n | where TimeGenerated > ago(7d)\n | extend status = tostring(abx_body.status)\n | summarize count() by status\n | sort by count_ desc" + "query": "ABNORMAL_SECURITY_CASE_V2_CL\n | where TimeGenerated > ago(7d)\n | summarize count() by CaseStatus = abx_body_abx_body_case_status_s\n | sort by count_ desc" }, { "description": "Event volume by type (last 24h)", - "query": "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n | where TimeGenerated > ago(24h)\n | extend event_type = tostring(abx_metadata.event_type)\n | summarize count() by event_type\n | order by count_ desc" + "query": "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n | where TimeGenerated > ago(24h)\n | summarize count() by event_type = abx_metadata_event_type_s\n | order by count_ desc" } ], "dataTypes": [ { - "name": "ABNORMAL_SECURITY_THREAT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_AUDIT_LOG_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_AUDIT_LOG_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_ATO_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_REMEDIATION_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_REMEDIATION_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_REMEDIATION_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_VENDOR_CASE_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" }, { - "name": "ABNORMAL_SECURITY_LOGS_CL", - "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" + "name": "ABNORMAL_SECURITY_LOGS_V2_CL", + "lastDataReceivedQuery": "ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize Time = max(TimeGenerated)\n| where isnotempty(Time)" } ], "connectivityCriteria": [ { "type": "IsConnectedQuery", "value": [ - "union ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" + "union ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL\n| summarize LastLogReceived = max(TimeGenerated)\n| project IsConnected = LastLogReceived > ago(7d)" ] } ], @@ -2199,7 +2199,7 @@ { "type": "Markdown", "parameters": { - "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs → `ABNORMAL_SECURITY_THREAT_LOG_CL`, cases → `ABNORMAL_SECURITY_CASE_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_CL`." + "content": "#### Configure in Abnormal Security Portal\n1. Log in to [Abnormal Security Portal](https://portal.abnormalsecurity.com)\n2. Navigate to **Settings > Integrations > SIEM**\n3. Select **Microsoft Sentinel (Azure Monitor CCF)**\n4. Enter all 7 values from above\n5. Click **Verify Credentials** to test the connection\n6. Click **Save** and **Enable** the integration\n\n**Multi-table routing:** Events are automatically routed to per-event-type tables (e.g., threat logs → `ABNORMAL_SECURITY_THREAT_LOG_V2_CL`, cases → `ABNORMAL_SECURITY_CASE_V2_CL`). Unknown event types go to the fallback table `ABNORMAL_SECURITY_LOGS_V2_CL`." } } ] @@ -2211,7 +2211,7 @@ { "type": "Markdown", "parameters": { - "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_CL, ABNORMAL_SECURITY_CASE_CL, ABNORMAL_SECURITY_AUDIT_LOG_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_CL, ABNORMAL_SECURITY_ATO_CASE_CL, ABNORMAL_SECURITY_REMEDIATION_CL, ABNORMAL_SECURITY_VENDOR_CASE_CL, ABNORMAL_SECURITY_LOGS_CL | where TimeGenerated > ago(1h) | extend event_type = tostring(abx_metadata.event_type) | summarize count() by event_type | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." + "content": "Wait 5-10 minutes after enabling the integration, then run this KQL query:\n\nunion ABNORMAL_SECURITY_THREAT_LOG_V2_CL, ABNORMAL_SECURITY_CASE_V2_CL, ABNORMAL_SECURITY_AUDIT_LOG_V2_CL, ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL, ABNORMAL_SECURITY_POSTURE_CHANGE_V2_CL, ABNORMAL_SECURITY_ATO_CASE_V2_CL, ABNORMAL_SECURITY_REMEDIATION_V2_CL, ABNORMAL_SECURITY_VENDOR_CASE_V2_CL, ABNORMAL_SECURITY_LOGS_V2_CL | where TimeGenerated > ago(1h) | summarize count() by event_type = abx_metadata_event_type_s | order by count_ desc\n\nIf no data appears after 15 minutes, verify credentials in the Abnormal Security Portal and check Azure Monitor for ingestion errors." } } ] @@ -2379,7 +2379,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity data connector with template version 3.1.0", + "description": "AbnormalSecurity data connector with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('dataConnectorVersion2')]", @@ -2769,7 +2769,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurityThreatLog Data Parser with template version 3.1.0", + "description": "AbnormalSecurityThreatLog Data Parser with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('parserObject1').parserVersion1]", @@ -2786,7 +2786,7 @@ "displayName": "Parser for Abnormal Security Threat Log", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityThreatLog", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| project\n TimeGenerated,\n ThreatId = abx_body_abx_body_threat_id_g,\n MessageId = abx_body_abx_body_abx_message_id_str_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n Subject = abx_body_abx_body_subject_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderAddress = abx_body_abx_body_from_address_s,\n SenderDomain = abx_body_abx_body_sender_domain_s,\n SenderIpAddress = abx_body_abx_body_sender_ip_address_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n ToAddresses = abx_body_abx_body_to_addresses_s,\n ReceivedTime = abx_body_abx_body_received_time_t,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackStrategy = abx_body_abx_body_attack_strategy_s,\n AttackVector = abx_body_abx_body_attack_vector_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n AttackedParty = abx_body_abx_body_attacked_party_s,\n ImpersonatedParty = abx_body_abx_body_impersonated_party_s,\n AutoRemediated = abx_body_abx_body_auto_remediated_b,\n PostRemediated = abx_body_abx_body_post_remediated_b,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n RemediationTimestamp = abx_body_abx_body_remediation_timestamp_t,\n SpfResult = abx_body_abx_body_sender_auth_results_spf_s,\n DkimResult = abx_body_abx_body_sender_auth_results_dkim_s,\n DmarcResult = abx_body_abx_body_sender_auth_results_dmarc_s,\n Urls = abx_body_abx_body_urls_s,\n UrlCount = abx_body_abx_body_url_count_d,\n AttachmentNames = abx_body_abx_body_attachment_names_s,\n AttachmentCount = abx_body_abx_body_attachment_count_d,\n SummaryInsights = abx_body_abx_body_summary_insights_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| project\n TimeGenerated,\n ThreatId = abx_body_abx_body_threat_id_g,\n MessageId = abx_body_abx_body_abx_message_id_str_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n Subject = abx_body_abx_body_subject_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderAddress = abx_body_abx_body_from_address_s,\n SenderDomain = abx_body_abx_body_sender_domain_s,\n SenderIpAddress = abx_body_abx_body_sender_ip_address_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n ToAddresses = abx_body_abx_body_to_addresses_s,\n ReceivedTime = abx_body_abx_body_received_time_t,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackStrategy = abx_body_abx_body_attack_strategy_s,\n AttackVector = abx_body_abx_body_attack_vector_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n AttackedParty = abx_body_abx_body_attacked_party_s,\n ImpersonatedParty = abx_body_abx_body_impersonated_party_s,\n AutoRemediated = abx_body_abx_body_auto_remediated_b,\n PostRemediated = abx_body_abx_body_post_remediated_b,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n RemediationTimestamp = abx_body_abx_body_remediation_timestamp_t,\n SpfResult = abx_body_abx_body_sender_auth_results_spf_s,\n DkimResult = abx_body_abx_body_sender_auth_results_dkim_s,\n DmarcResult = abx_body_abx_body_sender_auth_results_dmarc_s,\n Urls = abx_body_abx_body_urls_s,\n UrlCount = abx_body_abx_body_url_count_d,\n AttachmentNames = abx_body_abx_body_attachment_names_s,\n AttachmentCount = abx_body_abx_body_attachment_count_d,\n SummaryInsights = abx_body_abx_body_summary_insights_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -2850,7 +2850,7 @@ "displayName": "Parser for Abnormal Security Threat Log", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityThreatLog", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| project\n TimeGenerated,\n ThreatId = abx_body_abx_body_threat_id_g,\n MessageId = abx_body_abx_body_abx_message_id_str_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n Subject = abx_body_abx_body_subject_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderAddress = abx_body_abx_body_from_address_s,\n SenderDomain = abx_body_abx_body_sender_domain_s,\n SenderIpAddress = abx_body_abx_body_sender_ip_address_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n ToAddresses = abx_body_abx_body_to_addresses_s,\n ReceivedTime = abx_body_abx_body_received_time_t,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackStrategy = abx_body_abx_body_attack_strategy_s,\n AttackVector = abx_body_abx_body_attack_vector_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n AttackedParty = abx_body_abx_body_attacked_party_s,\n ImpersonatedParty = abx_body_abx_body_impersonated_party_s,\n AutoRemediated = abx_body_abx_body_auto_remediated_b,\n PostRemediated = abx_body_abx_body_post_remediated_b,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n RemediationTimestamp = abx_body_abx_body_remediation_timestamp_t,\n SpfResult = abx_body_abx_body_sender_auth_results_spf_s,\n DkimResult = abx_body_abx_body_sender_auth_results_dkim_s,\n DmarcResult = abx_body_abx_body_sender_auth_results_dmarc_s,\n Urls = abx_body_abx_body_urls_s,\n UrlCount = abx_body_abx_body_url_count_d,\n AttachmentNames = abx_body_abx_body_attachment_names_s,\n AttachmentCount = abx_body_abx_body_attachment_count_d,\n SummaryInsights = abx_body_abx_body_summary_insights_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| project\n TimeGenerated,\n ThreatId = abx_body_abx_body_threat_id_g,\n MessageId = abx_body_abx_body_abx_message_id_str_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n Subject = abx_body_abx_body_subject_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderAddress = abx_body_abx_body_from_address_s,\n SenderDomain = abx_body_abx_body_sender_domain_s,\n SenderIpAddress = abx_body_abx_body_sender_ip_address_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n ToAddresses = abx_body_abx_body_to_addresses_s,\n ReceivedTime = abx_body_abx_body_received_time_t,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackStrategy = abx_body_abx_body_attack_strategy_s,\n AttackVector = abx_body_abx_body_attack_vector_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n AttackedParty = abx_body_abx_body_attacked_party_s,\n ImpersonatedParty = abx_body_abx_body_impersonated_party_s,\n AutoRemediated = abx_body_abx_body_auto_remediated_b,\n PostRemediated = abx_body_abx_body_post_remediated_b,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n RemediationTimestamp = abx_body_abx_body_remediation_timestamp_t,\n SpfResult = abx_body_abx_body_sender_auth_results_spf_s,\n DkimResult = abx_body_abx_body_sender_auth_results_dkim_s,\n DmarcResult = abx_body_abx_body_sender_auth_results_dmarc_s,\n Urls = abx_body_abx_body_urls_s,\n UrlCount = abx_body_abx_body_url_count_d,\n AttachmentNames = abx_body_abx_body_attachment_names_s,\n AttachmentCount = abx_body_abx_body_attachment_count_d,\n SummaryInsights = abx_body_abx_body_summary_insights_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -2899,7 +2899,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurityAtoCases Data Parser with template version 3.1.0", + "description": "AbnormalSecurityAtoCases Data Parser with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('parserObject2').parserVersion2]", @@ -2916,7 +2916,7 @@ "displayName": "Parser for Abnormal Security Account Takeover Cases", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityAtoCases", - "query": "ABNORMAL_SECURITY_ATO_CASE_CL\n| project\n TimeGenerated,\n AtoCaseId = abx_body_abx_body_ato_case_id_s,\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n Severity = abx_body_abx_body_severity_s,\n Status = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n", + "query": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| project\n TimeGenerated,\n AtoCaseId = abx_body_abx_body_ato_case_id_s,\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n Severity = abx_body_abx_body_severity_s,\n Status = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n", "functionParameters": "", "version": 2, "tags": [ @@ -2980,7 +2980,7 @@ "displayName": "Parser for Abnormal Security Account Takeover Cases", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityAtoCases", - "query": "ABNORMAL_SECURITY_ATO_CASE_CL\n| project\n TimeGenerated,\n AtoCaseId = abx_body_abx_body_ato_case_id_s,\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n Severity = abx_body_abx_body_severity_s,\n Status = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n", + "query": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| project\n TimeGenerated,\n AtoCaseId = abx_body_abx_body_ato_case_id_s,\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n Severity = abx_body_abx_body_severity_s,\n Status = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n", "functionParameters": "", "version": 2, "tags": [ @@ -3029,7 +3029,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurityAbuseMailbox Data Parser with template version 3.1.0", + "description": "AbnormalSecurityAbuseMailbox Data Parser with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('parserObject3').parserVersion3]", @@ -3046,7 +3046,7 @@ "displayName": "Parser for Abnormal Security Abuse Mailbox", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityAbuseMailbox", - "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| project\n TimeGenerated,\n CampaignId = abx_body_abx_body_campaign_id_g,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n Reported = abx_body_abx_body_reported_b,\n MessageReportedTime = abx_body_abx_body_message_reported_time_s,\n ReporterName = abx_body_abx_body_reporter_name_s,\n ReporterAddress = abx_body_abx_body_reporter_address_s,\n RecipientName = abx_body_abx_body_recipient_name_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n EmailLabelOrLocation = abx_body_abx_body_email_label_or_location_s,\n NotAnalyzed = abx_body_abx_body_not_analyzed_b,\n ReasonForNoAnalysis = abx_body_abx_body_reason_for_no_analysis_s\n", + "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| project\n TimeGenerated,\n CampaignId = abx_body_abx_body_campaign_id_g,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n Reported = abx_body_abx_body_reported_b,\n MessageReportedTime = abx_body_abx_body_message_reported_time_s,\n ReporterName = abx_body_abx_body_reporter_name_s,\n ReporterAddress = abx_body_abx_body_reporter_address_s,\n RecipientName = abx_body_abx_body_recipient_name_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n EmailLabelOrLocation = abx_body_abx_body_email_label_or_location_s,\n NotAnalyzed = abx_body_abx_body_not_analyzed_b,\n ReasonForNoAnalysis = abx_body_abx_body_reason_for_no_analysis_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -3110,7 +3110,7 @@ "displayName": "Parser for Abnormal Security Abuse Mailbox", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityAbuseMailbox", - "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| project\n TimeGenerated,\n CampaignId = abx_body_abx_body_campaign_id_g,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n Reported = abx_body_abx_body_reported_b,\n MessageReportedTime = abx_body_abx_body_message_reported_time_s,\n ReporterName = abx_body_abx_body_reporter_name_s,\n ReporterAddress = abx_body_abx_body_reporter_address_s,\n RecipientName = abx_body_abx_body_recipient_name_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n EmailLabelOrLocation = abx_body_abx_body_email_label_or_location_s,\n NotAnalyzed = abx_body_abx_body_not_analyzed_b,\n ReasonForNoAnalysis = abx_body_abx_body_reason_for_no_analysis_s\n", + "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| project\n TimeGenerated,\n CampaignId = abx_body_abx_body_campaign_id_g,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n Reported = abx_body_abx_body_reported_b,\n MessageReportedTime = abx_body_abx_body_message_reported_time_s,\n ReporterName = abx_body_abx_body_reporter_name_s,\n ReporterAddress = abx_body_abx_body_reporter_address_s,\n RecipientName = abx_body_abx_body_recipient_name_s,\n RecipientAddress = abx_body_abx_body_recipient_address_s,\n InternetMessageId = abx_body_abx_body_internet_message_id_s,\n EmailLabelOrLocation = abx_body_abx_body_email_label_or_location_s,\n NotAnalyzed = abx_body_abx_body_not_analyzed_b,\n ReasonForNoAnalysis = abx_body_abx_body_reason_for_no_analysis_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -3159,7 +3159,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurityVendorCases Data Parser with template version 3.1.0", + "description": "AbnormalSecurityVendorCases Data Parser with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('parserObject4').parserVersion4]", @@ -3176,7 +3176,7 @@ "displayName": "Parser for Abnormal Security Vendor Cases", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityVendorCases", - "query": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| project\n TimeGenerated,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n FirstObservedTime = abx_body_abx_body_firstObservedTime_t,\n LastModifiedTime = abx_body_abx_body_lastModifiedTime_t,\n Insights = abx_body_abx_body_insights_s,\n Timeline = abx_body_abx_body_timeline_s\n", + "query": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| project\n TimeGenerated,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n FirstObservedTime = abx_body_abx_body_firstObservedTime_t,\n LastModifiedTime = abx_body_abx_body_lastModifiedTime_t,\n Insights = abx_body_abx_body_insights_s,\n Timeline = abx_body_abx_body_timeline_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -3240,7 +3240,7 @@ "displayName": "Parser for Abnormal Security Vendor Cases", "category": "Microsoft Sentinel Parser", "functionAlias": "AbnormalSecurityVendorCases", - "query": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| project\n TimeGenerated,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n FirstObservedTime = abx_body_abx_body_firstObservedTime_t,\n LastModifiedTime = abx_body_abx_body_lastModifiedTime_t,\n Insights = abx_body_abx_body_insights_s,\n Timeline = abx_body_abx_body_timeline_s\n", + "query": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| project\n TimeGenerated,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n FirstObservedTime = abx_body_abx_body_firstObservedTime_t,\n LastModifiedTime = abx_body_abx_body_lastModifiedTime_t,\n Insights = abx_body_abx_body_insights_s,\n Timeline = abx_body_abx_body_timeline_s\n", "functionParameters": "", "version": 2, "tags": [ @@ -3289,7 +3289,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_HighRiskEmailAttack_AnalyticalRules Analytics Rule with template version 3.1.0", + "description": "AbnormalSecurity_HighRiskEmailAttack_AnalyticalRules Analytics Rule with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject1').analyticRuleVersion1]", @@ -3306,7 +3306,7 @@ "description": "Identifies email attacks detected by Abnormal Security whose attack type maps to a\nhigh-risk category (credential phishing, Business Email Compromise, invoice/payment\nfraud, malware, extortion, sensitive-data phishing, internal account-takeover attacks,\nor scams). Lower-risk categories such as Spam, Graymail, and Reconnaissance are\nintentionally excluded. Use this to triage targeted email threats that reached a mailbox.", "displayName": "Abnormal Security - High-risk email attack detected", "enabled": false, - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| where abx_body_abx_body_attack_type_s in~ (\n \"Phishing: Credential\",\n \"Social Engineering (BEC)\",\n \"Invoice/Payment Fraud (BEC)\",\n \"Malware\",\n \"Extortion\",\n \"Phishing: Sensitive Data\",\n \"Internal-to-Internal Attacks (Email Account Takeover)\",\n \"Scam\")\n| extend\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n SenderEmail = abx_body_abx_body_from_address_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderIP = abx_body_abx_body_sender_ip_address_s,\n Subject = abx_body_abx_body_subject_s,\n MessageId = abx_body_abx_body_internet_message_id_s,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n| project TimeGenerated, RecipientEmail, SenderEmail, SenderName, SenderIP, Subject, MessageId, AttackType, AttackScore, RemediationStatus, PortalUrl\n", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| where abx_body_abx_body_attack_type_s in~ (\n \"Phishing: Credential\",\n \"Social Engineering (BEC)\",\n \"Invoice/Payment Fraud (BEC)\",\n \"Malware\",\n \"Extortion\",\n \"Phishing: Sensitive Data\",\n \"Internal-to-Internal Attacks (Email Account Takeover)\",\n \"Scam\")\n| extend\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n SenderEmail = abx_body_abx_body_from_address_s,\n SenderName = abx_body_abx_body_from_name_s,\n SenderIP = abx_body_abx_body_sender_ip_address_s,\n Subject = abx_body_abx_body_subject_s,\n MessageId = abx_body_abx_body_internet_message_id_s,\n AttackType = abx_body_abx_body_attack_type_s,\n AttackScore = abx_body_abx_body_attack_score_d,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n PortalUrl = abx_body_abx_body_abx_portal_url_s\n| project TimeGenerated, RecipientEmail, SenderEmail, SenderName, SenderIP, Subject, MessageId, AttackType, AttackScore, RemediationStatus, PortalUrl\n", "queryFrequency": "PT1H", "queryPeriod": "PT1H", "severity": "High", @@ -3318,7 +3318,7 @@ "requiredDataConnectors": [ { "dataTypes": [ - "ABNORMAL_SECURITY_THREAT_LOG_CL" + "ABNORMAL_SECURITY_THREAT_LOG_V2_CL" ], "connectorId": "AbnormalSecurityPush" } @@ -3334,8 +3334,8 @@ "entityType": "Account", "fieldMappings": [ { - "columnName": "RecipientEmail", - "identifier": "FullName" + "identifier": "FullName", + "columnName": "RecipientEmail" } ] }, @@ -3343,16 +3343,16 @@ "entityType": "MailMessage", "fieldMappings": [ { - "columnName": "RecipientEmail", - "identifier": "Recipient" + "identifier": "Recipient", + "columnName": "RecipientEmail" }, { - "columnName": "SenderEmail", - "identifier": "Sender" + "identifier": "Sender", + "columnName": "SenderEmail" }, { - "columnName": "MessageId", - "identifier": "NetworkMessageId" + "identifier": "NetworkMessageId", + "columnName": "MessageId" } ] }, @@ -3360,8 +3360,8 @@ "entityType": "IP", "fieldMappings": [ { - "columnName": "SenderIP", - "identifier": "Address" + "identifier": "Address", + "columnName": "SenderIP" } ] } @@ -3370,21 +3370,21 @@ "aggregationKind": "AlertPerResult" }, "customDetails": { - "RemediationStatus": "RemediationStatus", "AbnormalPortalUrl": "PortalUrl", "AttackType": "AttackType", + "RemediationStatus": "RemediationStatus", "AttackScore": "AttackScore" }, "alertDetailsOverride": { - "alertDescriptionFormat": "Abnormal Security detected a {{AttackType}} attack from {{SenderEmail}} to {{RecipientEmail}}. See attack score and remediation status in the custom details.", - "alertDisplayNameFormat": "Abnormal Security: {{AttackType}} email delivered to {{RecipientEmail}}" + "alertDisplayNameFormat": "Abnormal Security: {{AttackType}} email delivered to {{RecipientEmail}}", + "alertDescriptionFormat": "Abnormal Security detected a {{AttackType}} attack from {{SenderEmail}} to {{RecipientEmail}}. See attack score and remediation status in the custom details." }, "incidentConfiguration": { "groupingConfiguration": { + "enabled": false, "lookbackDuration": "PT5H", "reopenClosedIncident": false, - "matchingMethod": "AllEntities", - "enabled": false + "matchingMethod": "AllEntities" }, "createIncident": true } @@ -3440,7 +3440,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_AccountTakeover_AnalyticalRules Analytics Rule with template version 3.1.0", + "description": "AbnormalSecurity_AccountTakeover_AnalyticalRules Analytics Rule with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject2').analyticRuleVersion2]", @@ -3457,7 +3457,7 @@ "description": "Creates an incident when Abnormal Security opens an Account Takeover (ATO) case,\nindicating a mailbox or user account is suspected to be compromised. The ATO case\nseverity, status, and observed indicators are surfaced for triage.", "displayName": "Abnormal Security - Account Takeover case opened", "enabled": false, - "query": "ABNORMAL_SECURITY_ATO_CASE_CL\n| where isnotempty(abx_body_abx_body_ato_case_id_s)\n// Collapse to one row per ATO case (earliest event in the window) so repeated\n// events for the same case do not raise duplicate alerts.\n| summarize arg_min(TimeGenerated, *) by CaseId = abx_body_abx_body_ato_case_id_s\n| extend\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n CaseSeverity = abx_body_abx_body_severity_s,\n CaseStatus = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n| project TimeGenerated, CompromisedAccount, CaseId, CaseSeverity, CaseStatus, Indicators, FirstDetected\n", + "query": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| where isnotempty(abx_body_abx_body_ato_case_id_s)\n// Collapse to one row per ATO case (earliest event in the window) so repeated\n// events for the same case do not raise duplicate alerts.\n| summarize arg_min(TimeGenerated, *) by CaseId = abx_body_abx_body_ato_case_id_s\n| extend\n CompromisedAccount = abx_body_abx_body_compromised_account_s,\n CaseSeverity = abx_body_abx_body_severity_s,\n CaseStatus = abx_body_abx_body_status_s,\n Indicators = abx_body_abx_body_indicators_s,\n FirstDetected = abx_body_abx_body_first_detected_t\n| project TimeGenerated, CompromisedAccount, CaseId, CaseSeverity, CaseStatus, Indicators, FirstDetected\n", "queryFrequency": "PT1H", "queryPeriod": "PT1H", "severity": "High", @@ -3469,7 +3469,7 @@ "requiredDataConnectors": [ { "dataTypes": [ - "ABNORMAL_SECURITY_ATO_CASE_CL" + "ABNORMAL_SECURITY_ATO_CASE_V2_CL" ], "connectorId": "AbnormalSecurityPush" } @@ -3487,8 +3487,8 @@ "entityType": "Account", "fieldMappings": [ { - "columnName": "CompromisedAccount", - "identifier": "FullName" + "identifier": "FullName", + "columnName": "CompromisedAccount" } ] } @@ -3497,20 +3497,20 @@ "aggregationKind": "AlertPerResult" }, "customDetails": { - "AtoCaseId": "CaseId", "CaseStatus": "CaseStatus", - "CaseSeverity": "CaseSeverity" + "CaseSeverity": "CaseSeverity", + "AtoCaseId": "CaseId" }, "alertDetailsOverride": { - "alertDescriptionFormat": "Abnormal Security opened ATO case {{CaseId}} (severity {{CaseSeverity}}) for the compromised account {{CompromisedAccount}}.", - "alertDisplayNameFormat": "Abnormal Security: Account Takeover case for {{CompromisedAccount}}" + "alertDisplayNameFormat": "Abnormal Security: Account Takeover case for {{CompromisedAccount}}", + "alertDescriptionFormat": "Abnormal Security opened ATO case {{CaseId}} (severity {{CaseSeverity}}) for the compromised account {{CompromisedAccount}}." }, "incidentConfiguration": { "groupingConfiguration": { + "enabled": true, "lookbackDuration": "PT5H", "reopenClosedIncident": false, - "matchingMethod": "AllEntities", - "enabled": true + "matchingMethod": "AllEntities" }, "createIncident": true } @@ -3566,7 +3566,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_AbuseMailboxMalicious_AnalyticalRules Analytics Rule with template version 3.1.0", + "description": "AbnormalSecurity_AbuseMailboxMalicious_AnalyticalRules Analytics Rule with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject3').analyticRuleVersion3]", @@ -3583,7 +3583,7 @@ "description": "Creates an incident when an email a user reported to the Abnormal Security Abuse\nMailbox is judged malicious. Surfaces the reporter, the original recipient, and the\ncampaign so analysts can scope and remediate look-alike messages. Spam- and safe-judged\nreports are intentionally excluded.", "displayName": "Abnormal Security - User-reported email judged malicious", "enabled": false, - "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| where abx_body_abx_body_reported_b == true\n| where tolower(abx_body_abx_body_judgement_s) == \"malicious\"\n| extend\n ReporterEmail = abx_body_abx_body_reporter_address_s,\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n MessageId = abx_body_abx_body_internet_message_id_s,\n CampaignId = abx_body_abx_body_campaign_id_g\n| project TimeGenerated, ReporterEmail, RecipientEmail, Subject, Judgement, MessageId, CampaignId\n", + "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| where abx_body_abx_body_reported_b == true\n| where tolower(abx_body_abx_body_judgement_s) == \"malicious\"\n| extend\n ReporterEmail = abx_body_abx_body_reporter_address_s,\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n Subject = abx_body_abx_body_subject_s,\n Judgement = abx_body_abx_body_judgement_s,\n MessageId = abx_body_abx_body_internet_message_id_s,\n CampaignId = abx_body_abx_body_campaign_id_g\n| project TimeGenerated, ReporterEmail, RecipientEmail, Subject, Judgement, MessageId, CampaignId\n", "queryFrequency": "PT1H", "queryPeriod": "PT1H", "severity": "Medium", @@ -3595,7 +3595,7 @@ "requiredDataConnectors": [ { "dataTypes": [ - "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL" + "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL" ], "connectorId": "AbnormalSecurityPush" } @@ -3611,8 +3611,8 @@ "entityType": "Account", "fieldMappings": [ { - "columnName": "ReporterEmail", - "identifier": "FullName" + "identifier": "FullName", + "columnName": "ReporterEmail" } ] }, @@ -3620,16 +3620,16 @@ "entityType": "MailMessage", "fieldMappings": [ { - "columnName": "RecipientEmail", - "identifier": "Recipient" + "identifier": "Recipient", + "columnName": "RecipientEmail" }, { - "columnName": "Subject", - "identifier": "Subject" + "identifier": "Subject", + "columnName": "Subject" }, { - "columnName": "MessageId", - "identifier": "NetworkMessageId" + "identifier": "NetworkMessageId", + "columnName": "MessageId" } ] } @@ -3638,19 +3638,19 @@ "aggregationKind": "AlertPerResult" }, "customDetails": { - "CampaignId": "CampaignId", - "Judgement": "Judgement" + "Judgement": "Judgement", + "CampaignId": "CampaignId" }, "alertDetailsOverride": { - "alertDescriptionFormat": "An email reported by {{ReporterEmail}} was judged {{Judgement}} by Abnormal Security. Original recipient: {{RecipientEmail}}.", - "alertDisplayNameFormat": "Abnormal Security: user-reported {{Judgement}} email ({{Subject}})" + "alertDisplayNameFormat": "Abnormal Security: user-reported {{Judgement}} email ({{Subject}})", + "alertDescriptionFormat": "An email reported by {{ReporterEmail}} was judged {{Judgement}} by Abnormal Security. Original recipient: {{RecipientEmail}}." }, "incidentConfiguration": { "groupingConfiguration": { + "enabled": true, "lookbackDuration": "PT5H", "reopenClosedIncident": false, - "matchingMethod": "AllEntities", - "enabled": true + "matchingMethod": "AllEntities" }, "createIncident": true } @@ -3706,7 +3706,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_VendorCompromise_AnalyticalRules Analytics Rule with template version 3.1.0", + "description": "AbnormalSecurity_VendorCompromise_AnalyticalRules Analytics Rule with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject4').analyticRuleVersion4]", @@ -3723,7 +3723,7 @@ "description": "Creates an incident when Abnormal Security opens a vendor case indicating a\ncompromised or impersonated vendor domain (vendor email compromise). Surfaces the\nvendor domain and Abnormal insights so analysts can review related correspondence.", "displayName": "Abnormal Security - Vendor compromise case detected", "enabled": false, - "query": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| where isnotempty(abx_body_abx_body_vendorCaseId_g)\n// Collapse to one row per vendor case (earliest event in the window) so repeated\n// events for the same case do not raise duplicate alerts.\n| summarize arg_min(TimeGenerated, *) by CaseId = abx_body_abx_body_vendorCaseId_g\n| extend\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n Insights = abx_body_abx_body_insights_s,\n FirstObserved = abx_body_abx_body_firstObservedTime_t\n| project TimeGenerated, VendorDomain, CaseId, Insights, FirstObserved\n", + "query": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| where isnotnull(abx_body_abx_body_vendorCaseId_g)\n// Collapse to one row per vendor case (earliest event in the window) so repeated\n// events for the same case do not raise duplicate alerts.\n| summarize arg_min(TimeGenerated, *) by CaseId = abx_body_abx_body_vendorCaseId_g\n| extend\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n Insights = abx_body_abx_body_insights_s,\n FirstObserved = abx_body_abx_body_firstObservedTime_t\n| project TimeGenerated, VendorDomain, CaseId, Insights, FirstObserved\n", "queryFrequency": "PT1H", "queryPeriod": "PT1H", "severity": "Medium", @@ -3735,7 +3735,7 @@ "requiredDataConnectors": [ { "dataTypes": [ - "ABNORMAL_SECURITY_VENDOR_CASE_CL" + "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" ], "connectorId": "AbnormalSecurityPush" } @@ -3751,8 +3751,8 @@ "entityType": "DNS", "fieldMappings": [ { - "columnName": "VendorDomain", - "identifier": "DomainName" + "identifier": "DomainName", + "columnName": "VendorDomain" } ] } @@ -3761,19 +3761,19 @@ "aggregationKind": "AlertPerResult" }, "customDetails": { - "VendorCaseId": "CaseId", - "VendorDomain": "VendorDomain" + "VendorDomain": "VendorDomain", + "VendorCaseId": "CaseId" }, "alertDetailsOverride": { - "alertDescriptionFormat": "Abnormal Security opened vendor case {{CaseId}} for the domain {{VendorDomain}}. Review related correspondence for vendor email compromise.", - "alertDisplayNameFormat": "Abnormal Security: vendor compromise case for {{VendorDomain}}" + "alertDisplayNameFormat": "Abnormal Security: vendor compromise case for {{VendorDomain}}", + "alertDescriptionFormat": "Abnormal Security opened vendor case {{CaseId}} for the domain {{VendorDomain}}. Review related correspondence for vendor email compromise." }, "incidentConfiguration": { "groupingConfiguration": { + "enabled": true, "lookbackDuration": "PT5H", "reopenClosedIncident": false, - "matchingMethod": "AllEntities", - "enabled": true + "matchingMethod": "AllEntities" }, "createIncident": true } @@ -3829,7 +3829,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_UnremediatedThreats_HuntingQueries Hunting Query with template version 3.1.0", + "description": "AbnormalSecurity_UnremediatedThreats_HuntingQueries Hunting Query with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject1').huntingQueryVersion1]", @@ -3845,7 +3845,7 @@ "eTag": "*", "displayName": "Abnormal Security - Threats still in the mailbox", "category": "Hunting Queries", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| where abx_body_abx_body_auto_remediated_b == false\n and abx_body_abx_body_post_remediated_b == false\n| extend\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n SenderEmail = abx_body_abx_body_from_address_s,\n Subject = abx_body_abx_body_subject_s,\n AttackType = abx_body_abx_body_attack_type_s,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n MessageId = abx_body_abx_body_internet_message_id_s\n| project TimeGenerated, RecipientEmail, SenderEmail, Subject, AttackType, RemediationStatus, MessageId\n| sort by TimeGenerated desc\n", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| where abx_body_abx_body_auto_remediated_b == false\n and abx_body_abx_body_post_remediated_b == false\n| extend\n RecipientEmail = abx_body_abx_body_recipient_address_s,\n SenderEmail = abx_body_abx_body_from_address_s,\n Subject = abx_body_abx_body_subject_s,\n AttackType = abx_body_abx_body_attack_type_s,\n RemediationStatus = abx_body_abx_body_remediation_status_s,\n MessageId = abx_body_abx_body_internet_message_id_s\n| project TimeGenerated, RecipientEmail, SenderEmail, Subject, AttackType, RemediationStatus, MessageId\n| sort by TimeGenerated desc\n", "version": 2, "tags": [ { @@ -3913,7 +3913,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_TopAttackTargets_HuntingQueries Hunting Query with template version 3.1.0", + "description": "AbnormalSecurity_TopAttackTargets_HuntingQueries Hunting Query with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject2').huntingQueryVersion2]", @@ -3929,7 +3929,7 @@ "eTag": "*", "displayName": "Abnormal Security - Most-targeted recipients", "category": "Hunting Queries", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| extend RecipientEmail = abx_body_abx_body_recipient_address_s\n| where isnotempty(RecipientEmail)\n| summarize\n ThreatCount = count(),\n DistinctAttackTypes = dcount(abx_body_abx_body_attack_type_s),\n AttackTypes = make_set(abx_body_abx_body_attack_type_s, 10),\n LastSeen = max(TimeGenerated)\n by RecipientEmail\n| where ThreatCount > 1\n| sort by ThreatCount desc\n", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| extend RecipientEmail = abx_body_abx_body_recipient_address_s\n| where isnotempty(RecipientEmail)\n| summarize\n ThreatCount = count(),\n DistinctAttackTypes = dcount(abx_body_abx_body_attack_type_s),\n AttackTypes = make_set(abx_body_abx_body_attack_type_s, 10),\n LastSeen = max(TimeGenerated)\n by RecipientEmail\n| where ThreatCount > 1\n| sort by ThreatCount desc\n", "version": 2, "tags": [ { @@ -3997,7 +3997,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_AbuseMailboxCampaigns_HuntingQueries Hunting Query with template version 3.1.0", + "description": "AbnormalSecurity_AbuseMailboxCampaigns_HuntingQueries Hunting Query with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject3').huntingQueryVersion3]", @@ -4013,7 +4013,7 @@ "eTag": "*", "displayName": "Abnormal Security - User-reported email campaigns", "category": "Hunting Queries", - "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| where abx_body_abx_body_reported_b == true\n| extend\n CampaignId = abx_body_abx_body_campaign_id_g,\n Judgement = abx_body_abx_body_judgement_s,\n Subject = abx_body_abx_body_subject_s\n| where isnotempty(CampaignId)\n| summarize\n ReportCount = count(),\n Recipients = dcount(abx_body_abx_body_recipient_address_s),\n Judgements = make_set(Judgement, 5),\n Subjects = make_set(Subject, 5),\n LastReported = max(TimeGenerated)\n by CampaignId\n| sort by ReportCount desc\n", + "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| where abx_body_abx_body_reported_b == true\n| extend\n CampaignId = abx_body_abx_body_campaign_id_g,\n Judgement = abx_body_abx_body_judgement_s,\n Subject = abx_body_abx_body_subject_s\n| where isnotempty(CampaignId)\n| summarize\n ReportCount = count(),\n Recipients = dcount(abx_body_abx_body_recipient_address_s),\n Judgements = make_set(Judgement, 5),\n Subjects = make_set(Subject, 5),\n LastReported = max(TimeGenerated)\n by CampaignId\n| sort by ReportCount desc\n", "version": 2, "tags": [ { @@ -4081,7 +4081,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity_NewVendorDomains_HuntingQueries Hunting Query with template version 3.1.0", + "description": "AbnormalSecurity_NewVendorDomains_HuntingQueries Hunting Query with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject4').huntingQueryVersion4]", @@ -4097,7 +4097,7 @@ "eTag": "*", "displayName": "Abnormal Security - Newly observed vendor domains", "category": "Hunting Queries", - "query": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| extend\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n FirstObserved = abx_body_abx_body_firstObservedTime_t\n| where isnotempty(VendorDomain)\n| summarize FirstObserved = min(FirstObserved), Cases = make_set(VendorCaseId, 10), CaseCount = count() by VendorDomain\n| sort by FirstObserved desc\n", + "query": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| extend\n VendorDomain = abx_body_abx_body_vendorDomain_s,\n VendorCaseId = abx_body_abx_body_vendorCaseId_g,\n FirstObserved = abx_body_abx_body_firstObservedTime_t\n| where isnotempty(VendorDomain)\n| summarize FirstObserved = min(FirstObserved), Cases = make_set(VendorCaseId, 10), CaseCount = count() by VendorDomain\n| sort by FirstObserved desc\n", "version": 2, "tags": [ { @@ -4165,7 +4165,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurityOverview Workbook with template version 3.1.0", + "description": "AbnormalSecurityOverview Workbook with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion1')]", @@ -4183,7 +4183,7 @@ }, "properties": { "displayName": "[parameters('workbook1-name')]", - "serializedData": "{\"version\":\"Notebook/1.0\",\"items\":[{\"type\":1,\"content\":{\"json\":\"## Abnormal Security Overview\\n\\nThis workbook summarizes email threats, account takeover cases, user-reported messages, and vendor cases ingested from the Abnormal Security CCF Push connector. Use the time range selector to adjust the reporting window.\"},\"name\":\"title\"},{\"type\":9,\"content\":{\"version\":\"KqlParameterItem/1.0\",\"parameters\":[{\"id\":\"a1f1c0d2-0000-4a00-9000-000000000001\",\"version\":\"KqlParameterItem/1.0\",\"name\":\"TimeRange\",\"label\":\"Time range\",\"type\":4,\"isRequired\":true,\"typeSettings\":{\"selectableValues\":[{\"durationMs\":86400000},{\"durationMs\":604800000},{\"durationMs\":2592000000},{\"durationMs\":7776000000}],\"allowCustom\":true},\"value\":{\"durationMs\":604800000}}],\"style\":\"pills\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"name\":\"parameters\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_CL\\n| summarize Threats = count() by bin(TimeGenerated, 1d)\\n| render timechart\",\"size\":0,\"title\":\"Threats detected over time\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"name\":\"threats-over-time\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_CL\\n| summarize Count = count() by AttackType = tostring(abx_body_abx_body_attack_type_s)\\n| where isnotempty(AttackType)\\n| sort by Count desc\\n| render piechart\",\"size\":0,\"title\":\"Attacks by type\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"customWidth\":\"50\",\"name\":\"attacks-by-type\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_CL\\n| summarize Threats = count() by Recipient = tostring(abx_body_abx_body_recipient_address_s)\\n| where isnotempty(Recipient)\\n| sort by Threats desc\\n| take 10\",\"size\":0,\"title\":\"Top targeted recipients\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"top-recipients\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_ATO_CASE_CL\\n| summarize Cases = count() by Severity = tostring(abx_body_abx_body_severity_s)\\n| sort by Cases desc\",\"size\":0,\"title\":\"Account Takeover cases by severity\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"ato-by-severity\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\\n| where abx_body_abx_body_reported_b == true\\n| summarize Reports = count() by Judgement = tostring(abx_body_abx_body_judgement_s)\\n| sort by Reports desc\",\"size\":0,\"title\":\"User-reported messages by judgement\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"abuse-by-judgement\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_VENDOR_CASE_CL\\n| summarize Cases = count() by VendorDomain = tostring(abx_body_abx_body_vendorDomain_s)\\n| where isnotempty(VendorDomain)\\n| sort by Cases desc\\n| take 10\",\"size\":0,\"title\":\"Vendor cases by domain\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"name\":\"vendor-cases\"}],\"$schema\":\"https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json\"}\n", + "serializedData": "{\"version\":\"Notebook/1.0\",\"items\":[{\"type\":1,\"content\":{\"json\":\"## Abnormal Security Overview\\n\\nThis workbook summarizes email threats, account takeover cases, user-reported messages, and vendor cases ingested from the Abnormal Security CCF Push connector. Use the time range selector to adjust the reporting window.\"},\"name\":\"title\"},{\"type\":9,\"content\":{\"version\":\"KqlParameterItem/1.0\",\"parameters\":[{\"id\":\"a1f1c0d2-0000-4a00-9000-000000000001\",\"version\":\"KqlParameterItem/1.0\",\"name\":\"TimeRange\",\"label\":\"Time range\",\"type\":4,\"isRequired\":true,\"typeSettings\":{\"selectableValues\":[{\"durationMs\":86400000},{\"durationMs\":604800000},{\"durationMs\":2592000000},{\"durationMs\":7776000000}],\"allowCustom\":true},\"value\":{\"durationMs\":604800000}}],\"style\":\"pills\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"name\":\"parameters\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_V2_CL\\n| summarize Threats = count() by bin(TimeGenerated, 1d)\\n| render timechart\",\"size\":0,\"title\":\"Threats detected over time\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"name\":\"threats-over-time\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_V2_CL\\n| summarize Count = count() by AttackType = tostring(abx_body_abx_body_attack_type_s)\\n| where isnotempty(AttackType)\\n| sort by Count desc\\n| render piechart\",\"size\":0,\"title\":\"Attacks by type\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\"},\"customWidth\":\"50\",\"name\":\"attacks-by-type\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_THREAT_LOG_V2_CL\\n| summarize Threats = count() by Recipient = tostring(abx_body_abx_body_recipient_address_s)\\n| where isnotempty(Recipient)\\n| sort by Threats desc\\n| take 10\",\"size\":0,\"title\":\"Top targeted recipients\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"top-recipients\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_ATO_CASE_V2_CL\\n| summarize Cases = count() by Severity = tostring(abx_body_abx_body_severity_s)\\n| sort by Cases desc\",\"size\":0,\"title\":\"Account Takeover cases by severity\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"ato-by-severity\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\\n| where abx_body_abx_body_reported_b == true\\n| summarize Reports = count() by Judgement = tostring(abx_body_abx_body_judgement_s)\\n| sort by Reports desc\",\"size\":0,\"title\":\"User-reported messages by judgement\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"customWidth\":\"50\",\"name\":\"abuse-by-judgement\"},{\"type\":3,\"content\":{\"version\":\"KqlItem/1.0\",\"query\":\"ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\\n| summarize Cases = count() by VendorDomain = tostring(abx_body_abx_body_vendorDomain_s)\\n| where isnotempty(VendorDomain)\\n| sort by Cases desc\\n| take 10\",\"size\":0,\"title\":\"Vendor cases by domain\",\"timeContext\":{\"durationMs\":604800000},\"timeContextFromParameter\":\"TimeRange\",\"queryType\":0,\"resourceType\":\"microsoft.operationalinsights/workspaces\",\"visualization\":\"table\"},\"name\":\"vendor-cases\"}],\"$schema\":\"https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json\"}\n", "version": "1.0", "sourceId": "[variables('workspaceResourceId')]", "category": "sentinel" @@ -4217,19 +4217,19 @@ "operator": "AND", "criteria": [ { - "contentId": "ABNORMAL_SECURITY_THREAT_LOG_CL", + "contentId": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", "kind": "DataType" }, { - "contentId": "ABNORMAL_SECURITY_ATO_CASE_CL", + "contentId": "ABNORMAL_SECURITY_ATO_CASE_V2_CL", "kind": "DataType" }, { - "contentId": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", + "contentId": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", "kind": "DataType" }, { - "contentId": "ABNORMAL_SECURITY_VENDOR_CASE_CL", + "contentId": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL", "kind": "DataType" }, { @@ -4265,7 +4265,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AbnormalSecurity-AddIncidentComment Playbook with template version 3.1.0", + "description": "AbnormalSecurity-AddIncidentComment Playbook with template version 3.2.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('playbookVersion1')]", @@ -4454,7 +4454,7 @@ "apiVersion": "2023-04-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "3.1.0", + "version": "3.2.0", "kind": "Solution", "contentSchemaVersion": "3.0.0", "displayName": "AbnormalSecurity", diff --git a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAbuseMailbox.yaml b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAbuseMailbox.yaml index 910ed292146..6267ebc9a2b 100644 --- a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAbuseMailbox.yaml +++ b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAbuseMailbox.yaml @@ -7,7 +7,7 @@ Category: Microsoft Sentinel Parser FunctionName: AbnormalSecurityAbuseMailbox FunctionAlias: AbnormalSecurityAbuseMailbox FunctionQuery: | - ABNORMAL_SECURITY_ABUSE_MAILBOX_CL + ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL | project TimeGenerated, CampaignId = abx_body_abx_body_campaign_id_g, diff --git a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAtoCases.yaml b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAtoCases.yaml index f8ac71c48eb..e39ed5ce1d0 100644 --- a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAtoCases.yaml +++ b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityAtoCases.yaml @@ -7,7 +7,7 @@ Category: Microsoft Sentinel Parser FunctionName: AbnormalSecurityAtoCases FunctionAlias: AbnormalSecurityAtoCases FunctionQuery: | - ABNORMAL_SECURITY_ATO_CASE_CL + ABNORMAL_SECURITY_ATO_CASE_V2_CL | project TimeGenerated, AtoCaseId = abx_body_abx_body_ato_case_id_s, diff --git a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityThreatLog.yaml b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityThreatLog.yaml index 326e5e90d42..99fd4d186d2 100644 --- a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityThreatLog.yaml +++ b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityThreatLog.yaml @@ -7,7 +7,7 @@ Category: Microsoft Sentinel Parser FunctionName: AbnormalSecurityThreatLog FunctionAlias: AbnormalSecurityThreatLog FunctionQuery: | - ABNORMAL_SECURITY_THREAT_LOG_CL + ABNORMAL_SECURITY_THREAT_LOG_V2_CL | project TimeGenerated, ThreatId = abx_body_abx_body_threat_id_g, diff --git a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityVendorCases.yaml b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityVendorCases.yaml index 3abbe9e11cb..4b071a4b7c8 100644 --- a/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityVendorCases.yaml +++ b/Solutions/AbnormalSecurity/Parsers/AbnormalSecurityVendorCases.yaml @@ -7,7 +7,7 @@ Category: Microsoft Sentinel Parser FunctionName: AbnormalSecurityVendorCases FunctionAlias: AbnormalSecurityVendorCases FunctionQuery: | - ABNORMAL_SECURITY_VENDOR_CASE_CL + ABNORMAL_SECURITY_VENDOR_CASE_V2_CL | project TimeGenerated, VendorCaseId = abx_body_abx_body_vendorCaseId_g, diff --git a/Solutions/AbnormalSecurity/ReleaseNotes.md b/Solutions/AbnormalSecurity/ReleaseNotes.md index 956f2234660..b9af3069930 100644 --- a/Solutions/AbnormalSecurity/ReleaseNotes.md +++ b/Solutions/AbnormalSecurity/ReleaseNotes.md @@ -1,5 +1,6 @@ | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | |-------------|--------------------------------|--------------------------------------------------------------------------------| +| 3.2.0 | 28-07-2026 | Renamed the nine CCF Push output tables to `ABNORMAL_SECURITY_*_V2_CL` so the connector always provisions fresh, correctly-typed tables and never collides with Classic tables created by the legacy Azure Functions (Data Collector API) connector — resolving the `Invalid output table schema` Deploy failure on workspaces that previously ran the legacy connector. DCR input streams (`Custom-ABNORMAL_SECURITY_*`) are unchanged; only DCR **output** streams, table definitions, Parsers, Hunting Queries, Analytic Rules, and the Workbook now target the `*_V2_CL` tables. GUID-shaped columns (`*_trace_id_g`, `*_threat_id_g`, `*_campaign_id_g`, `*_vendorCaseId_g`) are now declared as type `guid` with matching `toguid()` conversions in the DCR transforms (fresh V2 tables have no legacy Classic schema to conflict with); all other column names and datatypes are unchanged from 3.1.0. | | 3.1.0 | 05-06-2026 | Added Microsoft Sentinel content for the CCF Push connector to meet MISA integration criteria: four scheduled **Analytic Rules** (high-risk email attack, account takeover, user-reported malicious email, vendor compromise) with entity mappings and MITRE ATT&CK techniques; four **Hunting Queries**; four **Parsers** normalizing the per-event-type tables to friendly column names; an **Abnormal Security Overview Workbook**; and an incident-comment **Playbook**. | | 3.0.0 | 08-05-2026 | Added CCF Push connector with multi-table routing (9 tables), DeployPushConnectorButton, and OAuth 2.0 authentication. Legacy Azure Functions connector retained for backward compatibility.
Full MLA column parity: renamed abx_body_* columns to abx_body_abx_body_*, added abx_body_abx_metadata_* columns across all 9 streams. Fixed DCR transforms with explicit tostring(abx_body) and tostring(abx_metadata) conversions. Fixed fallback stream to Custom-ABNORMAL_SECURITY_LOGS_CL. Added top-level workspace/tables resources in mainTemplate for direct ARM deployment. | | 2.0.1 | 29-06-2023 | Renaming Azure Function to Azure Functions in **Data Connector** Description and Updated the python runtime version to 3.11 | diff --git a/Solutions/AbnormalSecurity/Workbooks/AbnormalSecurityOverview.json b/Solutions/AbnormalSecurity/Workbooks/AbnormalSecurityOverview.json index 3af6bda9fb4..bed34f64483 100644 --- a/Solutions/AbnormalSecurity/Workbooks/AbnormalSecurityOverview.json +++ b/Solutions/AbnormalSecurity/Workbooks/AbnormalSecurityOverview.json @@ -42,7 +42,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Threats = count() by bin(TimeGenerated, 1d)\n| render timechart", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Threats = count() by bin(TimeGenerated, 1d)\n| render timechart", "size": 0, "title": "Threats detected over time", "timeContext": { "durationMs": 604800000 }, @@ -56,7 +56,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Count = count() by AttackType = tostring(abx_body_abx_body_attack_type_s)\n| where isnotempty(AttackType)\n| sort by Count desc\n| render piechart", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Count = count() by AttackType = tostring(abx_body_abx_body_attack_type_s)\n| where isnotempty(AttackType)\n| sort by Count desc\n| render piechart", "size": 0, "title": "Attacks by type", "timeContext": { "durationMs": 604800000 }, @@ -71,7 +71,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_THREAT_LOG_CL\n| summarize Threats = count() by Recipient = tostring(abx_body_abx_body_recipient_address_s)\n| where isnotempty(Recipient)\n| sort by Threats desc\n| take 10", + "query": "ABNORMAL_SECURITY_THREAT_LOG_V2_CL\n| summarize Threats = count() by Recipient = tostring(abx_body_abx_body_recipient_address_s)\n| where isnotempty(Recipient)\n| sort by Threats desc\n| take 10", "size": 0, "title": "Top targeted recipients", "timeContext": { "durationMs": 604800000 }, @@ -87,7 +87,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_ATO_CASE_CL\n| summarize Cases = count() by Severity = tostring(abx_body_abx_body_severity_s)\n| sort by Cases desc", + "query": "ABNORMAL_SECURITY_ATO_CASE_V2_CL\n| summarize Cases = count() by Severity = tostring(abx_body_abx_body_severity_s)\n| sort by Cases desc", "size": 0, "title": "Account Takeover cases by severity", "timeContext": { "durationMs": 604800000 }, @@ -103,7 +103,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL\n| where abx_body_abx_body_reported_b == true\n| summarize Reports = count() by Judgement = tostring(abx_body_abx_body_judgement_s)\n| sort by Reports desc", + "query": "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL\n| where abx_body_abx_body_reported_b == true\n| summarize Reports = count() by Judgement = tostring(abx_body_abx_body_judgement_s)\n| sort by Reports desc", "size": 0, "title": "User-reported messages by judgement", "timeContext": { "durationMs": 604800000 }, @@ -119,7 +119,7 @@ "type": 3, "content": { "version": "KqlItem/1.0", - "query": "ABNORMAL_SECURITY_VENDOR_CASE_CL\n| summarize Cases = count() by VendorDomain = tostring(abx_body_abx_body_vendorDomain_s)\n| where isnotempty(VendorDomain)\n| sort by Cases desc\n| take 10", + "query": "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL\n| summarize Cases = count() by VendorDomain = tostring(abx_body_abx_body_vendorDomain_s)\n| where isnotempty(VendorDomain)\n| sort by Cases desc\n| take 10", "size": 0, "title": "Vendor cases by domain", "timeContext": { "durationMs": 604800000 }, diff --git a/Workbooks/WorkbooksMetadata.json b/Workbooks/WorkbooksMetadata.json index fcc30fd4fd2..30b6147135f 100644 --- a/Workbooks/WorkbooksMetadata.json +++ b/Workbooks/WorkbooksMetadata.json @@ -10716,10 +10716,10 @@ "logoFileName": "abnormalsecurity.svg", "description": "Summarizes email threats, account takeover cases, user-reported messages, and vendor cases ingested from the Abnormal Security CCF Push connector.", "dataTypesDependencies": [ - "ABNORMAL_SECURITY_THREAT_LOG_CL", - "ABNORMAL_SECURITY_ATO_CASE_CL", - "ABNORMAL_SECURITY_ABUSE_MAILBOX_CL", - "ABNORMAL_SECURITY_VENDOR_CASE_CL" + "ABNORMAL_SECURITY_THREAT_LOG_V2_CL", + "ABNORMAL_SECURITY_ATO_CASE_V2_CL", + "ABNORMAL_SECURITY_ABUSE_MAILBOX_V2_CL", + "ABNORMAL_SECURITY_VENDOR_CASE_V2_CL" ], "dataConnectorsDependencies": [ "AbnormalSecurityPush"