Skip to content

zerofox threat intelligence offer fix#1

Open
dnrr-dev wants to merge 399 commits into
masterfrom
zerofox-threat-intelligence-offer-fix
Open

zerofox threat intelligence offer fix#1
dnrr-dev wants to merge 399 commits into
masterfrom
zerofox-threat-intelligence-offer-fix

Conversation

@dnrr-dev

Copy link
Copy Markdown
Owner
  • Remove case-sensitive duplicate file
  • All the files created
  • Revert "Remove case-sensitive duplicate file"
  • ccp
  • ccf
  • validation tests
  • format
  • added to solution
  • updated logo
  • renamed
  • remove hardcoded
  • updated connector and connector definition
  • packaged
  • portal to platform
  • Fixed mentions of sentinel
  • added release notes
  • Repackaged with fixes
  • Match DCR and tables for streaming
  • Correct time fields
  • re packaged
  • New workbook
  • Updated incident tab
  • Re packaged
  • Incident table
  • re package
  • New analytic rules
  • Re packaged
  • Removed identity tab
  • New summary page
  • summary page fixes
  • remove pre text
  • packaged again
  • repackaged
  • repackaged with pwsh 7
  • fixed held emails query
  • packaged 0909 20 mar 26
  • Added workbook metadata
  • Repackage 1530 20 Mar 26
  • Update Azure SQL analytic and hunting rules
  • Format YAML alert descriptions and fix KQL summarize
  • SQL Sentinel: add hotWord, adjust alerts
  • format
  • Updated workbook metafata
  • Renamed to autonomous response
  • Last response rename
  • make sure for incident prev groups
  • ActiveAI
  • Repackaged 27 Mar 26 at 09:11 UTC
  • Added legacy
  • Repackaged 27 Mar 26 at 09:18 UTC
  • missed response action
  • Repackaged 27 Mar 26 at 09:24 UTC
  • Valid connector id
  • Repackaged 27 Mar 26 at 09:36 UTC
  • Pipeline errors
  • Repackaged 27 Mar 26 at 09:49 UTC
  • Black and white images
  • Updated metadata
  • merge conflicts
  • Create .keep
  • Create .keep
  • Create .keep
  • Create .keep
  • Create .keep
  • Add files via upload
  • Add files via upload
  • Delete Solutions/FieldEffectMDR/Data Connectors/.keep
  • Delete Solutions/FieldEffectMDR/Analytic Rules/.keep
  • Delete Solutions/FieldEffectMDR/Data Connectors/Solution_FieldEffect.json
  • Create .keep
  • Add files via upload
  • Delete Solutions/FieldEffectMDR/Data Connectors/.keep
  • Add files via upload
  • Delete Solutions/FieldEffectMDR/Data/.keep
  • Add files via upload
  • Delete Solutions/FieldEffectMDR/Package/.keep
  • Add files via upload
  • Delete Solutions/FieldEffectMDR/Parsers/.keep
  • Add files via upload
  • Add files via upload
  • Remove invalid comment from mainTemplate.json
  • Fix analytic rule, add KQL custom table, and update logo for validation
  • Fix analytic rule, add KQL custom table, and update logo for validation
  • Fix analytic rule, add KQL custom table, and update logo for validation
  • changed contact link
  • repackaged 15 apr
  • Fix SVG logo id to GUID format
  • templates and new zip packages
  • recover missing description
  • Fix SVG logo ids to GUID format for logo validation
  • Fix YAML syntax in AROAlert analytic rule template
  • Add tactics and align AROAlert with detection template schema
  • Fix AROAlert analytic rule schema and allow-list FieldEffectCCF connector id
  • Fix custom table schema format for FieldEffectAROAlerts_CL
  • Add FieldEffectCCF to ValidConnectorIds allow-list
  • Initial Solution for Google SecOps with Data Connector, Parser and Analytic Rules
  • Fix ARM-TTK schema, apiVersions, and unused variables in mainTemplate
  • Akamai Guardicore: function-app-free CCF migration + DCR-based playbook enrichment
  • Updated logic for fetch detection
  • Address PR review comments
  • Align DCR and poller config with V3 packaging patterns for ARM-TTK compliance
  • Add UniFi Site Manager (CCF) solution
  • Fix: add missing mv-expand for consoleGroupMembers in UniFiCloudConsoleGroupChurn hunting query (KQL validation fix)
  • Fix UniFi Site Manager (CCF) CI failures
  • UniFi Site Manager (CCF): support metadata to Community convention
  • fix(unifi-sitemanager): resolve PR Add unifi site manager ccf solution Azure/Azure-Sentinel#14253 CI failures (Copilot, ARM-TTK, KQL)
  • fix(unifi-sitemanager): replace placeholder support email
  • fix(unifi-sitemanager): connector publisher 'Custom' -> 'Community'
  • refactor(unifi-sitemanager): rename custom tables Unifi_Cloud_ -> Unifi_SiteManager_**
  • changed analytic rules and repackaged
  • copilot review and repackage
  • Fix and repackage
  • solutions stuff
  • feat(unifi-sitemanager): release 3.0.0 with rebuilt workbook + preview images + reviewer fixes
  • add time generated to custom tables
  • add default array
  • re packaged
  • Remove empty properties
  • revert yaml
  • copilot changes
  • re package
  • Update solution identity and category domains
  • Address second round of PR review comments
  • fix analytic rules
  • re package
  • Fix Microsoft Sentinel branding + collapse to single 3.0.0 initial release
  • fix(unifi-sitemanager): address v-shukore PR review feedback
  • spaces not tabs
  • re package
  • Address third round of PR review
  • feat(Tools): add CCF Blob Connector Accelerator with ContosoFort reference implementation
  • fix: remove UTF-8 BOM from all JSON files in CCF Blob Connector Accelerator
  • chore: remove .vscode folder from CCF Blob Connector Accelerator
  • fix(unifi-sitemanager): remove empty groupByEntities from analytic rules
  • fix(unifi-sitemanager): tune 5 noisy analytic rules to reduce false alarms
  • fix(unifi-sitemanager): tune 3 additional analytic rules
  • fix(unifi-sitemanager): final PR cleanup, E2E validated
  • Update FieldEffect solution artifacts to pass local test-tenant validation
  • feat: remove Premium MDTI data connector from Threat Intelligence (NEW) solution
  • fix: revert hardcoded management URL in mainTemplate and update ReleaseNotes
  • chore: update 3.0.19.zip package with ARM-TTK fix
  • removed unused detection fields befor ingesting data
  • removed unused fileds
  • Update SilverfortAma.json
  • fixed pipeline failures
  • reset csvs
  • updated for azure gov
  • fixed validation checks
  • Copilot fix for python version command
  • Vaikora-SentinelOne v3.0.1: omit agent_id query param when VaikoraAgentId is empty
  • Vaikora-CrowdStrike v3.0.1: omit agent_id query param when VaikoraAgentId is empty
  • Vaikora-AzureSecurityCenter v3.0.1: align playbook + analytic rules with Vaikora /actions API schema
  • Repackaged using V3 tool
  • fix(Tools): add missing comma in ContosoFort SolutionMetadata.json
  • Adding a new query string parameter
  • Updated relevantTechniques in Analytic Rules
  • fix: clarify ReleaseNotes change history for PMDTI connector removal
  • Add eDCRule solution
  • re packaged 3.0.1
  • Add 3.0.1 package with AMA and python --version fixes
  • Add entry in releasenotes.md
  • Regenerate FieldEffect package and validate connector deployment, connection, and ingestion
  • Update QualysVM connector staged artifacts
  • Fixes from feedback
  • Update QualysVM connector and package template artifacts
  • Rebuild Package/3.0.0.zip to match the loose mainTemplate/createUiDefinition
  • resolve conflicts
  • conflicts
  • new line
  • fix(unifi-sitemanager): sync Package/3.0.0.zip with mainTemplate.json
  • SAP ETD Cloud 3.0.5: telemetry-tampering analytic rules
  • re package ai analyst
  • SAP BTP 3.1.0: rework Cloud Integration artifact deployment rule
  • Fix SAPETD-SystemStoppedReporting: shorten CustomDetails key
  • Fix SAPETD-NoNewDataReceived: shorten CustomDetails key
  • fix(vaikora-asc): set playbook workflow location to resourceGroup().location
  • Fix SolutionMetadata publisherId and provider values
  • Updated ReleaseNotes.md to use the required 3-column markdown table format, corrected the date format to DD-MM-YYYY, and aligned the version with the solution package version.
  • Updated createUiDefinition.json to align the analytic rule count with the package content and replaced the Azure Sentinel branding reference with Microsoft Sentinel branding.
  • Rename Solutions/eDCRule/Analytics Rules/[AzureSubscrption] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/Analytics Rules/Solutions/eDCRule/Analytic Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • add tactics and techniques
  • re package
  • Rename Solutions/eDCRule/Analytics Rules/Solutions/eDCRule/Analytic Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/Analytics Rules/Analytics Rules[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename Analytics Rules[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to [AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename Solutions/eDCRule/Analytics Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/Analytic Rules[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename Solutions/eDCRule/Analytic Rules[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/Analytic Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml to [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml
  • Rename Solutions/eDCRule/Analytic Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename Solutions/eDCRule/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to Solutions/eDCRule/Analytic Rules/[AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml to [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml
  • Rename [AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to [AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename [AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml to [AzureSubscription] Suspicious Azure VM Run Command Execution Detected.yaml
  • Rename [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles.yaml to [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles.yaml
  • Rename [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml to [AzureSubscrption]偵測到可疑的 Azure VM Run Command 執行操作.yaml
  • Rename [Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions.yaml to [Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions.yaml
  • Rename [Entra ID] Domain Federation Trust Settings Modified.yaml to [Entra ID] Domain Federation Trust Settings Modified.yaml
  • Rename [Entra ID] Mass Privileged Role Change Activity Detected.yaml to [Entra ID] Mass Privileged Role Change Activity Detected.yaml
  • Rename [Entra ID] Privilege Elevation Request Denied.yaml to [Entra ID] Privilege Elevation Request Denied.yaml
  • Rename [Entra ID]特權帳戶的驗證方法已更改.yaml to [Entra ID]特權帳戶的驗證方法已更改.yaml
  • Rename [Entra ID]網域聯合信任設置修改.yaml to [Entra ID]網域聯合信任設置修改.yaml
  • Rename [Entra ID]特權角色分配給新的使用者.yaml to [Entra ID]特權角色分配給新的使用者.yaml
  • Rename [Entra ID]提升權限請求已被拒絕.yaml to [Entra ID]提升權限請求已被拒絕.yaml
  • Rename [Entra ID]應用程式取得角色管理權限後,隨即指派管理員權限.yaml to [Entra ID]應用程式取得角色管理權限後,隨即指派管理員權限.yaml
  • Rename [Entra ID]偵測到大量特權角色變更動作.yaml to [Entra ID]偵測到大量特權角色變更動作.yaml
  • Rename [Entra ID]授予應用程式可指派Microsoft Entra ID 角色的管理權限.yaml to [Entra ID]授予應用程式可指派Microsoft Entra ID 角色的管理權限.yaml
  • Rename [Entra ID]可疑的 OAuth Token 持續使用行為.yaml to [Entra ID]可疑的 OAuth Token 持續使用行為.yaml
  • Rename [Entra ID] Suspicious Continuous OAuth Token Usage.yaml to [Entra ID] Suspicious Continuous OAuth Token Usage.yaml
  • Rename [Entra ID]使用者指派了特權角色.yaml to [Entra ID]使用者指派了特權角色.yaml
  • Rename [Entra ID] Privileged Role Assigned to User.yaml to [Entra ID] Privileged Role Assigned to User.yaml
  • Rename [Entra ID] Privileged Role Assigned to a New User.yaml to [Entra ID] Privileged Role Assigned to a New User.yaml
  • Rename [Entra ID] Authentication Method Changed for Privileged Account.yaml to [Entra ID] Authentication Method Changed for Privileged Account.yaml
  • Updated Solution_eDCRule.json to use standard relative paths for analytic rule templates and aligned the folder naming with the repo convention.
