Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New resubmit of version 3.0.1 #11615

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open

Conversation

roberteliass
Copy link
Contributor

Changes:

Added six new analytic rule templates to the CTERA Sentinel Solution:
RansomwareUserBlocked.yaml: Detects malicious users blocked by the CTERA Ransom Protect AI engine.
RansomwareDetected.yaml: Identifies ransomware attacks detected by the CTERA Ransom Protect AI engine.
MassDeletions.yaml: Monitors and flags mass file deletion events.
MassPermissionsChange.yaml: Detects large-scale permissions changes in files or folders.
MassAccessDenied.yaml: Flags excessive access denied events.
InfectedFileDetected.yaml: Detects infected files identified by the CTERA platform.
Updated createUiDefinition.json to reflect the addition of six analytic rules in the solution description and configuration steps.
Refined analytics rule descriptions for clarity and accuracy.

Reason for Change(s):
To enhance the CTERA Sentinel Solution with additional analytic capabilities, covering diverse scenarios such as ransomware detection, user blocking, mass file operations, and file infections.
Ensures alignment with Microsoft Sentinel best practices for analytic rules and solution design.

Version Updated:
Yes
Updated the version field for all six analytic rules to reflect the changes in this submission.
Testing Completed:
Tested all YAML files in a standalone Microsoft Sentinel environment without custom parsers or dependencies.
Validated successful execution of analytic rules, ensuring accurate detection and alert generation.
Tested createUiDefinition.json updates in the deployment interface for correct rendering and functionality.

Validations:
Ensured all validations are passing.
Addressed any flagged issues during local testing and validation.

Additional Notes:
Contributions adhere to Microsoft Sentinel guidelines for analytic rule structure and functionality.
Assistance is available if any further refinements are required.

@roberteliass roberteliass requested review from a team as code owners December 30, 2024 20:47
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Dec 31, 2024
@roberteliass
Copy link
Contributor Author

@v-prasadboke - can you help merging this request, the reason I submitting a new one, is since the incorrect 3.0.1.zip file was included on the Azure:master github, which didn't allow me to proceed with the Microsoft Partner Center offer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants