Skip to content

Commit

Permalink
Merge pull request #11435 from Azure/v-rusraut/Claroty,ForcepointCSG,…
Browse files Browse the repository at this point in the history
…ForcepointNGFWRemovedDC

Repackage - Claroty
  • Loading branch information
v-atulyadav authored Nov 21, 2024
2 parents a247c92 + bb165f4 commit 410edb5
Show file tree
Hide file tree
Showing 37 changed files with 160 additions and 2,678 deletions.
8 changes: 1 addition & 7 deletions Solutions/Claroty/Analytic Rules/ClarotyAssetDown.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -32,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -33,5 +27,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down Expand Up @@ -46,5 +40,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: SrcIpAddr
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -37,5 +31,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down Expand Up @@ -39,5 +33,5 @@ entityMappings:
fieldMappings:
- identifier: DistinguishedName
columnName: SGCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
8 changes: 1 addition & 7 deletions Solutions/Claroty/Analytic Rules/ClarotyNewAsset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -32,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
8 changes: 1 addition & 7 deletions Solutions/Claroty/Analytic Rules/ClarotyPolicyViolation.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -32,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -32,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -32,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
2 changes: 1 addition & 1 deletion Solutions/Claroty/Analytic Rules/ClarotyTreat.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,5 +32,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
8 changes: 2 additions & 6 deletions Solutions/Claroty/Data/Solution_Claroty.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"Name": "Claroty",
"Author": "Microsoft - support@microsoft.com",
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
"Description": "The [Claroty](https://claroty.com/) solution for Microsoft Sentinel enables ingestion of  [Continuous Threat Detection](https://claroty.com/resources/datasheets/continuous-threat-detection) and [Secure Remote Access](https://claroty.com/industrial-cybersecurity/sra) events into Microsoft Sentinel. \n\nThis solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.\n\n**NOTE:** Microsoft recommends installation of CEF via AMA Connector. The existing connectors are about to be deprecated by Aug 31, 2024.",
"Description": "The [Claroty](https://claroty.com/) solution for Microsoft Sentinel enables ingestion of  [Continuous Threat Detection](https://claroty.com/resources/datasheets/continuous-threat-detection) and [Secure Remote Access](https://claroty.com/industrial-cybersecurity/sra) events into Microsoft Sentinel. \n\nThis solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.\n\n**NOTE:** Microsoft recommends installation of CEF via AMA Connector. The existing connectors were deprecated on **Aug 31, 2024**.",
"Workbooks": [
"Workbooks/ClarotyOverview.json"
],
Expand All @@ -21,10 +21,6 @@
"Hunting Queries/ClarotyUnresolvedAlerts.yaml",
"Hunting Queries/ClarotyWriteExecuteOperations.yaml"
],
"Data Connectors": [
"Data Connectors/Connector_Claroty_CEF.json",
"Data Connectors/template_ClarotyAMA.json"
],
"Analytic Rules": [
"Analytic Rules/ClarotyAssetDown.yaml",
"Analytic Rules/ClarotyCriticalBaselineDeviation.yaml",
Expand All @@ -42,7 +38,7 @@
],
"Metadata": "SolutionMetadata.json",
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Claroty",
"Version": "3.0.2",
"Version": "3.0.3",
"TemplateSpec": true,
"Is1PConnector": false
}
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for baseline deviation events.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotyConflictAssets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for conflicting assets.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotyCriticalEvents.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for critical severity events.'
severity: High
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotyPLCLogins.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for PLC login security alerts.'
severity: High
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotySRAFailedLogins.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for login failure events.'
severity: High
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotyScanSources.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for sources of network scans.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/Claroty/Hunting Queries/ClarotyScantargets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for targets of network scans.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for unapproved access events.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for alerts with unresolved status.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for operations with Write and Execute accesses.'
severity: Medium
requiredDataConnectors:
- connectorId: Claroty
dataTypes:
- ClarotyEvent
- connectorId: ClarotyAma
dataTypes:
- ClarotyEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Binary file added Solutions/Claroty/Package/3.0.3.zip
Binary file not shown.
Loading

0 comments on commit 410edb5

Please sign in to comment.