Skip to content

Commit

Permalink
MDIoT analytic rules entities
Browse files Browse the repository at this point in the history
  • Loading branch information
idoscapa committed Jan 9, 2025
1 parent b2be59a commit 5d1d41e
Show file tree
Hide file tree
Showing 14 changed files with 42 additions and 126 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -49,14 +49,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -80,5 +74,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled

0 comments on commit 5d1d41e

Please sign in to comment.