diff --git a/Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml b/Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml index fe2baa8c907..adabcc3e0e9 100644 --- a/Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml +++ b/Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml @@ -13,6 +13,9 @@ requiredDataConnectors: dataTypes: - CloudAppEvents - AADSignInEventsBeta + - connectorId: AzureActiveDirectory + dataTypes: + - SigninLogs queryFrequency: 1h queryPeriod: 1h triggerOperator: gt @@ -75,5 +78,5 @@ entityMappings: columnName: ApplicationId customDetails: Count: TotalCount -version: 1.0.1 +version: 1.0.2 kind: Scheduled \ No newline at end of file diff --git a/Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json b/Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json index c657a4cb5cc..cc9febe32cf 100644 --- a/Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json +++ b/Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json @@ -386,7 +386,7 @@ "Workbooks/MicrosoftDefenderForIdentity.json" ], "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Microsoft Defender XDR", - "Version": "3.0.15", + "Version": "3.0.16", "Metadata": "SolutionMetadata.json", "TemplateSpec": true, "StaticDataConnectorIds": [ diff --git a/Solutions/Microsoft Defender XDR/Package/3.0.16.zip b/Solutions/Microsoft Defender XDR/Package/3.0.16.zip new file mode 100644 index 00000000000..ea538056a3d Binary files /dev/null and b/Solutions/Microsoft Defender XDR/Package/3.0.16.zip differ diff --git a/Solutions/Microsoft Defender XDR/Package/mainTemplate.json b/Solutions/Microsoft Defender XDR/Package/mainTemplate.json index 175a685fbf7..abb85595872 100644 --- a/Solutions/Microsoft Defender XDR/Package/mainTemplate.json +++ b/Solutions/Microsoft Defender XDR/Package/mainTemplate.json @@ -57,7 +57,7 @@ "email": "support@microsoft.com", "_email": "[variables('email')]", "_solutionName": "Microsoft Defender XDR", - "_solutionVersion": "3.0.15", + "_solutionVersion": "3.0.16", "solutionId": "azuresentinel.azure-sentinel-solution-microsoft365defender", "_solutionId": "[variables('solutionId')]", "uiConfigId1": "MicrosoftThreatProtection", @@ -252,11 +252,11 @@ "_analyticRulecontentProductId26": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','506f4d6b-3864-4bb1-8f75-a13fb066f97a','-', '1.0.0')))]" }, "analyticRuleObject27": { - "analyticRuleVersion27": "1.0.1", + "analyticRuleVersion27": "1.0.2", "_analyticRulecontentId27": "e5f8e196-3544-4a8b-96a9-17c1b6a49710", "analyticRuleId27": "[resourceId('Microsoft.SecurityInsights/AlertRuleTemplates', 'e5f8e196-3544-4a8b-96a9-17c1b6a49710')]", "analyticRuleTemplateSpecName27": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-ar-',uniquestring('e5f8e196-3544-4a8b-96a9-17c1b6a49710')))]", - "_analyticRulecontentProductId27": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','e5f8e196-3544-4a8b-96a9-17c1b6a49710','-', '1.0.1')))]" + "_analyticRulecontentProductId27": "[concat(take(variables('_solutionId'),50),'-','ar','-', uniqueString(concat(variables('_solutionId'),'-','AnalyticsRule','-','e5f8e196-3544-4a8b-96a9-17c1b6a49710','-', '1.0.2')))]" }, "analyticRuleObject28": { "analyticRuleVersion28": "1.0.0", @@ -2030,7 +2030,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Microsoft Defender XDR data connector with template version 3.0.15", + "description": "Microsoft Defender XDR data connector with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('dataConnectorVersion1')]", @@ -2531,7 +2531,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PossiblePhishingwithCSL&NetworkSession_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "PossiblePhishingwithCSL&NetworkSession_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject1').analyticRuleVersion1]", @@ -2559,86 +2559,86 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "AlertEvidence", "EmailEvents", "IdentityInfo", "DeviceEvents", "DeviceNetworkEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] }, { + "connectorId": "Zscaler", "dataTypes": [ "CommonSecurityLog" - ], - "connectorId": "Zscaler" + ] }, { + "connectorId": "Fortinet", "dataTypes": [ "CommonSecurityLog" - ], - "connectorId": "Fortinet" + ] }, { + "connectorId": "CheckPoint", "dataTypes": [ "CommonSecurityLog" - ], - "connectorId": "CheckPoint" + ] }, { + "connectorId": "PaloAltoNetworks", "dataTypes": [ "CommonSecurityLog" - ], - "connectorId": "PaloAltoNetworks" + ] }, { + "connectorId": "AWSS3", "datatypes": [ "AWSVPCFlow" - ], - "connectorId": "AWSS3" + ] }, { + "connectorId": "WindowsForwardedEvents", "dataTypes": [ "WindowsEvent" - ], - "connectorId": "WindowsForwardedEvents" + ] }, { + "connectorId": "SecurityEvents", "dataTypes": [ "SecurityEvent" - ], - "connectorId": "SecurityEvents" + ] }, { + "connectorId": "WindowsSecurityEvents", "dataTypes": [ "SecurityEvent" - ], - "connectorId": "WindowsSecurityEvents" + ] }, { + "connectorId": "MicrosoftSysmonForLinux", "dataTypes": [ "Syslog" - ], - "connectorId": "MicrosoftSysmonForLinux" + ] }, { + "connectorId": "AzureNSG", "dataTypes": [ "AzureDiagnostics" - ], - "connectorId": "AzureNSG" + ] }, { + "connectorId": "AzureMonitor(VMInsights)", "dataTypes": [ "VMConnection" - ], - "connectorId": "AzureMonitor(VMInsights)" + ] }, { + "connectorId": "AIVectraStream", "dataTypes": [ "VectraStream_CL" - ], - "connectorId": "AIVectraStream" + ] } ], "tactics": [ @@ -2651,7 +2651,6 @@ ], "entityMappings": [ { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -2665,10 +2664,10 @@ "identifier": "UPNSuffix", "columnName": "InitiatingProcessAccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -2682,10 +2681,10 @@ "identifier": "UPNSuffix", "columnName": "RecipientEmailUPNSuffix" } - ] + ], + "entityType": "Account" }, { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -2699,25 +2698,26 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "SourceIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "DestinationIP" } - ] + ], + "entityType": "IP" } ] } @@ -2773,7 +2773,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SUNSPOTHashes_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "SUNSPOTHashes_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject2').analyticRuleVersion2]", @@ -2801,11 +2801,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceImageLoadEvents", "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -2816,7 +2816,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -2830,10 +2829,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -2847,7 +2846,8 @@ "identifier": "UPNSuffix", "columnName": "InitiatingProcessAccountDomain" } - ] + ], + "entityType": "Account" } ] } @@ -2903,7 +2903,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialBuildProcessCompromiseMDE_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "PotentialBuildProcessCompromiseMDE_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject3').analyticRuleVersion3]", @@ -2931,11 +2931,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents", "DeviceFileEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -2946,7 +2946,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "HostName", @@ -2956,10 +2955,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -2973,7 +2972,8 @@ "identifier": "UPNSuffix", "columnName": "FileEditDomain" } - ] + ], + "entityType": "Account" } ] } @@ -3029,7 +3029,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SolarWinds_TEARDROP_Process-IOCs_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "SolarWinds_TEARDROP_Process-IOCs_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject4').analyticRuleVersion4]", @@ -3057,10 +3057,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3075,7 +3075,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3089,10 +3088,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -3106,10 +3105,10 @@ "identifier": "UPNSuffix", "columnName": "InitiatingProcessAccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "FileHash", "fieldMappings": [ { "identifier": "Algorithm", @@ -3119,7 +3118,8 @@ "identifier": "Value", "columnName": "InitiatingProcessSHA1" } - ] + ], + "entityType": "FileHash" } ] } @@ -3175,7 +3175,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SolarWinds_SUNBURST_Network-IOCs_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "SolarWinds_SUNBURST_Network-IOCs_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject5').analyticRuleVersion5]", @@ -3203,10 +3203,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceNetworkEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3221,7 +3221,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3235,10 +3234,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -3252,28 +3251,28 @@ "identifier": "UPNSuffix", "columnName": "InitiatingProcessAccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "RemoteIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "URL", "fieldMappings": [ { "identifier": "Url", "columnName": "RemoteUrl" } - ] + ], + "entityType": "URL" }, { - "entityType": "FileHash", "fieldMappings": [ { "identifier": "Algorithm", @@ -3283,7 +3282,8 @@ "identifier": "Value", "columnName": "InitiatingProcessMD5" } - ] + ], + "entityType": "FileHash" } ] } @@ -3339,7 +3339,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SolarWinds_SUNBURST_&_SUPERNOVA_File-IOCs_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "SolarWinds_SUNBURST_&_SUPERNOVA_File-IOCs_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject6').analyticRuleVersion6]", @@ -3367,10 +3367,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceFileEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3385,7 +3385,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3399,10 +3398,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -3416,10 +3415,10 @@ "identifier": "UPNSuffix", "columnName": "InitiatingProcessAccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "FileHash", "fieldMappings": [ { "identifier": "Algorithm", @@ -3429,7 +3428,8 @@ "identifier": "Value", "columnName": "MD5" } - ] + ], + "entityType": "FileHash" } ] } @@ -3485,7 +3485,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AVdetectionsrelatedtoUkrainebasedthreats_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "AVdetectionsrelatedtoUkrainebasedthreats_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject7').analyticRuleVersion7]", @@ -3513,10 +3513,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "SecurityAlert" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3527,7 +3527,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3541,7 +3540,8 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" } ] } @@ -3597,7 +3597,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AVTarrask_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "AVTarrask_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject8').analyticRuleVersion8]", @@ -3625,10 +3625,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "SecurityAlert" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3639,7 +3639,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3653,16 +3652,17 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "PublicIP" } - ] + ], + "entityType": "IP" } ] } @@ -3718,7 +3718,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AVSpringShell_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "AVSpringShell_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject9').analyticRuleVersion9]", @@ -3746,10 +3746,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "SecurityAlert" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3760,7 +3760,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3774,16 +3773,17 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "PublicIP" } - ] + ], + "entityType": "IP" } ] } @@ -3839,7 +3839,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PossibleWebpBufferOverflow_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "PossibleWebpBufferOverflow_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject10').analyticRuleVersion10]", @@ -3867,13 +3867,13 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents", "DeviceNetworkEvents", "DeviceEvents", "DeviceTvmSoftwareVulnerabilities" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -3884,7 +3884,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -3898,10 +3897,10 @@ "identifier": "DnsDomain", "columnName": "HostNameDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -3915,43 +3914,44 @@ "identifier": "UPNSuffix", "columnName": "UPNSuffix" } - ] + ], + "entityType": "Account" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "LocalIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", "columnName": "ProcessId" } - ] + ], + "entityType": "Process" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", "columnName": "InitiatingProcessId" } - ] + ], + "entityType": "Process" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ], "eventGroupingSettings": { @@ -3963,13 +3963,13 @@ }, "incidentConfiguration": { "groupingConfiguration": { + "lookbackDuration": "PT5H", + "enabled": false, "reopenClosedIncident": false, "matchingMethod": "Selected", - "lookbackDuration": "PT5H", "groupByEntities": [ "Account" - ], - "enabled": false + ] }, "createIncident": false } @@ -4026,7 +4026,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DeimosComponentExecution_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "DeimosComponentExecution_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject11').analyticRuleVersion11]", @@ -4054,10 +4054,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4072,7 +4072,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4086,7 +4085,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4142,7 +4142,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ImminentRansomware_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "ImminentRansomware_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject12').analyticRuleVersion12]", @@ -4179,7 +4179,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4193,7 +4192,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4249,7 +4249,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MaliciousCMDExecutionByJava_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "MaliciousCMDExecutionByJava_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject13').analyticRuleVersion13]", @@ -4277,10 +4277,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4291,7 +4291,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4305,7 +4304,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4361,7 +4361,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "C2-NamedPipe_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "C2-NamedPipe_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject14').analyticRuleVersion14]", @@ -4389,10 +4389,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4403,7 +4403,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4417,7 +4416,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4473,7 +4473,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DoppelPaymerProcDump_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "DoppelPaymerProcDump_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject15').analyticRuleVersion15]", @@ -4501,10 +4501,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4515,7 +4515,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4529,7 +4528,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4585,7 +4585,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LSASSCredDumpProcdump_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "LSASSCredDumpProcdump_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject16').analyticRuleVersion16]", @@ -4613,10 +4613,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4627,7 +4627,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4641,7 +4640,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4697,7 +4697,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DoppelpaymerStopService_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "DoppelpaymerStopService_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject17').analyticRuleVersion17]", @@ -4725,10 +4725,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4741,7 +4741,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4755,7 +4754,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4811,7 +4811,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "QakbotCampaignSelfDeletion_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "QakbotCampaignSelfDeletion_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject18').analyticRuleVersion18]", @@ -4839,10 +4839,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4853,7 +4853,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4867,7 +4866,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -4923,7 +4923,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Regsvr32Rundll32ImageLoadsAbnormalExtension_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "Regsvr32Rundll32ImageLoadsAbnormalExtension_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject19').analyticRuleVersion19]", @@ -4951,11 +4951,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents", "DeviceNetworkEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -4971,7 +4971,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -4985,34 +4984,35 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "LocalIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "RemoteIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "URL", "fieldMappings": [ { "identifier": "Url", "columnName": "RemoteUrl" } - ] + ], + "entityType": "URL" } ] } @@ -5068,7 +5068,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Regsvr32Rundll32WithAnomalousParentProcess_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "Regsvr32Rundll32WithAnomalousParentProcess_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject20').analyticRuleVersion20]", @@ -5096,11 +5096,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents", "DeviceNetworkEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5116,7 +5116,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5130,34 +5129,35 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "LocalIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "RemoteIP" } - ] + ], + "entityType": "IP" }, { - "entityType": "URL", "fieldMappings": [ { "identifier": "Url", "columnName": "RemoteUrl" } - ] + ], + "entityType": "URL" } ] } @@ -5213,7 +5213,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousCommandInitiatedByWebServerProcess_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "SuspiciousCommandInitiatedByWebServerProcess_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject21').analyticRuleVersion21]", @@ -5241,10 +5241,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5260,7 +5260,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5274,7 +5273,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -5330,7 +5330,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "BITSAdminActivity_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "BITSAdminActivity_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject22').analyticRuleVersion22]", @@ -5358,10 +5358,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5376,7 +5376,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5390,10 +5389,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -5403,7 +5402,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -5459,7 +5459,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "OfficeAppsLaunchingWscript_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "OfficeAppsLaunchingWscript_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject23').analyticRuleVersion23]", @@ -5487,10 +5487,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5505,7 +5505,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5519,10 +5518,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -5532,7 +5531,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -5588,7 +5588,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialKerberoastActivities_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "PotentialKerberoastActivities_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject24').analyticRuleVersion24]", @@ -5616,10 +5616,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "IdentityLogonEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5633,7 +5633,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5647,10 +5646,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -5664,7 +5663,8 @@ "identifier": "Name", "columnName": "AccountName" } - ] + ], + "entityType": "Account" } ] } @@ -5720,7 +5720,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "FilesCopiedToUSBDrives_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "FilesCopiedToUSBDrives_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject25').analyticRuleVersion25]", @@ -5748,11 +5748,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceEvents", "DeviceFileEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5763,7 +5763,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5777,10 +5776,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "File", "fieldMappings": [ { "identifier": "Name", @@ -5790,10 +5789,10 @@ "identifier": "Directory", "columnName": "FolderPath" } - ] + ], + "entityType": "File" }, { - "entityType": "FileHash", "fieldMappings": [ { "identifier": "Algorithm", @@ -5803,7 +5802,8 @@ "identifier": "Value", "columnName": "SHA256" } - ] + ], + "entityType": "FileHash" } ] } @@ -5859,7 +5859,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MosaicLoader_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "MosaicLoader_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject26').analyticRuleVersion26]", @@ -5887,10 +5887,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceRegistryEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -5901,7 +5901,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -5915,10 +5914,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "RegistryValue", "fieldMappings": [ { "identifier": "Name", @@ -5928,7 +5927,8 @@ "identifier": "Value", "columnName": "RegistryValueData" } - ] + ], + "entityType": "RegistryValue" } ] } @@ -5984,7 +5984,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AnomalousVoulmeOfFileDeletion_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "AnomalousVoulmeOfFileDeletion_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject27').analyticRuleVersion27]", @@ -6012,11 +6012,17 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "CloudAppEvents", "AADSignInEventsBeta" - ], - "connectorId": "MicrosoftThreatProtection" + ] + }, + { + "connectorId": "AzureActiveDirectory", + "dataTypes": [ + "SigninLogs" + ] } ], "tactics": [ @@ -6027,16 +6033,15 @@ ], "entityMappings": [ { - "entityType": "Account", "fieldMappings": [ { "identifier": "AadUserId", "columnName": "UserId" } - ] + ], + "entityType": "Account" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "Name", @@ -6046,16 +6051,17 @@ "identifier": "NTDomain", "columnName": "NTDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "CloudApplication", "fieldMappings": [ { "identifier": "AppId", "columnName": "ApplicationId" } - ] + ], + "entityType": "CloudApplication" } ], "customDetails": { @@ -6114,7 +6120,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RemoteFileCreationWithPsExec_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "RemoteFileCreationWithPsExec_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject28').analyticRuleVersion28]", @@ -6142,10 +6148,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceFileEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6156,7 +6162,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6170,7 +6175,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -6226,7 +6232,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ServiceAccountsPerformingRemotePS_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "ServiceAccountsPerformingRemotePS_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject29').analyticRuleVersion29]", @@ -6254,11 +6260,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceLogonEvents", "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6269,7 +6275,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6283,10 +6288,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -6300,7 +6305,8 @@ "identifier": "Name", "columnName": "AccountName" } - ] + ], + "entityType": "Account" } ] } @@ -6356,7 +6362,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AccountCreation_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "AccountCreation_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject30').analyticRuleVersion30]", @@ -6384,10 +6390,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6398,7 +6404,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6412,10 +6417,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -6425,7 +6430,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -6481,7 +6487,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LocalAdminGroupChanges_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "LocalAdminGroupChanges_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject31').analyticRuleVersion31]", @@ -6509,11 +6515,11 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "IdentityInfo", "DeviceEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6524,7 +6530,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6538,10 +6543,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -6555,7 +6560,8 @@ "identifier": "NTDomain", "columnName": "laccountdomain" } - ] + ], + "entityType": "Account" } ] } @@ -6611,7 +6617,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RareProcessAsService_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "RareProcessAsService_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject32').analyticRuleVersion32]", @@ -6639,13 +6645,13 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents", "DeviceNetworkEvents", "DeviceFileEvents", "DeviceImageLoadEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6660,7 +6666,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6674,10 +6679,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -6687,7 +6692,8 @@ "identifier": "CommandLine", "columnName": "ServiceProcessCmdline" } - ] + ], + "entityType": "Process" } ] } @@ -6743,7 +6749,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DisableSecurityServiceViaRegistry_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "DisableSecurityServiceViaRegistry_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject33').analyticRuleVersion33]", @@ -6771,10 +6777,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6785,7 +6791,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6799,10 +6804,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -6816,10 +6821,10 @@ "identifier": "NTDomain", "columnName": "AccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -6829,7 +6834,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -6885,7 +6891,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DataDeletionOnMulipleDrivesUsingCipherExe_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "DataDeletionOnMulipleDrivesUsingCipherExe_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject34').analyticRuleVersion34]", @@ -6913,10 +6919,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -6927,7 +6933,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -6941,7 +6946,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -6997,7 +7003,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LaZagneCredTheft_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "LaZagneCredTheft_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject35').analyticRuleVersion35]", @@ -7025,10 +7031,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7039,7 +7045,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7053,10 +7058,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -7066,7 +7071,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -7122,7 +7128,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LogDeletionUsingWevtutil_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "LogDeletionUsingWevtutil_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject36').analyticRuleVersion36]", @@ -7150,10 +7156,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7164,7 +7170,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7178,7 +7183,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -7234,7 +7240,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MultiProcessKillWithTaskKill_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "MultiProcessKillWithTaskKill_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject37').analyticRuleVersion37]", @@ -7262,10 +7268,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7276,7 +7282,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7290,7 +7295,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -7346,7 +7352,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialCobaltStrikeRansomwareActivity_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "PotentialCobaltStrikeRansomwareActivity_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject38').analyticRuleVersion38]", @@ -7374,12 +7380,12 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "AlertInfo", "AlertEvidence", "DeviceLogonEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7396,7 +7402,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7410,10 +7415,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -7427,16 +7432,17 @@ "identifier": "DnsDomain", "columnName": "AccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "IP", "fieldMappings": [ { "identifier": "Address", "columnName": "RemoteIP" } - ] + ], + "entityType": "IP" } ] } @@ -7492,7 +7498,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "QakbotDiscoveryActivities_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "QakbotDiscoveryActivities_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject39').analyticRuleVersion39]", @@ -7520,10 +7526,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7538,7 +7544,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7552,7 +7557,8 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" } ] } @@ -7608,7 +7614,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ShadowCopyDeletion_AnalyticalRules Analytics Rule with template version 3.0.15", + "description": "ShadowCopyDeletion_AnalyticalRules Analytics Rule with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject40').analyticRuleVersion40]", @@ -7636,10 +7642,10 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "MicrosoftThreatProtection", "dataTypes": [ "DeviceProcessEvents" - ], - "connectorId": "MicrosoftThreatProtection" + ] } ], "tactics": [ @@ -7650,7 +7656,6 @@ ], "entityMappings": [ { - "entityType": "Host", "fieldMappings": [ { "identifier": "FullName", @@ -7664,10 +7669,10 @@ "identifier": "DnsDomain", "columnName": "DnsDomain" } - ] + ], + "entityType": "Host" }, { - "entityType": "Account", "fieldMappings": [ { "identifier": "FullName", @@ -7681,10 +7686,10 @@ "identifier": "DnsDomain", "columnName": "AccountDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "Process", "fieldMappings": [ { "identifier": "ProcessId", @@ -7694,7 +7699,8 @@ "identifier": "CommandLine", "columnName": "ProcessCommandLine" } - ] + ], + "entityType": "Process" } ] } @@ -7750,7 +7756,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Appspot Phishing Abuse_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Appspot Phishing Abuse_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject1').huntingQueryVersion1]", @@ -7835,7 +7841,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PayloadDropUsingCertUtil_HuntingQueries Hunting Query with template version 3.0.15", + "description": "PayloadDropUsingCertUtil_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject2').huntingQueryVersion2]", @@ -7916,7 +7922,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "JudgementPandaExfilActivity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "JudgementPandaExfilActivity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject3').huntingQueryVersion3]", @@ -8001,7 +8007,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DeimosComponentExecution_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DeimosComponentExecution_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject4').huntingQueryVersion4]", @@ -8082,7 +8088,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LemonDuckRegistrationFunction_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LemonDuckRegistrationFunction_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject5').huntingQueryVersion5]", @@ -8163,7 +8169,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DeviceWithLog4jAlerts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DeviceWithLog4jAlerts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject6').huntingQueryVersion6]", @@ -8244,7 +8250,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Log4jVulnRelatedAlerts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Log4jVulnRelatedAlerts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject7').huntingQueryVersion7]", @@ -8325,7 +8331,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ImminentRansomware_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ImminentRansomware_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject8').huntingQueryVersion8]", @@ -8406,7 +8412,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MaliciousUseOfMSBuildAsLoLBin_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MaliciousUseOfMSBuildAsLoLBin_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject9').huntingQueryVersion9]", @@ -8487,7 +8493,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "QakbotReconActivities_HuntingQueries Hunting Query with template version 3.0.15", + "description": "QakbotReconActivities_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject10').huntingQueryVersion10]", @@ -8568,7 +8574,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RobbinhoodDriver_HuntingQueries Hunting Query with template version 3.0.15", + "description": "RobbinhoodDriver_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject11').huntingQueryVersion11]", @@ -8649,7 +8655,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Snip3MaliciousNetworkConnectivity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Snip3MaliciousNetworkConnectivity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject12').huntingQueryVersion12]", @@ -8730,7 +8736,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MaliciousCMDExecutionByJava_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MaliciousCMDExecutionByJava_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject13').huntingQueryVersion13]", @@ -8811,7 +8817,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Check for spoofing attempts on the domain with Authentication failures_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Check for spoofing attempts on the domain with Authentication failures_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject14').huntingQueryVersion14]", @@ -8896,7 +8902,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "C2-NamedPipe_HuntingQueries Hunting Query with template version 3.0.15", + "description": "C2-NamedPipe_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject15').huntingQueryVersion15]", @@ -8977,7 +8983,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ReconWithRundll_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ReconWithRundll_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject16').huntingQueryVersion16]", @@ -9058,7 +9064,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DoppelPaymerProcdump_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DoppelPaymerProcdump_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject17').huntingQueryVersion17]", @@ -9139,7 +9145,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LaZagne_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LaZagne_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject18').huntingQueryVersion18]", @@ -9220,7 +9226,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LSASSCredDumpProcdump_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LSASSCredDumpProcdump_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject19').huntingQueryVersion19]", @@ -9301,7 +9307,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ClearSystemLogs_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ClearSystemLogs_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject20').huntingQueryVersion20]", @@ -9382,7 +9388,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DoppelpaymerStopServices_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DoppelpaymerStopServices_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject21').huntingQueryVersion21]", @@ -9463,7 +9469,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "QakbotCampaignSelfDeletion_HuntingQueries Hunting Query with template version 3.0.15", + "description": "QakbotCampaignSelfDeletion_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject22').huntingQueryVersion22]", @@ -9544,7 +9550,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Regsvr32Rundll32ImageLoadsAbnormalExtension_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Regsvr32Rundll32ImageLoadsAbnormalExtension_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject23').huntingQueryVersion23]", @@ -9629,7 +9635,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Regsvr32Rundll32WithAnomalousParentProcess_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Regsvr32Rundll32WithAnomalousParentProcess_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject24').huntingQueryVersion24]", @@ -9714,7 +9720,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Delivered Bad Emails from Top bad IPv4 addresses_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Delivered Bad Emails from Top bad IPv4 addresses_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject25').huntingQueryVersion25]", @@ -9799,7 +9805,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousCommandInitiatedByWebServerProcess_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousCommandInitiatedByWebServerProcess_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject26').huntingQueryVersion26]", @@ -9880,7 +9886,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User&GroupEnumWithNetCommand_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User&GroupEnumWithNetCommand_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject27').huntingQueryVersion27]", @@ -9957,7 +9963,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ATP policy status check_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ATP policy status check_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject28').huntingQueryVersion28]", @@ -10042,7 +10048,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "JNLP attachment_HuntingQueries Hunting Query with template version 3.0.15", + "description": "JNLP attachment_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject29').huntingQueryVersion29]", @@ -10127,7 +10133,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Safe attachment detection_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Safe attachment detection_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject30').huntingQueryVersion30]", @@ -10212,7 +10218,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Authentication failures_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Authentication failures_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject31').huntingQueryVersion31]", @@ -10297,7 +10303,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "CompAuth Failure Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "CompAuth Failure Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject32').huntingQueryVersion32]", @@ -10382,7 +10388,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DKIM Failure Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DKIM Failure Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject33').huntingQueryVersion33]", @@ -10467,7 +10473,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DMARC Failure Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DMARC Failure Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject34').huntingQueryVersion34]", @@ -10552,7 +10558,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SPF Failure Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SPF Failure Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject35').huntingQueryVersion35]", @@ -10637,7 +10643,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof attempts with auth failure_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof attempts with auth failure_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject36').huntingQueryVersion36]", @@ -10722,7 +10728,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Spoof detections by Sender Domain_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Spoof detections by Sender Domain_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject37').huntingQueryVersion37]", @@ -10807,7 +10813,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Spoof DMARC detections by Sender Domain_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Spoof DMARC detections by Sender Domain_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject38').huntingQueryVersion38]", @@ -10892,7 +10898,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Spoof Intra-Org detections by SenderDomain_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Spoof Intra-Org detections by SenderDomain_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject39').huntingQueryVersion39]", @@ -10977,7 +10983,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Message from Accepted Domain with DMARC TempError_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Message from Accepted Domain with DMARC TempError_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject40').huntingQueryVersion40]", @@ -11062,7 +11068,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Message with URL listed on OpenPhish delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Message with URL listed on OpenPhish delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject41').huntingQueryVersion41]", @@ -11147,7 +11153,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Potential OAuth phishing email delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Potential OAuth phishing email delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject42').huntingQueryVersion42]", @@ -11232,7 +11238,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Potentially malicious SVG file delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Potentially malicious SVG file delivered into Inbox_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject43').huntingQueryVersion43]", @@ -11317,7 +11323,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Audit Email Preview-Download action_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Audit Email Preview-Download action_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject44').huntingQueryVersion44]", @@ -11402,7 +11408,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Bad email percentage - Inbound emails_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Bad email percentage - Inbound emails_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject45').huntingQueryVersion45]", @@ -11487,7 +11493,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Calculate MDO Efficacy_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Calculate MDO Efficacy_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject46').huntingQueryVersion46]", @@ -11572,7 +11578,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email sender IP address Geo location information_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email sender IP address Geo location information_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject47').huntingQueryVersion47]", @@ -11657,7 +11663,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for Admin email access_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for Admin email access_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject48').huntingQueryVersion48]", @@ -11742,7 +11748,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for TABL changes_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for TABL changes_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject49').huntingQueryVersion49]", @@ -11827,7 +11833,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Local time to UTC time conversion_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Local time to UTC time conversion_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject50').huntingQueryVersion50]", @@ -11912,7 +11918,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Mail item accessed_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Mail item accessed_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject51').huntingQueryVersion51]", @@ -11997,7 +12003,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious email senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious email senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject52').huntingQueryVersion52]", @@ -12082,7 +12088,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO daily detection summary report_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO daily detection summary report_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject53').huntingQueryVersion53]", @@ -12167,7 +12173,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "New TABL Items_HuntingQueries Hunting Query with template version 3.0.15", + "description": "New TABL Items_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject54').huntingQueryVersion54]", @@ -12252,7 +12258,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Domains sending Malicious Emails (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Domains sending Malicious Emails (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject55').huntingQueryVersion55]", @@ -12337,7 +12343,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 External Senders (Malware)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 External Senders (Malware)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject56').huntingQueryVersion56]", @@ -12422,7 +12428,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 External Senders (Phish)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 External Senders (Phish)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject57').huntingQueryVersion57]", @@ -12507,7 +12513,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 External Senders (Spam)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 External Senders (Spam)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject58').huntingQueryVersion58]", @@ -12592,7 +12598,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 External Senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 External Senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject59').huntingQueryVersion59]", @@ -12677,7 +12683,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Targeted Users (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Targeted Users (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject60').huntingQueryVersion60]", @@ -12762,7 +12768,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Users clicking on Malicious URLs (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Users clicking on Malicious URLs (Malware+Phish+Spam)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject61').huntingQueryVersion61]", @@ -12847,7 +12853,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total number of detections by MDO over time_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total number of detections by MDO over time_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject62').huntingQueryVersion62]", @@ -12932,7 +12938,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total number of detections by MDO_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total number of detections by MDO_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject63').huntingQueryVersion63]", @@ -13017,7 +13023,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Automated email notifications and suspicious sign-in activity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Automated email notifications and suspicious sign-in activity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject64').huntingQueryVersion64]", @@ -13102,7 +13108,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "BEC - File sharing tactics - Dropbox_HuntingQueries Hunting Query with template version 3.0.15", + "description": "BEC - File sharing tactics - Dropbox_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject65').huntingQueryVersion65]", @@ -13187,7 +13193,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "BEC - File sharing tactics - OneDrive or SharePoint_HuntingQueries Hunting Query with template version 3.0.15", + "description": "BEC - File sharing tactics - OneDrive or SharePoint_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject66').huntingQueryVersion66]", @@ -13272,7 +13278,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email bombing_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email bombing_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject67').huntingQueryVersion67]", @@ -13353,7 +13359,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Emails containing links to IP addresses_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Emails containing links to IP addresses_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject68').huntingQueryVersion68]", @@ -13438,7 +13444,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Files share contents and suspicious sign-in activity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Files share contents and suspicious sign-in activity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject69').huntingQueryVersion69]", @@ -13523,7 +13529,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Good emails from senders with bad patterns_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Good emails from senders with bad patterns_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject70').huntingQueryVersion70]", @@ -13608,7 +13614,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for email bombing attacks_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for email bombing attacks_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject71').huntingQueryVersion71]", @@ -13693,7 +13699,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for email conversation take over attempts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for email conversation take over attempts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject72').huntingQueryVersion72]", @@ -13778,7 +13784,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for malicious attachments using external IOC source_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for malicious attachments using external IOC source_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject73').huntingQueryVersion73]", @@ -13863,7 +13869,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for malicious URLs using external IOC source_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for malicious URLs using external IOC source_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject74').huntingQueryVersion74]", @@ -13948,7 +13954,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Inbox rule change which forward-redirect email_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Inbox rule change which forward-redirect email_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject75').huntingQueryVersion75]", @@ -14033,7 +14039,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO_CountOfRecipientsEmailaddressbySubject_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO_CountOfRecipientsEmailaddressbySubject_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject76').huntingQueryVersion76]", @@ -14118,7 +14124,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO_Countofrecipientsemailaddressesbysubject_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO_Countofrecipientsemailaddressesbysubject_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject77').huntingQueryVersion77]", @@ -14203,7 +14209,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO_CountOfSendersEmailaddressbySubject_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO_CountOfSendersEmailaddressbySubject_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject78').huntingQueryVersion78]", @@ -14288,7 +14294,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO_SummaryOfSenders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO_SummaryOfSenders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject79').huntingQueryVersion79]", @@ -14373,7 +14379,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDO_URLClickedinEmail_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDO_URLClickedinEmail_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject80').huntingQueryVersion80]", @@ -14458,7 +14464,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top outbound recipient domains sending inbound emails with threats_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top outbound recipient domains sending inbound emails with threats_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject81').huntingQueryVersion81]", @@ -14543,7 +14549,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Detections by detection methods_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Detections by detection methods_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject82').huntingQueryVersion82]", @@ -14628,7 +14634,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Mail reply to new domain_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Mail reply to new domain_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject83').huntingQueryVersion83]", @@ -14713,7 +14719,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Mailflow by directionality_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Mailflow by directionality_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject84').huntingQueryVersion84]", @@ -14798,7 +14804,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious emails detected per day_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious emails detected per day_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject85').huntingQueryVersion85]", @@ -14883,7 +14889,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Sender recipient contact establishment_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Sender recipient contact establishment_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject86').huntingQueryVersion86]", @@ -14968,7 +14974,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detections by Delivery Location - High_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detections by Delivery Location - High_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject87').huntingQueryVersion87]", @@ -15053,7 +15059,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detections by Delivery Location - Medium_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detections by Delivery Location - Medium_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject88').huntingQueryVersion88]", @@ -15138,7 +15144,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 100 malicious email senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 100 malicious email senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject89').huntingQueryVersion89]", @@ -15223,7 +15229,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 100 senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 100 senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject90').huntingQueryVersion90]", @@ -15308,7 +15314,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Zero day threats_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Zero day threats_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject91').huntingQueryVersion91]", @@ -15393,7 +15399,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email containing malware accessed on a unmanaged device_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email containing malware accessed on a unmanaged device_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject92').huntingQueryVersion92]", @@ -15478,7 +15484,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email containing malware sent by an internal sender_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email containing malware sent by an internal sender_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject93').huntingQueryVersion93]", @@ -15563,7 +15569,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email malware detection report_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email malware detection report_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject94').huntingQueryVersion94]", @@ -15648,7 +15654,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "File Malware Detection Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "File Malware Detection Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject95').huntingQueryVersion95]", @@ -15733,7 +15739,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "File Malware Top Families by AV_HuntingQueries Hunting Query with template version 3.0.15", + "description": "File Malware Top Families by AV_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject96').huntingQueryVersion96]", @@ -15818,7 +15824,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "File Malware Top Families by Safe Attachments_HuntingQueries Hunting Query with template version 3.0.15", + "description": "File Malware Top Families by Safe Attachments_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject97').huntingQueryVersion97]", @@ -15903,7 +15909,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware Detection Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware Detection Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject98').huntingQueryVersion98]", @@ -15988,7 +15994,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware Detections by Delivery Location_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware Detections by Delivery Location_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject99').huntingQueryVersion99]", @@ -16073,7 +16079,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware Detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware Detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject100').huntingQueryVersion100]", @@ -16158,7 +16164,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware Detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware Detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject101').huntingQueryVersion101]", @@ -16243,7 +16249,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware detections by Workload Locations_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware detections by Workload Locations_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject102').huntingQueryVersion102]", @@ -16328,7 +16334,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malware detections by Workload Type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malware detections by Workload Type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject103').huntingQueryVersion103]", @@ -16413,7 +16419,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Domains sending Malware_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Domains sending Malware_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject104').huntingQueryVersion104]", @@ -16498,7 +16504,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Email Malware Families_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Email Malware Families_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject105').huntingQueryVersion105]", @@ -16583,7 +16589,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Users receiving Malware_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Users receiving Malware_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject106').huntingQueryVersion106]", @@ -16668,7 +16674,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Zero-day Malware Detections Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Zero-day Malware Detections Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject107').huntingQueryVersion107]", @@ -16753,7 +16759,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Communication from suspicious external users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Communication from suspicious external users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject108').huntingQueryVersion108]", @@ -16838,7 +16844,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Communication to suspicious external users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Communication to suspicious external users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject109').huntingQueryVersion109]", @@ -16923,7 +16929,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Expanding recipients into separate rows_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Expanding recipients into separate rows_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject110').huntingQueryVersion110]", @@ -17008,7 +17014,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "External malicious Teams messages sent from internal senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "External malicious Teams messages sent from internal senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject111').huntingQueryVersion111]", @@ -17093,7 +17099,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for malicious messages using External Threat Intelligence_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for malicious messages using External Threat Intelligence_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject112').huntingQueryVersion112]", @@ -17178,7 +17184,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Inbound Teams messages by sender domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Inbound Teams messages by sender domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject113').huntingQueryVersion113]", @@ -17263,7 +17269,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious Teams messages by URL detection methods_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious Teams messages by URL detection methods_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject114').huntingQueryVersion114]", @@ -17348,7 +17354,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious Teams messages received from external senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious Teams messages received from external senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject115').huntingQueryVersion115]", @@ -17433,7 +17439,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Microsoft Teams chat initiated by a suspicious external user_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Microsoft Teams chat initiated by a suspicious external user_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject116').huntingQueryVersion116]", @@ -17518,7 +17524,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Number of unique accounts performing Teams message Admin submissions_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Number of unique accounts performing Teams message Admin submissions_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject117').huntingQueryVersion117]", @@ -17603,7 +17609,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Number of unique accounts performing Teams message User submissions_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Number of unique accounts performing Teams message User submissions_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject118').huntingQueryVersion118]", @@ -17688,7 +17694,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Possible partner impersonation in external Team messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Possible partner impersonation in external Team messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject119').huntingQueryVersion119]", @@ -17773,7 +17779,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Possible Teams phishing activity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Possible Teams phishing activity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject120').huntingQueryVersion120]", @@ -17858,7 +17864,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Potentially malicious URL click in Teams_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Potentially malicious URL click in Teams_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject121').huntingQueryVersion121]", @@ -17943,7 +17949,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Rare Domains in External Teams Messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Rare Domains in External Teams Messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject122').huntingQueryVersion122]", @@ -18028,7 +18034,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Suspicious Teams Display Name_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Suspicious Teams Display Name_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject123').huntingQueryVersion123]", @@ -18113,7 +18119,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Admin submission of Malware and Phish daily trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Admin submission of Malware and Phish daily trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject124').huntingQueryVersion124]", @@ -18198,7 +18204,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Admin submission of No Threats daily trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Admin submission of No Threats daily trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject125').huntingQueryVersion125]", @@ -18283,7 +18289,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Admin-User Submissions Grading Verdicts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Admin-User Submissions Grading Verdicts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject126').huntingQueryVersion126]", @@ -18368,7 +18374,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams blocked URL clicks daily trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams blocked URL clicks daily trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject127').huntingQueryVersion127]", @@ -18453,7 +18459,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Malware ZAP _HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Malware ZAP _HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject128').huntingQueryVersion128]", @@ -18538,7 +18544,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Message with URL listed on OpenPhish_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Message with URL listed on OpenPhish_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject129').huntingQueryVersion129]", @@ -18623,7 +18629,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams message ZAPed with the same URL in Email_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams message ZAPed with the same URL in Email_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject130').huntingQueryVersion130]", @@ -18708,7 +18714,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams messages from a specific sender by ThreadType_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams messages from a specific sender by ThreadType_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject131').huntingQueryVersion131]", @@ -18793,7 +18799,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams messages with suspicious URL domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams messages with suspicious URL domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject132').huntingQueryVersion132]", @@ -18878,7 +18884,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Phish ZAP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Phish ZAP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject133').huntingQueryVersion133]", @@ -18963,7 +18969,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams post delivery events daily trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams post delivery events daily trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject134').huntingQueryVersion134]", @@ -19048,7 +19054,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams Spam ZAP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams Spam ZAP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject135').huntingQueryVersion135]", @@ -19133,7 +19139,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams URL clicks actions summarized by URLs clicked on_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams URL clicks actions summarized by URLs clicked on_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject136').huntingQueryVersion136]", @@ -19218,7 +19224,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams URL clicks through actions on Phish or Malware URLs summarized by URLs_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams URL clicks through actions on Phish or Malware URLs summarized by URLs_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject137').huntingQueryVersion137]", @@ -19303,7 +19309,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams User submissions daily trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams User submissions daily trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject138').huntingQueryVersion138]", @@ -19388,7 +19394,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Teams users clicking on suspicious URL domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Teams users clicking on suspicious URL domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject139').huntingQueryVersion139]", @@ -19473,7 +19479,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Attacked user by Phish messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Attacked user by Phish messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject140').huntingQueryVersion140]", @@ -19558,7 +19564,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 external senders sending Teams messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 external senders sending Teams messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject141').huntingQueryVersion141]", @@ -19643,7 +19649,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 External senders sending Teams phishing messsages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 External senders sending Teams phishing messsages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject142').huntingQueryVersion142]", @@ -19728,7 +19734,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 sender domains - Admin Teams message submissions FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 sender domains - Admin Teams message submissions FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject143').huntingQueryVersion143]", @@ -19813,7 +19819,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 sender domains - Teams user submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 sender domains - Teams user submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject144').huntingQueryVersion144]", @@ -19898,7 +19904,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 senders - Teams users submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 senders - Teams users submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject145').huntingQueryVersion145]", @@ -19983,7 +19989,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 senders of Admin Teams message submissions FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 senders of Admin Teams message submissions FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject146').huntingQueryVersion146]", @@ -20068,7 +20074,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 senders of Admin Teams message submissions FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 senders of Admin Teams message submissions FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject147').huntingQueryVersion147]", @@ -20153,7 +20159,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Users clicking on malicious URLs in Teams_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Users clicking on malicious URLs in Teams_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject148').huntingQueryVersion148]", @@ -20238,7 +20244,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top accounts performing Teams admin submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top accounts performing Teams admin submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject149').huntingQueryVersion149]", @@ -20323,7 +20329,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top accounts performing Teams user submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top accounts performing Teams user submissions FN or FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject150').huntingQueryVersion150]", @@ -20408,7 +20414,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top domains outbound sending Malicious Teams messages inbound_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top domains outbound sending Malicious Teams messages inbound_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject151').huntingQueryVersion151]", @@ -20493,7 +20499,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top external malicious senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top external malicious senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject152').huntingQueryVersion152]", @@ -20578,7 +20584,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top External Sender domains - Malware_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top External Sender domains - Malware_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject153').huntingQueryVersion153]", @@ -20663,7 +20669,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top External Sender domains - Phish_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top External Sender domains - Phish_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject154').huntingQueryVersion154]", @@ -20748,7 +20754,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top External Sender domains - Spam_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top External Sender domains - Spam_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject155').huntingQueryVersion155]", @@ -20833,7 +20839,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top malicious URLs clicked by users in Teams_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top malicious URLs clicked by users in Teams_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject156').huntingQueryVersion156]", @@ -20918,7 +20924,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total number of MDO Teams protection detections daily_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total number of MDO Teams protection detections daily_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject157').huntingQueryVersion157]", @@ -21003,7 +21009,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL click on URLs in ZAP-d Teams messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL click on URLs in ZAP-d Teams messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject158').huntingQueryVersion158]", @@ -21088,7 +21094,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam and Phish delivered to Inbox due to Admin Overrides_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam and Phish delivered to Inbox due to Admin Overrides_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject159').huntingQueryVersion159]", @@ -21173,7 +21179,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam and Phish delivered to Inbox due to User Overrides_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam and Phish delivered to Inbox due to User Overrides_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject160').huntingQueryVersion160]", @@ -21258,7 +21264,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top policies performing admin overrides_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top policies performing admin overrides_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject161').huntingQueryVersion161]", @@ -21343,7 +21349,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top policies performing user overrides_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top policies performing user overrides_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject162').huntingQueryVersion162]", @@ -21428,7 +21434,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Emails with Admin Overrides - Allow_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Emails with Admin Overrides - Allow_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject163').huntingQueryVersion163]", @@ -21513,7 +21519,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Emails with Admin Overrides - Block_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Emails with Admin Overrides - Block_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject164').huntingQueryVersion164]", @@ -21598,7 +21604,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Emails with User Overrides - Allow_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Emails with User Overrides - Allow_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject165').huntingQueryVersion165]", @@ -21683,7 +21689,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Emails with User Overrides - Block_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Emails with User Overrides - Block_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject166').huntingQueryVersion166]", @@ -21768,7 +21774,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detection Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detection Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject167').huntingQueryVersion167]", @@ -21853,7 +21859,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detections by Delivery Location - High_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detections by Delivery Location - High_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject168').huntingQueryVersion168]", @@ -21938,7 +21944,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detections by Delivery Location - Medium_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detections by Delivery Location - Medium_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject169').huntingQueryVersion169]", @@ -22023,7 +22029,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detections by Delivery Location Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detections by Delivery Location Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject170').huntingQueryVersion170]", @@ -22108,7 +22114,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject171').huntingQueryVersion171]", @@ -22193,7 +22199,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phish Detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phish Detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject172').huntingQueryVersion172]", @@ -22278,7 +22284,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Possible