Giter Site home page Giter Site logo

Comments (6)

shainw avatar shainw commented on September 27, 2024

The Detections are meant to be used as is, but in some cases may need some tuning for a given environment. The HighConfTIDetection is looking at connections that contain a MaliciousIP which is identified by our internal TI feed and automatically joined to the Firewall data as context. While our TI team tries to keep this from getting stale or incorrect data, it is possible the TI is incorrect. In the case of the HighConfTIDetection, it looks like we missed making sure it was a connection versus a blocked connection. If you have other detections that are firing alerts that are incorrect or inconclusive, can you submit additional Issues for those or potentially use our request feedback form to send directly to my team. The form is at the bottom of this Blog - https://techcommunity.microsoft.com/t5/Azure-Sentinel/Azure-Sentinel-Blog-Table-of-Contents/ba-p/731727

I am out of the office until Wednesday, but will have someone look at the HighConfTIDetection while I am out.

Thanks,
Shain

from azure-sentinel.

petebryan avatar petebryan commented on September 27, 2024

@DSharpPro thanks for the feedback, as @shainw said we want to filter out blocked connections. I have made some changes to a couple of rules including HighConfTIDetection.txt, you can see what we have done in the PR (#214).

Please give this updated query a test in your Sentinel workspace and let us know if this improves the fidelity of this detection. We create these queries with the aim to be as widely applicable as possible but vendor log messages differ so we might not have quite the right syntax for every vendor. Can you let us know what firewall vendor you are using and I can try and make sure that is covered in the scope of this query.

Thanks,
Pete

from azure-sentinel.

shainw avatar shainw commented on September 27, 2024

@DSharpPro - Thanks for the participation in general and if you happen to be at Blackhat our team will be at Blackhat and several of us will be at the Azure Sentinel booth, including Pete who did the fix you mentioned above. Hope to see you and any of our other Github contributors. Thanks Shain

from azure-sentinel.

DSharpPro avatar DSharpPro commented on September 27, 2024

Hi @petebryan, @shainw,
We have now updated the queries to reflect the changes you've made. We are running Cisco ASA's.
Also, is it possible to get a list of "malicious IP's" from Microsoft so we can upload to our firewalls so the block list contains both Cisco and Microsoft's data base?
Thanks,

from azure-sentinel.

shainw avatar shainw commented on September 27, 2024

Hey @DSharpPro,
That is not exposed directly that I know of, but I will see if there is a possibility of doing so.
Shain

from azure-sentinel.

shainw avatar shainw commented on September 27, 2024

@DSharpPro - I chatted with our internal TI folks, I was explained that at this time Microsoft does not expose any TI feeds to the public.

from azure-sentinel.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.