  • Updated BasePath to use the repository-relative solution path, set TemplateSpec to false for version 3.0.0, and added Is1PConnector as false for this partner solution.
  • Updated BasePath to use the repository-relative solution path, set TemplateSpec to false for version 3.0.0, and added Is1PConnector as false for this partner solution.
  • Update createUiDefinition.json
  • Updated the query to use a single IP address for geo_info_from_ip_address() by extracting the first value from NewIPs before calling the function.
  • Removed the BOM/non-ASCII character before the id field and ensured the YAML file is saved as UTF-8 without BOM.
  • Updated Source_Network_IPAddress to project the actual IP field instead of the GeoInfo dynamic object, and kept the geo-enrichment result in Source_Network_IPLocation.
  • Fix YAML indentation and remove BOM
  • Fix AccountCustomEntity
  • Fix AccountCustomEntity
  • Update [Entra ID] Privilege Elevation Request Denied.yaml
  • Fix AccountCustomEntity
  • Fix AccountCustomEntity
  • Add AWS Config CCF data connector
  • Add AWS Config custom table schema
  • SAP ETD 3.0.5: address Copilot review feedback on telemetry-tampering rules
  • SAP BTP 3.1.0: address Copilot review feedback on Solution data file
  • fix IPCustomEntity
  • Update [Entra ID] Privilege Elevation Request Denied.yaml
  • Regenerate eDCRule package using V3 tool
  • Refactor CloudFormation template for AWS Config
  • Fix eDCRule validation issues and regenerate package
  • resolve conflicts
  • revert
  • Fix ARM-TTK "URIs Should Be Properly Constructed" in enrichment trigger playbook
  • Readme file for Crowdstrike Solution
  • Format release notes table and bold CCF
  • Update ReleaseNotes.md
  • Update Azure SQL solution templates and query versions
  • Add Utimaco ESKM Sentinel solution files
  • Address PR review comments
  • Address PR review comments - version mismatches
  • Address PR review comments - PollingConfig changes
  • Address PR review comment - added logo
  • Renamed Logo file
  • Updated Logo file path
  • Updated casing
  • Fixed workbook issues
  • Solution version chnaged to version
  • KQL query updated
  • Updated publisher ID
  • corrected Query in Workbook
  • Corrected UI text
  • Addressed review comments - settings.json, table schema, testparameters
  • Addressed review comments - logo raw file change, workbook preview image, version update, releasenotes
  • fix(StealthTalk): correct publisherId from 'stealthtalk' to 'stealthtalkinc' to match Partner Center registered publisher ID The publisherId in SolutionMetadata.json was set to a brand-name shorthand 'stealthtalk' instead of the actual Partner Center registered publisher ID 'stealthtalkinc'. This caused Partner Center certification check 300.4.1.1 to fail: the Marketplace identifier publisherId.offerId derived from the GitHub source did not match the 'Offer Name' in Partner Center. Changes: - SolutionMetadata.json: publisherId 'stealthtalk' -> 'stealthtalkinc' - Package/mainTemplate.json: surgical update of solutionId variable to embed corrected publisherId (no V3 rebuild, to keep the diff minimal and avoid V3-tool cosmetic field reordering) - Package/3.0.0.zip: repacked with the patched mainTemplate.json
  • update readmefile
  • Fixed Logo Validation issues
  • update
  • Bump AWS Security Hub solution to v3.0.4
  • update
  • Update ReleaseNotes.md
  • Update 3.0.4.zip
  • Update ReleaseNotes.md
  • Repackaged the solution
  • update
  • [Imperva Cloud WAF] - update to use CommonEventFormatTransformer ([Imperva Cloud WAF] - update to use CommonEventFormatTransformer Azure/Azure-Sentinel#14456)
  • add tables and modify data collection rules to ingest zimperium incident data
  • Add to description of yaml files that parsers were created by the tool ([ASIM] Add to description of yaml files that parsers were created by the tool Azure/Azure-Sentinel#14467)
