Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat][New Module] Adding support for Microsoft Defender ATP #19197

Merged
merged 22 commits into from
Jul 14, 2020
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
4d3ebf8
atp MVP push
P1llus Jun 12, 2020
27a60ba
stashing changes for later
P1llus Jun 12, 2020
86e8f72
Initial MVP for Defender ATP
P1llus Jun 15, 2020
f344d42
Updating default config
P1llus Jun 15, 2020
443ac5d
some updates, still not complete before more testing with new httpjso…
P1llus Jun 18, 2020
0296140
added new things to the pipeline, sorted them and commented them for …
P1llus Jun 20, 2020
24c655f
updated ingest pipeline with more ECS fields and evidence fields
P1llus Jun 25, 2020
cb01b5e
updated pipelines to fix yml indentations and added date_cursor funct…
P1llus Jun 30, 2020
6be6205
mage fmt update
P1llus Jun 30, 2020
cbf15f4
applying some new changes for date cursor and rebasing
P1llus Jul 4, 2020
8d6b316
Cleaning up pipelines, adding testdata, updating config fields, makin…
P1llus Jul 5, 2020
b46e849
changes to generate golden files
leehinman Jul 6, 2020
31ace16
adding requested changes based on PR comments, fixing some field type…
P1llus Jul 7, 2020
e7132bc
adding null checks for evidence subfield
P1llus Jul 7, 2020
37eeb56
updating painless scripts
P1llus Jul 7, 2020
db32b3a
mage fmt update
P1llus Jul 9, 2020
fc70654
one last styling change, will need to revert the event.test.message o…
P1llus Jul 9, 2020
a23be78
update golden files
P1llus Jul 9, 2020
fcb1082
updating tests to ignore timestamp and event.ingested
P1llus Jul 9, 2020
00b9f63
temp removing the default text for dashboard, dashboard will be inclu…
P1llus Jul 10, 2020
a4e762a
Merge branch 'master' into filebeat_atp_module_mvp
P1llus Jul 14, 2020
937975b
updating docs due to merge with microsoft dhcp
P1llus Jul 14, 2020
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
updating tests to ignore timestamp and event.ingested
  • Loading branch information
P1llus committed Jul 13, 2020
commit fcb1082a0edd38fbcb5e90d5554457f6241c046a
5 changes: 5 additions & 0 deletions filebeat/tests/system/test_modules.py
Original file line number Diff line number Diff line change
Expand Up @@ -264,6 +264,11 @@ def clean_keys(obj):
if "event.end" not in obj:
delete_key(obj, "@timestamp")

# Remove event.ingested from testing, as it will never be the same.
if obj["event.dataset"] == "microsoft.defender_atp":
delete_key(obj, "event.ingested")
delete_key(obj, "@timestamp")


def delete_key(obj, key):
if key in obj:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
[
{
"@timestamp": "2020-07-09T15:30:07.117Z",
"cloud.account.id": "123543-d66c-4c7e-9e30-40034eb7c6f3",
"cloud.instance.id": "c5a964f417c11f6277d5bf9489f0d",
"cloud.provider": "azure",
Expand All @@ -13,7 +12,6 @@
"event.duration": 0,
"event.end": "2020-06-30T10:07:44.333733Z",
"event.id": "da637291085411733957_-1043898914",
"event.ingested": "2020-07-09T15:30:08.724746Z",
"event.kind": "alert",
"event.module": "microsoft",
"event.provider": "defender_atp",
Expand Down Expand Up @@ -52,7 +50,6 @@
"threat.technique.name": "Malware"
},
{
"@timestamp": "2020-07-09T15:30:07.117Z",
"cloud.account.id": "123543-d66c-4c7e-9e30-40034eb7c6f3",
"cloud.instance.id": "543bc5a964f417c11f6277d5bf9489f0d",
"cloud.provider": "azure",
Expand All @@ -65,7 +62,6 @@
"event.duration": 2442699369800,
"event.end": "2020-06-30T09:45:39.5484377Z",
"event.id": "da637291048912199236_1126926584",
"event.ingested": "2020-07-09T15:30:08.808102Z",
"event.kind": "alert",
"event.module": "microsoft",
"event.provider": "defender_atp",
Expand Down Expand Up @@ -119,7 +115,6 @@
"threat.technique.name": "DefenseEvasion"
},
{
"@timestamp": "2020-07-09T15:30:07.117Z",
"cloud.account.id": "43521344-d66c-4c7e-9e30-40034eb7c6f3",
"cloud.instance.id": "53425a964f417c11f6277d5bf9489f0d",
"cloud.provider": "azure",
Expand All @@ -131,7 +126,6 @@
"event.duration": 2442699369800,
"event.end": "2020-06-30T09:45:39.5484377Z",
"event.id": "da637291048912199236_1126926584",
"event.ingested": "2020-07-09T15:30:08.811408Z",
"event.kind": "alert",
"event.module": "microsoft",
"event.provider": "defender_atp",
Expand Down Expand Up @@ -176,7 +170,6 @@
"threat.technique.name": "DefenseEvasion"
},
{
"@timestamp": "2020-07-09T15:30:07.117Z",
"cloud.account.id": "1234543-d66c-4c7e-9e30-40034eb7c6f3",
"cloud.instance.id": "t4563234bc5a964f417c11f6277d5bf9489f0d",
"cloud.provider": "azure",
Expand All @@ -189,7 +182,6 @@
"event.duration": 892514711800,
"event.end": "2020-06-30T09:46:15.0876676Z",
"event.id": "da637291063515066999_-2102938302",
"event.ingested": "2020-07-09T15:30:08.813613Z",
"event.kind": "alert",
"event.module": "microsoft",
"event.provider": "defender_atp",
Expand Down