Skip to content

Update DataType of AnomalousVoulmeOfFileDeletion analytic rule and AttackSimulatorTrainingNonReporters readme for Microsoft Defender XDR - #14781

Draft
v-kasghosh wants to merge 3 commits into
masterfrom
v-kasghosh/Microsoft_Defender_XDR/bug_fixing
Draft

Update DataType of AnomalousVoulmeOfFileDeletion analytic rule and AttackSimulatorTrainingNonReporters readme for Microsoft Defender XDR#14781
v-kasghosh wants to merge 3 commits into
masterfrom
v-kasghosh/Microsoft_Defender_XDR/bug_fixing

Conversation

@v-kasghosh

Copy link
Copy Markdown
Contributor

Adds AzureActiveDirectory connector with SigninLogs data type as a required data connector to the AnomalousVoulmeOfFileDeletion analytic rule, bumping its version from 1.0.1 to 1.0.2. Also updates the solution package to version 3.0.16 and fixes deploy button URLs in the AttackSimulatorTrainingNonReporters readme to include the correct 'master' branch path.

Required items, please complete

Change(s):

  • DataType of AnomalousVoulmeOfFileDeletion analytic rule and AttackSimulatorTrainingNonReporters Playbookreadme

Reason for Change(s):

  • Detected Bugs during solution Testing

Version Updated:

  • 3,0.16
  • 1.0.2

Adds AzureActiveDirectory connector with SigninLogs data type as a required data connector to the AnomalousVoulmeOfFileDeletion analytic rule, bumping its version from 1.0.1 to 1.0.2. Also updates the solution package to version 3.0.16 and fixes deploy button URLs in the AttackSimulatorTrainingNonReporters readme to include the correct 'master' branch path.
@v-kasghosh v-kasghosh added the Solution Solution specialty review needed label Jul 29, 2026
@contentautomationbot

Copy link
Copy Markdown

Hello how are you I am GitHub bot
😀😀
I see that you changed templates under the detections/analytic rules folder. Did you remember to update the version of the templates you changed?
If not, and if you want customers to be aware that a new version of this template is available, please update the version property of the template you changed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates Microsoft Defender XDR solution assets to reflect corrected deployment documentation and updated connector requirements for an analytic rule.

Changes:

  • Fixes “Deploy to Azure” / “Deploy to Azure Gov” button URLs in the AttackSimulatorTrainingNonReporters playbook README by adding an explicit branch path.
  • Bumps the Microsoft Defender XDR solution package version to 3.0.16.
  • Adds AzureActiveDirectory (SigninLogs) as a required data connector for the AnomalousVoulmeOfFileDeletion analytic rule and bumps its version to 1.0.2.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 2 comments.

File Description
Solutions/Microsoft Defender XDR/Playbooks/AttackSimulatorTrainingNonReporters/readme.md Updates deploy button links to include branch path in raw GitHub URL.
Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json Increments solution package version.
Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml Adds required Azure AD connector/data type and bumps analytic rule version.

Comment on lines +21 to +22
[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json)
[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json)
Comment on lines +21 to +22
[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json)
[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FMicrosoft%2520Defender%2520XDR%2FPlaybooks%2FAttackSimulatorTrainingNonReporters%2Fazuredeploy.json)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content-Package Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants