Skip to content

Commit

Permalink
Repackaged - Cisco SEG
Browse files Browse the repository at this point in the history
  • Loading branch information
v-rusraut committed Nov 14, 2024
1 parent 3c0d446 commit d128e4c
Show file tree
Hide file tree
Showing 28 changed files with 95 additions and 1,094 deletions.
8 changes: 1 addition & 7 deletions Solutions/CiscoSEG/Analytic Rules/CiscoSEGDLPViolation.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -34,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -35,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down Expand Up @@ -39,5 +33,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -36,5 +30,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -34,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -35,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -35,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down Expand Up @@ -41,5 +35,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -35,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -34,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand All @@ -34,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
4 changes: 0 additions & 4 deletions Solutions/CiscoSEG/Data/Solution_CiscoSEG.json
Original file line number Diff line number Diff line change
Expand Up @@ -31,10 +31,6 @@
"Parsers": [
"Parsers/CiscoSEGEvent.yaml"
],
"Data Connectors": [
"Data Connectors/Connector_Cisco_SEG_CEF.json",
"Data Connectors/template_CiscoSEGAMA.json"
],
"Workbooks": [
"Workbooks/CiscoSEG.json"
],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for dropped mails.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for dropped outgoing mails.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for mails with DKIM failure status.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for mails with DMARK failure status.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for mails with SPF failure status.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/CiscoSEG/Hunting Queries/CiscoSEGFailedTLSIn.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches failed TLS incoming connections.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/CiscoSEG/Hunting Queries/CiscoSEGFailedTLSOut.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches failed TLS outgoing connections.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for connections with insecure protocol.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
6 changes: 0 additions & 6 deletions Solutions/CiscoSEG/Hunting Queries/CiscoSEGSpamMails.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for sources of spam mails.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,6 @@ description: |
'Query searches for top users receiving spam mails.'
severity: Medium
requiredDataConnectors:
- connectorId: CiscoSEG
dataTypes:
- CiscoSEGEvent
- connectorId: CiscoSEGAma
dataTypes:
- CiscoSEGEvent
- connectorId: CefAma
dataTypes:
- CommonSecurityLog
Expand Down
Binary file added Solutions/CiscoSEG/Package/3.0.4.zip
Binary file not shown.
Loading

0 comments on commit d128e4c

Please sign in to comment.