  • Updates to schema tester ([ASIM] Updates to ASimSchemaTester to use both selected schema and common fields Azure/Azure-Sentinel#14468)
  • Update ReleaseNotes.md
  • Update WorkbooksMetadata.json
  • Updated Solution Metadata to change ownership from Microsoft to SailPoint
  • email and repackaged
  • Enhanced BloodHound workbooks by adding time context with a duration of 30 days instead default values for parameters, which was failing to run the query correctly.
  • Updated ReleaseNotes.md, mainTemplate.json & main zip file for version 3.2.2.
  • armttk
  • Update ReleaseNotes.md
  • update
  • update
  • Updated BloodHound workbooks to remove fallback resource IDs and adjusted time context duration in BloodHoundFindingTrends.json.
  • chore: fix ZeroFox Threat Intelligence solution id
  • Reverting the changes on Sailpoint
  • QualysVM: update user role comparison URL and package template version
  • Microsoft Defender XDR: fix ARM-TTK hardcoded URI false positives in phishing hunting queries
  • Updated Solution metadata to change ownership from microsoft to Sailpoint
  • align to use Python 3.12
  • Update validator skills ([ASIM] Update validator skills Azure/Azure-Sentinel#14473)
  • [ASIM] Modify Template Validation test to prevent flakey test results ([ASIM] Modify Template Validation test to prevent flakey test results Azure/Azure-Sentinel#14469)
  • Palo Alto XDR ASimAlert Parser (Palo Alto XDR ASimAlert Parser Azure/Azure-Sentinel#14401)
  • QualysVM: rebuild package at version 3.0.9 and update solution data version
  • Removed empty Instructions
  • Add KQL validator skip for Possible device code phishing query (AADSignInEventsBeta beta table); reword 3.0.15 release notes
  • Update ReleaseNotes.md
  • Microsoft Defender XDR: remove empty groupBy arrays from PossibleWebpBufferOverflow rule
  • mainTemplate update
  • MPL handling enhanced
  • deprecate Zoom Reports (via Azure function)
  • change title of the AzFun json file
  • BlueVoyant Anthropic ClaudeCompliance v3.0.0
  • update
  • UPDATE THE FILE NAME
  • copilot fixes
  • Update CiscoSEG and Infoblox package templates
  • support new Auth Types: CiscoDuo, CommVault, VisaXpayToken, BarracudaWAF, and EdgeGrid
  • SentinelOne: add multi-instance CCP connector support and package as … (SentinelOne: add multi-instance CCP connector support and package as … Azure/Azure-Sentinel#14406)
  • [ASIM] Fix ASIM workflows ([ASIM] Fix ASIM workflows Azure/Azure-Sentinel#14499)
  • Remove test code ([ASIM] Remove test code from testing workflows Azure/Azure-Sentinel#14501)
  • Update ReleaseNotes.md
  • Update Mulesoft ReleaseNotes for 3.1.0
  • Update README with AWS Config connector details
  • Update AWS Config CCF connector details
  • Update CiscoSEG & Infoblox NIOS to 3.0.5
  • Fix typo in CiscoSEG rule name, update package
  • Update analytic rule to 1.0.3 and APIs
  • Align ReleaseNotes table formatting
  • fix(vaikora-asc): build poll URL in a Compose action to satisfy arm-ttk URIs rule
  • fix(vaikora-sentinelone): build poll URL in a Compose action to satisfy arm-ttk URIs rule
  • fix(vaikora-crowdstrike): build poll URL in a Compose action to satisfy arm-ttk URIs rule
  • Bump PossibleWebpBufferOverflow detection version 1.1.2 -> 1.1.3
  • [ASIM] Netskope AlertEvent Parser ([ASIM] Netskope AlertEvent Parser Azure/Azure-Sentinel#14493)
  • Release version 2.3.0 with new features and updates
  • Bump plugin version to v2.3.0 and update release date
  • Update plugin version in README.md
  • Update 3.0.15.zip to match mainTemplate.json (analyticRuleVersion10: 1.1.3)
  • Update mainTemplate.json
  • Update 3.0.3.zip
  • Fix connector entries & update apiVersion
  • Bump package/template to 3.0.1
  • [ASIM] Add ASIM pr reviewer skill ([ASIM] Add ASIM pr reviewer skill Azure/Azure-Sentinel#14510)
  • fix(ZeroFox Threat Intelligence): fix solution id for publishing

ebenshoshan and others added 30 commits May 25, 2026 13:20
…W) solution

Removed the Premium Microsoft Defender Threat Intelligence data connector
from the solution package. The connector is no longer bundled in new
installs (v3.0.19). Kept in StaticDataConnectorIds for backward
compatibility with existing deployments.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…seNotes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace Microsoft Monitoring Agent (MMA) with Azure Monitoring Agent (AMA)
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…ntId is empty

Get_Vaikora_Actions built the URI by always concatenating 'agent_id=' to the query string. When VaikoraAgentId is empty (the documented use case for monitoring all agents), the request became /actions?agent_id=&per_page=100, which the Vaikora API rejects with HTTP 422 because Pydantic cannot parse '' as a UUID.

Fix wraps the agent_id segment with an if(empty(...)) check so it is omitted entirely when blank.

Verified end-to-end against api.vaikora.com on a real Sentinel workspace: Get_Vaikora_Actions now returns 200 OK and the rest of the playbook chain (Filter_High_Severity_Or_Anomaly, List_STAR_Rules, etc.) runs as designed.

arm-ttk local: 49/49 pass on Package/3.0.1.zip. 3.0.0.zip retained per repo policy.
…ntId is empty

Get_Vaikora_Actions built the URI by always concatenating 'agent_id=' into the query string. When VaikoraAgentId is empty (the documented use case for monitoring all agents), the request becomes /actions?agent_id=&per_page=100, which the Vaikora API rejects with HTTP 422 because Pydantic cannot parse '' as a UUID.

Fix wraps the agent_id segment with an if(empty(...)) check so it is omitted entirely when blank.

Verified end-to-end against api.vaikora.com on a real Sentinel workspace: Get_Vaikora_Actions now returns 200 OK with URL https://api.vaikora.com/api/v1/actions?per_page=100.

arm-ttk local: 49/49 pass on Package/3.0.1.zip. 3.0.0.zip retained per repo policy.
…ith Vaikora /actions API schema

The 3.0.0 release shipped against an assumed alert-shaped API response. End-to-end testing surfaced that the Vaikora /api/v1/actions endpoint returns action-shaped events. Concrete defects in 3.0.0:

- Poll_Vaikora_Actions always sent agent_id=, even when VaikoraAgentId was blank. Vaikora API returns HTTP 422 because Pydantic cannot parse '' as a UUID.
- Send_to_Log_Analytics crashed with InvalidTemplate because replace() ran against null title/description fields that do not exist on the response.
- Filter_High_Risk_Actions referenced threat_detected, which is missing from the response.
- The three analytic rules queried Vaikora_SecurityAlerts_CL with columns (AlertId_s, Title_s, Description_s, SourceIP_s, UserName_s, etc.) that the playbook never wrote.
- The standalone playbook wrote to Vaikora_SecurityAlerts; the mainTemplate inner playbook wrote to Vaikora_AgentSignals. Same solution shipped two divergent target tables.

This PR aligns everything on the action-field schema and the Vaikora_AgentSignals_CL table:

- Poll_Vaikora_Actions URI now omits agent_id when VaikoraAgentId is empty.
- Send_to_Log_Analytics body rewritten to action fields (action_id, agent_id, action_type, resource_type, resource_id, status, severity, policy_id, policy_decision, is_anomaly, anomaly_score, anomaly_reason, log_hash, timestamp) with coalesce guards on nullable values. Log-Type set to Vaikora_AgentSignals.
- is_anomaly wrapped with toLower(string(coalesce(...))) so it serializes as JSON true/false instead of Logic Apps' default True/False, which json() refuses to parse.
- Parse_Response schema accepts nullable fields so rows where anomaly_reason or other optional fields are null pass validation.
- Filter_High_Risk_Actions drops the threat_detected check; mainTemplate inner playbook mirrors the fix.
- All three analytic rules rewritten to query Vaikora_AgentSignals_CL with action-field columns.
- entityMappings reduced to agent_id -> Account.Name.
- alertDetailsOverride placeholders updated and kept at or below the 3-placeholder cap.
- Solution description updated to reference Vaikora_AgentSignals_CL.

Validated end-to-end against api.vaikora.com on a real Sentinel workspace: full chain (Poll_Vaikora_Actions -> Parse_Response -> Filter_High_Risk_Actions -> For_Each_Security_Alert -> Send_to_Log_Analytics) all succeed. LA Data Collector API returned HTTP 200 with the action JSON including populated anomaly_reason.

arm-ttk local: 49/49 pass on Package/3.0.1.zip. 3.0.0.zip retained per repo policy.
Updated change history text to explicitly state the connector was removed
from the solution package (not just deprecated). Fixed table separator
to use validator-friendly format.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
v-sabiraj and others added 30 commits June 17, 2026 14:46
Rename Analytic Rules/CiscoSEGUnexpextedAttachment.yaml to CiscoSEGUnexpectedAttachment.yaml (fix typo) and remove executable bit; update Solution_CiscoSEG.json to reference the new filename and bump Version to 3.0.5; update packaged 3.0.5.zip and mainTemplate.json description to reflect the corrected rule name and version.
Bump analytic rule version and product id from 1.0.2 to 1.0.3 for the DNS solution, update savedSearches resources to apiVersion 2025-07-01, and apply structural/fmt adjustments to entity mappings and requiredDataConnectors ordering in mainTemplate.json. Also update the packaged 3.0.1.zip to include these changes.
Update Azure Function based connector to Python 3.12
Adjust whitespace in Solutions/BlueVoyant Anthropic ClaudeCompliance/ReleaseNotes.md to align the Markdown table columns for the 3.0.0 entry. No functional content changes—only formatting.
…solution-bv-claudecompliance-3-0-0

BlueVoyant Anthropic ClaudeCompliance v3.0.0
…tk URIs rule

The agent_id-omit fix placed a conditional concat() inside the HTTP poll
action's uri. arm-ttk 'URIs Should Be Properly Constructed' rejects concat or
format anywhere in a uri/url property, so it failed in v-shukore's local run
even though Sentinel CI's bundled arm-ttk subset passed.

Moved the URL construction into a Compose action and reference its output from
the uri (@{outputs('Compose_Poll_Endpoint')}). The action name deliberately
avoids a uri/url suffix, otherwise arm-ttk's key match ('ur[il]$') would treat
the action object itself as a uri property and re-flag the concat.

Runtime behavior is unchanged: empty VaikoraAgentId still omits the agent_id
query param. Applied to the package mainTemplate inner playbook and the
standalone azuredeploy.json; repackaged 3.0.1.zip.
…fy arm-ttk URIs rule

Same fix as Vaikora-ASC: the agent_id-omit conditional used concat() inside the
HTTP poll uri, which arm-ttk 'URIs Should Be Properly Constructed' rejects
(concat/format disallowed in any uri/url property). Moved URL construction into
a Compose action and the poll now reads "uri": "@{outputs('Compose_Poll_Endpoint')}".
The action name avoids a uri/url suffix so arm-ttk's key match doesn't re-flag it.
Runtime behavior unchanged. Applied to package mainTemplate + standalone playbook;
repackaged 3.0.1.zip.
…fy arm-ttk URIs rule

Same proactive fix as Vaikora-ASC/SentinelOne: the agent_id-omit conditional
used concat() inside the HTTP poll uri, which upstream arm-ttk 'URIs Should Be
Properly Constructed' rejects. Moved URL construction into a Compose action
(running after Get_CrowdStrike_Token, preserving the chain); the poll now reads
"uri": "@{outputs('Compose_Poll_Endpoint')}". Runtime behavior unchanged.
Applied to package mainTemplate + standalone playbook; repackaged 3.0.1.zip.
CI 'checkThatTemplatesVersionWasChanged' requires detection templates to have their version bumped when modified. Bump version in PossibleWebpBufferOverflow.yaml and manually update analyticRuleVersion10 in mainTemplate.json per maintainer guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* [ASIM] Netskope AlertEvent Parser

* correct sample logs file name and format

* copilot review

* correct changelog dates
Added optional Id configuration for telemetry, DCR stream logging, enabled compatibility with Logstash 9.4, and updated dependency versions.
Updated plugin version and release date in README.
…1.1.3)

The zip package contained the old version (1.1.2) for PossibleWebpBufferOverflow.
Both the standalone mainTemplate.json and the copy inside the zip must be identical.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…rdcoded-uri

Microsoft Defender XDR: fix ARM-TTK hardcoded URI false positives in …
Update README with AWS Config connector details and the
Updating documentation for Logstash plugin v2.3.0
Normalize requiredDataConnectors objects in mainTemplate.json (move connectorId before dataTypes and remove duplicate misplaced entries) and bump Microsoft.OperationalInsights savedSearches/apiVersion from 2022-10-01 to 2025-07-01. Also update the packaged 3.0.5.zip binary for the CiscoSEG solution.
Update Vaikora-CrowdStrike ThreatIntelligence package to template version 3.0.1: adjust playbook description and solution "version" field, add "lastPublishDate", and include the updated 3.0.1 package ZIP.
Update CiscoSEG and Infoblox package templates
…ke-v3.0.1-agent-id-fix

Vaikora-CrowdStrike v3.0.1 — omit empty agent_id query param
…ne-v3.0.1-agent-id-fix

Vaikora-SentinelOne v3.0.1 — omit empty agent_id query param
…1-agent-id-fix

Vaikora-AzureSecurityCenter v3.0.1 — align playbook + analytic rules with Vaikora /actions API schema
Updating Solution Metadata to change ownership from Microsoft to Sailpoint
* Add PR reviewer skill

* Update description

* Update

---------

Co-authored-by: Derrick Lee <derricklee@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.