device code phishing attempts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Possible device code phishing attempts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject173').huntingQueryVersion173]", @@ -22363,7 +22369,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Domains sending Phish_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Domains sending Phish_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject174').huntingQueryVersion174]", @@ -22448,7 +22454,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Users receiving Phish_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Users receiving Phish_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject175').huntingQueryVersion175]", @@ -22533,7 +22539,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Zero-day Phish Detections Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Zero-day Phish Detections Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject176').huntingQueryVersion176]", @@ -22618,7 +22624,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Campaign with randomly named attachments_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Campaign with randomly named attachments_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject177').huntingQueryVersion177]", @@ -22703,7 +22709,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Campaign with suspicious keywords_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Campaign with suspicious keywords_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject178').huntingQueryVersion178]", @@ -22788,7 +22794,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Custom detection-Emails with QR from non-prevalent senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Custom detection-Emails with QR from non-prevalent senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject179').huntingQueryVersion179]", @@ -22873,7 +22879,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Emails delivered having URLs from QR codes_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Emails delivered having URLs from QR codes_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject180').huntingQueryVersion180]", @@ -22958,7 +22964,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Emails with QR codes and suspicious keywords in subject_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Emails with QR codes and suspicious keywords in subject_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject181').huntingQueryVersion181]", @@ -23043,7 +23049,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Emails with QR codes from non-prevalent sender_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Emails with QR codes from non-prevalent sender_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject182').huntingQueryVersion182]", @@ -23128,7 +23134,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunting for sender patterns_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunting for sender patterns_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject183').huntingQueryVersion183]", @@ -23213,7 +23219,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunting for user signals-clusters_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunting for user signals-clusters_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject184').huntingQueryVersion184]", @@ -23298,7 +23304,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Inbound emails with QR code URLs_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Inbound emails with QR code URLs_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject185').huntingQueryVersion185]", @@ -23383,7 +23389,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Personalized campaigns based on the first few keywords_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Personalized campaigns based on the first few keywords_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject186').huntingQueryVersion186]", @@ -23468,7 +23474,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Personalized campaigns based on the last few keywords_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Personalized campaigns based on the last few keywords_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject187').huntingQueryVersion187]", @@ -23553,7 +23559,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Risky sign-in attempt from a non-managed device_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Risky sign-in attempt from a non-managed device_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject188').huntingQueryVersion188]", @@ -23638,7 +23644,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Suspicious sign-in attempts from QR code phishing campaigns_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Suspicious sign-in attempts from QR code phishing campaigns_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject189').huntingQueryVersion189]", @@ -23723,7 +23729,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Group quarantine release_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Group quarantine release_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject190').huntingQueryVersion190]", @@ -23808,7 +23814,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "High Confidence Phish Released_HuntingQueries Hunting Query with template version 3.0.15", + "description": "High Confidence Phish Released_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject191').huntingQueryVersion191]", @@ -23893,7 +23899,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine Phish reason trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine Phish reason trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject192').huntingQueryVersion192]", @@ -23978,7 +23984,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine Phish reason_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine Phish reason_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject193').huntingQueryVersion193]", @@ -24063,7 +24069,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine Release Email Details_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine Release Email Details_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject194').huntingQueryVersion194]", @@ -24148,7 +24154,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine release trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine release trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject195').huntingQueryVersion195]", @@ -24233,7 +24239,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine releases by Detection types_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine releases by Detection types_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject196').huntingQueryVersion196]", @@ -24318,7 +24324,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine Spam reason trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine Spam reason trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject197').huntingQueryVersion197]", @@ -24403,7 +24409,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Quarantine Spam reason_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Quarantine Spam reason_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject198').huntingQueryVersion198]", @@ -24488,7 +24494,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AIR investigation actions insight_HuntingQueries Hunting Query with template version 3.0.15", + "description": "AIR investigation actions insight_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject199').huntingQueryVersion199]", @@ -24573,7 +24579,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Email remediation action list_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Email remediation action list_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject200').huntingQueryVersion200]", @@ -24658,7 +24664,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Bulk Detection Top10 Domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Bulk Detection Top10 Domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject201').huntingQueryVersion201]", @@ -24743,7 +24749,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Delivery Location_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Delivery Location_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject202').huntingQueryVersion202]", @@ -24828,7 +24834,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection IP and Geo Position_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection IP and Geo Position_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject203').huntingQueryVersion203]", @@ -24913,7 +24919,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Mails with BCL_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Mails with BCL_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject204').huntingQueryVersion204]", @@ -24998,7 +25004,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Tech_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Tech_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject205').huntingQueryVersion205]", @@ -25083,7 +25089,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Top10 Domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Top10 Domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject206').huntingQueryVersion206]", @@ -25168,7 +25174,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Top10 Users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Top10 Users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject207').huntingQueryVersion207]", @@ -25253,7 +25259,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Top15 Domains Details_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Top15 Domains Details_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject208').huntingQueryVersion208]", @@ -25338,7 +25344,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Top15 Users Details_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Top15 Users Details_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject209').huntingQueryVersion209]", @@ -25423,7 +25429,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detection Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detection Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject210').huntingQueryVersion210]", @@ -25508,7 +25514,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spam Detections by Detection technology_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spam Detections by Detection technology_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject211').huntingQueryVersion211]", @@ -25593,7 +25599,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Display Name - Spoof and Impersonation_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Display Name - Spoof and Impersonation_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject212').huntingQueryVersion212]", @@ -25678,7 +25684,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Impersonation Phishing detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Impersonation Phishing detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject213').huntingQueryVersion213]", @@ -25763,7 +25769,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Impersonation Phishing detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Impersonation Phishing detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject214').huntingQueryVersion214]", @@ -25848,7 +25854,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Impersonation Phishing detections trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Impersonation Phishing detections trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject215').huntingQueryVersion215]", @@ -25933,7 +25939,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Referral phish emails_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Referral phish emails_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject216').huntingQueryVersion216]", @@ -26018,7 +26024,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof and impersonation detections by sender IP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof and impersonation detections by sender IP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject217').huntingQueryVersion217]", @@ -26103,7 +26109,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof and impersonation phish detections_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof and impersonation phish detections_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject218').huntingQueryVersion218]", @@ -26188,7 +26194,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof detections by Detection Technology Trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject219').huntingQueryVersion219]", @@ -26273,7 +26279,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof detections by Detection Technology_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject220').huntingQueryVersion220]", @@ -26358,7 +26364,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Spoof detections trend_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Spoof detections trend_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject221').huntingQueryVersion221]", @@ -26443,7 +26449,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Domains with BEC Threats inbound_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Domains with BEC Threats inbound_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject222').huntingQueryVersion222]", @@ -26528,7 +26534,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User not covered under display name impersonation_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User not covered under display name impersonation_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject223').huntingQueryVersion223]", @@ -26613,7 +26619,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submission Trend - FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submission Trend - FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject224').huntingQueryVersion224]", @@ -26698,7 +26704,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submission Trend - FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submission Trend - FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject225').huntingQueryVersion225]", @@ -26783,7 +26789,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Detection Method - Phish FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Detection Method - Phish FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject226').huntingQueryVersion226]", @@ -26868,7 +26874,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Detection Method - Spam FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Detection Method - Spam FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject227').huntingQueryVersion227]", @@ -26953,7 +26959,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Detection Type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Detection Type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject228').huntingQueryVersion228]", @@ -27038,7 +27044,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Grading Verdict - FN-FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Grading Verdict - FN-FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject229').huntingQueryVersion229]", @@ -27123,7 +27129,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Submission State - FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Submission State - FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject230').huntingQueryVersion230]", @@ -27208,7 +27214,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Submission State - FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Submission State - FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject231').huntingQueryVersion231]", @@ -27293,7 +27299,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Submission Type - FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Submission Type - FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject232').huntingQueryVersion232]", @@ -27378,7 +27384,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Admin Submissions by Submission Type - FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Admin Submissions by Submission Type - FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject233').huntingQueryVersion233]", @@ -27463,7 +27469,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top accounts performing admin submissions - FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top accounts performing admin submissions - FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject234').huntingQueryVersion234]", @@ -27548,7 +27554,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top accounts performing admin submissions - FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top accounts performing admin submissions - FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject235').huntingQueryVersion235]", @@ -27633,7 +27639,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top accounts performing user submissions_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top accounts performing user submissions_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject236').huntingQueryVersion236]", @@ -27718,7 +27724,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Detection Overrides - Admin Submissions_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Detection Overrides - Admin Submissions_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject237').huntingQueryVersion237]", @@ -27803,7 +27809,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Sender Domains - Admin Submissions FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Sender Domains - Admin Submissions FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject238').huntingQueryVersion238]", @@ -27888,7 +27894,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top Sender Domains - Admin Submissions FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top Sender Domains - Admin Submissions FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject239').huntingQueryVersion239]", @@ -27973,7 +27979,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Submissions by Submission Status_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Submissions by Submission Status_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject240').huntingQueryVersion240]", @@ -28058,7 +28064,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Total Submissions by Submission Type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Total Submissions by Submission Type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject241').huntingQueryVersion241]", @@ -28143,7 +28149,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User reported submissions_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User reported submissions_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject242').huntingQueryVersion242]", @@ -28228,7 +28234,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submission Accuracy versus Admin Verdicts_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submission Accuracy versus Admin Verdicts_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject243').huntingQueryVersion243]", @@ -28313,7 +28319,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top detection overrides by Admins_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top detection overrides by Admins_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject244').huntingQueryVersion244]", @@ -28398,7 +28404,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top detection overrides by Users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top detection overrides by Users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject245').huntingQueryVersion245]", @@ -28483,7 +28489,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top email (P2) senders domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top email (P2) senders domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject246').huntingQueryVersion246]", @@ -28568,7 +28574,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top email (P2) senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top email (P2) senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject247').huntingQueryVersion247]", @@ -28653,7 +28659,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top Intra-Org P2 senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top Intra-Org P2 senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject248').huntingQueryVersion248]", @@ -28738,7 +28744,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions - Top Intra-Org Subjects_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions - Top Intra-Org Subjects_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject249').huntingQueryVersion249]", @@ -28823,7 +28829,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions by Admin review status_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions by Admin review status_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject250').huntingQueryVersion250]", @@ -28908,7 +28914,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions by Grading Verdict - FN-FP_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions by Grading Verdict - FN-FP_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject251').huntingQueryVersion251]", @@ -28993,7 +28999,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions by Submission Type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions by Submission Type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject252').huntingQueryVersion252]", @@ -29078,7 +29084,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions from Junk Folder_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions from Junk Folder_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject253').huntingQueryVersion253]", @@ -29163,7 +29169,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User Submissions Trend - FN_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User Submissions Trend - FN_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject254').huntingQueryVersion254]", @@ -29248,7 +29254,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Attacked more than x times average_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Attacked more than x times average_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject255').huntingQueryVersion255]", @@ -29333,7 +29339,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious mails by sender IPs_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious mails by sender IPs_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject256').huntingQueryVersion256]", @@ -29418,7 +29424,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 percent of most attacked users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 percent of most attacked users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject257').huntingQueryVersion257]", @@ -29503,7 +29509,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 URL domains attacking organization_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 URL domains attacking organization_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject258').huntingQueryVersion258]", @@ -29588,7 +29594,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top external malicious senders_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top external malicious senders_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject259').huntingQueryVersion259]", @@ -29673,7 +29679,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top targeted users_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top targeted users_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject260').huntingQueryVersion260]", @@ -29758,7 +29764,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "End user malicious clicks_HuntingQueries Hunting Query with template version 3.0.15", + "description": "End user malicious clicks_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject261').huntingQueryVersion261]", @@ -29843,7 +29849,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL click count by click action_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL click count by click action_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject262').huntingQueryVersion262]", @@ -29928,7 +29934,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL click on ZAP Email_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL click on ZAP Email_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject263').huntingQueryVersion263]", @@ -30013,7 +30019,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL clicks actions by URL_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL clicks actions by URL_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject264').huntingQueryVersion264]", @@ -30098,7 +30104,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URLClick details based on malicious URL click alert_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URLClick details based on malicious URL click alert_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject265').huntingQueryVersion265]", @@ -30183,7 +30189,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User clicked through events_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User clicked through events_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject266').huntingQueryVersion266]", @@ -30268,7 +30274,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User clicks on malicious inbound emails_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User clicks on malicious inbound emails_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject267').huntingQueryVersion267]", @@ -30353,7 +30359,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "User clicks on phishing URLs in emails_HuntingQueries Hunting Query with template version 3.0.15", + "description": "User clicks on phishing URLs in emails_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject268').huntingQueryVersion268]", @@ -30438,7 +30444,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious Clicks allowed (click-through)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious Clicks allowed (click-through)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject269').huntingQueryVersion269]", @@ -30523,7 +30529,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Malicious Emails with QR code Urls_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Malicious Emails with QR code Urls_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject270').huntingQueryVersion270]", @@ -30608,7 +30614,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Phishing Email Url Redirector_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Phishing Email Url Redirector_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject271').huntingQueryVersion271]", @@ -30693,7 +30699,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SafeLinks URL detections_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SafeLinks URL detections_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject272').huntingQueryVersion272]", @@ -30778,7 +30784,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Users clicking on Malicious URLs (Malware)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Users clicking on Malicious URLs (Malware)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject273').huntingQueryVersion273]", @@ -30863,7 +30869,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Users clicking on Malicious URLs (Phish)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Users clicking on Malicious URLs (Phish)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject274').huntingQueryVersion274]", @@ -30948,7 +30954,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Top 10 Users clicking on Malicious URLs (Spam)_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Top 10 Users clicking on Malicious URLs (Spam)_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject275').huntingQueryVersion275]", @@ -31033,7 +31039,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL Click attempts by threat type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL Click attempts by threat type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject276').huntingQueryVersion276]", @@ -31118,7 +31124,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URL Clicks by Action_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URL Clicks by Action_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject277').huntingQueryVersion277]", @@ -31203,7 +31209,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "URLs by location_HuntingQueries Hunting Query with template version 3.0.15", + "description": "URLs by location_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject278').huntingQueryVersion278]", @@ -31288,7 +31294,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Post Delivery Events by Admin_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Post Delivery Events by Admin_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject279').huntingQueryVersion279]", @@ -31373,7 +31379,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Post Delivery Events by Location_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Post Delivery Events by Location_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject280').huntingQueryVersion280]", @@ -31458,7 +31464,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Post Delivery Events by ZAP type_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Post Delivery Events by ZAP type_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject281').huntingQueryVersion281]", @@ -31543,7 +31549,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Post Delivery Events over time_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Post Delivery Events over time_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject282').huntingQueryVersion282]", @@ -31628,7 +31634,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "EmailDelivered-ToInbox_HuntingQueries Hunting Query with template version 3.0.15", + "description": "EmailDelivered-ToInbox_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject283').huntingQueryVersion283]", @@ -31713,7 +31719,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AnomalousPayloadDeliveredWithISOFile_HuntingQueries Hunting Query with template version 3.0.15", + "description": "AnomalousPayloadDeliveredWithISOFile_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject284').huntingQueryVersion284]", @@ -31798,7 +31804,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "BitsadminActivity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "BitsadminActivity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject285').huntingQueryVersion285]", @@ -31879,7 +31885,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MaliciousUseOfMSIExec_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MaliciousUseOfMSIExec_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject286').huntingQueryVersion286]", @@ -31960,7 +31966,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MaliciousUseOfMsiExecMimikatz_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MaliciousUseOfMsiExecMimikatz_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject287').huntingQueryVersion287]", @@ -32041,7 +32047,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "OfficeAppsLaunchingWscript_HuntingQueries Hunting Query with template version 3.0.15", + "description": "OfficeAppsLaunchingWscript_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject288').huntingQueryVersion288]", @@ -32122,7 +32128,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialKerberoastActivities_HuntingQueries Hunting Query with template version 3.0.15", + "description": "PotentialKerberoastActivities_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject289').huntingQueryVersion289]", @@ -32207,7 +32213,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PowerShellDownloads_HuntingQueries Hunting Query with template version 3.0.15", + "description": "PowerShellDownloads_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject290').huntingQueryVersion290]", @@ -32288,7 +32294,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousAppExeutedByWebserver_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousAppExeutedByWebserver_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject291').huntingQueryVersion291]", @@ -32369,7 +32375,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousMshtaUsage_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousMshtaUsage_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject292').huntingQueryVersion292]", @@ -32450,7 +32456,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "FilesCopiedToUSBDrives_HuntingQueries Hunting Query with template version 3.0.15", + "description": "FilesCopiedToUSBDrives_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject293').huntingQueryVersion293]", @@ -32531,7 +32537,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "CVE-2022-26134-Confluence_HuntingQueries Hunting Query with template version 3.0.15", + "description": "CVE-2022-26134-Confluence_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject294').huntingQueryVersion294]", @@ -32616,7 +32622,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MosaicLoader_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MosaicLoader_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject295').huntingQueryVersion295]", @@ -32697,7 +32703,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SpoolsvSpawningRundll32_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SpoolsvSpawningRundll32_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject296').huntingQueryVersion296]", @@ -32778,7 +32784,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousDLLInSpoolFolder_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousDLLInSpoolFolder_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject297').huntingQueryVersion297]", @@ -32859,7 +32865,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousFilesInSpoolFolder_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousFilesInSpoolFolder_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject298').huntingQueryVersion298]", @@ -32940,7 +32946,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousSpoolsvChildProcess_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousSpoolsvChildProcess_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject299').huntingQueryVersion299]", @@ -33021,7 +33027,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PrintNightmareUsageDetection-CVE-2021-1675_HuntingQueries Hunting Query with template version 3.0.15", + "description": "PrintNightmareUsageDetection-CVE-2021-1675_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject300').huntingQueryVersion300]", @@ -33102,7 +33108,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SuspiciousFileCreationByPrintSpoolerService_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SuspiciousFileCreationByPrintSpoolerService_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject301').huntingQueryVersion301]", @@ -33187,7 +33193,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MITRESuspiciousEvents_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MITRESuspiciousEvents_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject302').huntingQueryVersion302]", @@ -33264,7 +33270,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AnomalousVoulmeOfFileDeletion_HuntingQueries Hunting Query with template version 3.0.15", + "description": "AnomalousVoulmeOfFileDeletion_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject303').huntingQueryVersion303]", @@ -33345,7 +33351,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DetectMailSniper_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DetectMailSniper_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject304').huntingQueryVersion304]", @@ -33426,7 +33432,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AccountBruteForce_HuntingQueries Hunting Query with template version 3.0.15", + "description": "AccountBruteForce_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject305').huntingQueryVersion305]", @@ -33503,7 +33509,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RemoteFileCreationWithPsExec_HuntingQueries Hunting Query with template version 3.0.15", + "description": "RemoteFileCreationWithPsExec_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject306').huntingQueryVersion306]", @@ -33584,7 +33590,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ServiceAccountsPerformingRemotePS_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ServiceAccountsPerformingRemotePS_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject307').huntingQueryVersion307]", @@ -33665,7 +33671,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "AccountCreation_HuntingQueries Hunting Query with template version 3.0.15", + "description": "AccountCreation_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject308').huntingQueryVersion308]", @@ -33742,7 +33748,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LocalAdminGroupChanges_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LocalAdminGroupChanges_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject309').huntingQueryVersion309]", @@ -33823,7 +33829,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RareProcessAsService_HuntingQueries Hunting Query with template version 3.0.15", + "description": "RareProcessAsService_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject310').huntingQueryVersion310]", @@ -33908,7 +33914,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ScheduledTaskCreation_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ScheduledTaskCreation_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject311').huntingQueryVersion311]", @@ -33989,7 +33995,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SAMNameChange_CVE-2021-42278_HuntingQueries Hunting Query with template version 3.0.15", + "description": "SAMNameChange_CVE-2021-42278_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject312').huntingQueryVersion312]", @@ -34070,7 +34076,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DataDeletionOnMulipleDrivesUsingCipherExe_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DataDeletionOnMulipleDrivesUsingCipherExe_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject313').huntingQueryVersion313]", @@ -34151,7 +34157,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DetectMultipleSignsOfRamsomwareActivity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DetectMultipleSignsOfRamsomwareActivity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject314').huntingQueryVersion314]", @@ -34232,7 +34238,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DisableSecurityServiceViaRegistry_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DisableSecurityServiceViaRegistry_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject315').huntingQueryVersion315]", @@ -34313,7 +34319,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DomainDiscoveryWMICwithDLLHostExe_HuntingQueries Hunting Query with template version 3.0.15", + "description": "DomainDiscoveryWMICwithDLLHostExe_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject316').huntingQueryVersion316]", @@ -34394,7 +34400,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MDEExclusionUsingPowerShell_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MDEExclusionUsingPowerShell_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject317').huntingQueryVersion317]", @@ -34475,7 +34481,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "IcedIdSuspiciousImageLoad_HuntingQueries Hunting Query with template version 3.0.15", + "description": "IcedIdSuspiciousImageLoad_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject318').huntingQueryVersion318]", @@ -34556,7 +34562,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LaZagneCredTheft_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LaZagneCredTheft_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject319').huntingQueryVersion319]", @@ -34637,7 +34643,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LogDeletionUsingWevtutil_HuntingQueries Hunting Query with template version 3.0.15", + "description": "LogDeletionUsingWevtutil_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject320').huntingQueryVersion320]", @@ -34718,7 +34724,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MultiProcessKillWithTaskKill_HuntingQueries Hunting Query with template version 3.0.15", + "description": "MultiProcessKillWithTaskKill_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject321').huntingQueryVersion321]", @@ -34799,7 +34805,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialCobaltStrikeRansomwareActivity_HuntingQueries Hunting Query with template version 3.0.15", + "description": "PotentialCobaltStrikeRansomwareActivity_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject322').huntingQueryVersion322]", @@ -34880,7 +34886,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "QakbotDiscoveryActivities_HuntingQueries Hunting Query with template version 3.0.15", + "description": "QakbotDiscoveryActivities_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject323').huntingQueryVersion323]", @@ -34961,7 +34967,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ShadowCopyDeletion_HuntingQueries Hunting Query with template version 3.0.15", + "description": "ShadowCopyDeletion_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject324').huntingQueryVersion324]", @@ -35046,7 +35052,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "TurningOffServicesWithSCCommad_HuntingQueries Hunting Query with template version 3.0.15", + "description": "TurningOffServicesWithSCCommad_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject325').huntingQueryVersion325]", @@ -35127,7 +35133,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Detect_CISA_Alert_AA22-117A2021_Top_Routinely_Exploited_Vulnerabilities_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Detect_CISA_Alert_AA22-117A2021_Top_Routinely_Exploited_Vulnerabilities_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject326').huntingQueryVersion326]", @@ -35208,7 +35214,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Punycode chars lookalike domains_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Punycode chars lookalike domains_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject327').huntingQueryVersion327]", @@ -35293,7 +35299,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for RMM tool execution following Teams messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for RMM tool execution following Teams messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject328').huntingQueryVersion328]", @@ -35378,7 +35384,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Hunt for alerts correlated with Teams messages_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Hunt for alerts correlated with Teams messages_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject329').huntingQueryVersion329]", @@ -35463,7 +35469,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Identify acting user for reported phish_HuntingQueries Hunting Query with template version 3.0.15", + "description": "Identify acting user for reported phish_HuntingQueries Hunting Query with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject330').huntingQueryVersion330]", @@ -35548,7 +35554,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MicrosoftDefenderForOffice365detectionsandinsights Workbook with template version 3.0.15", + "description": "MicrosoftDefenderForOffice365detectionsandinsights Workbook with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion1')]", @@ -35652,7 +35658,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MicrosoftDefenderForEndPoint Workbook with template version 3.0.15", + "description": "MicrosoftDefenderForEndPoint Workbook with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion2')]", @@ -35727,7 +35733,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MicrosoftDefenderForIdentity Workbook with template version 3.0.15", + "description": "MicrosoftDefenderForIdentity Workbook with template version 3.0.16", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion3')]", @@ -35819,7 +35825,7 @@ "apiVersion": "2023-04-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "3.0.15", + "version": "3.0.16", "kind": "Solution", "contentSchemaVersion": "3.0.0", "displayName": "Microsoft Defender XDR", diff --git a/Solutions/Microsoft Defender XDR/Playbooks/AttackSimulatorTrainingNonReporters/readme.md b/Solutions/Microsoft Defender XDR/Playbooks/AttackSimulatorTrainingNonReporters/readme.md index f0c1b719a56..89d61cea9c9 100644 --- a/Solutions/Microsoft Defender XDR/Playbooks/AttackSimulatorTrainingNonReporters/readme.md +++ b/Solutions/Microsoft Defender XDR/Playbooks/AttackSimulatorTrainingNonReporters/readme.md @@ -18,8 +18,8 @@ This playbook will execute using an incident based trigger and determine which m * Workflow Name: Enter the name of the Logic App to deploy (Default: TriggerASTNonReporting) * Email Address: Enter an email address. This will only control the 'Created By' field in the admin portal for any simulations created by the runbook. (This does _not_ modify the sender email address for emails sent via this runbook, which is configured as part of the Attack Simulator payload.) -[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json) -[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json) +[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json) +[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovernbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json) ## Post-Deployment instructions diff --git a/Solutions/Microsoft Defender XDR/ReleaseNotes.md b/Solutions/Microsoft Defender XDR/ReleaseNotes.md index b0fd08651fa..ac776e2fd1b 100644 --- a/Solutions/Microsoft Defender XDR/ReleaseNotes.md +++ b/Solutions/Microsoft Defender XDR/ReleaseNotes.md @@ -1,5 +1,6 @@ | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | |-------------|--------------------------------|---------------------------------------------------------------------------------------| +| 3.0.16 | 29-07-2026 | Updated **Analytic Rule** AnomalousVoulmeOfFileDeletion.yaml to add `AzureActiveDirectory` connector with `SigninLogs` data type. Fixed deploy button URLs in **Playbook** AttackSimulatorTrainingNonReporters readme to include the correct 'master' branch path. | | 3.0.15 | 22-06-2026 | Refactor OAuth and device-code phishing hunting queries to construct login.microsoftonline.com and login.microsoftonline.us URLs via strcat() (resolves ARM-TTK 'DeploymentTemplate Must Not Contain Hardcoded Uri'); remove empty groupByAlertDetails/groupByCustomDetails arrays from PossibleWebpBufferOverflow analytic rule (resolves ARM-TTK 'Template Should Not Contain Blanks'). Updated `Microsoft Defender XDR` to Product Name filter in **Data Connector** queries. Added new **Hunting Queries** Hunt for RMM tool execution following Teams messages, Hunt for alerts correlated with Teams messages and Identify acting user for reported phish. Also updated **Hunting Query** Punycode chars lookalike and corrected the incorrect mapping of `dataTypes: EmailEvents` with `connectorId: OfficeATP` across multiple **Hunting Queries**. | | 3.0.14 | 09-02-2026 | Added new **Hunting Query** Punycode chars lookalike domains.yaml. | | 3.0.13 | 22-01-2026 | Updated Defender XDR solution with new **Hunting Queries**. |