Skip to content

Adding a new workbook on Log4j hunting#3812

Merged
v-rucdu merged 12 commits intoAzure:masterfrom
samikroy:patch-13
Jan 12, 2022
Merged

Adding a new workbook on Log4j hunting#3812
v-rucdu merged 12 commits intoAzure:masterfrom
samikroy:patch-13

Conversation

@samikroy
Copy link
Contributor

@samikroy samikroy commented Dec 29, 2021

Change(s):

  • Azure-Sentinel/Workbooks/Log4jPostCompromiseHunting - A new workbook added with the following tabs
    FindTrace - A lookup to curated IOCs across all sentinel tables.
    SecurityNestedRecommendation - This section uses the Azure Defender Security Nested Recommendations data to find
    machines vulnerable to log4j CVE-2021-44228. Log4j is an open-source Apache logging library that is used in many Java-
    based applications. Security Nested Recommendations data is sent to Microsoft Sentinel using the continuous export
    feature of Azure Defender
    AzureDiagnostics - Azure Diagnostics
    MultipleDataSources - Across multiple data sources
    Syslog - From Syslog Sources

  • Azure-Sentinel/Workbooks/WorkbooksMetadata.json - To add workbook metadata.

  • Azure-Sentinel/Workbooks/Images/Logos - To add workbook logo.

  • Azure-Sentinel/Workbooks/Images/Preview - To add preview images.


@v-jayakal v-jayakal self-assigned this Dec 29, 2021
@shainw shainw added the Workbook Workbook specialty review needed label Jan 3, 2022
@v-rucdu v-rucdu merged commit a130832 into Azure:master Jan 12, 2022
@samikroy
Copy link
Contributor Author

@v-rucdu - Thank you for the approval & merge.

@samikroy samikroy deleted the patch-13 branch January 12, 2022 20:13
@samikroy samikroy restored the patch-13 branch January 26, 2022 03:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Workbook Workbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants