Comments (2)
Hi @atgithub11
Thanks for asking about this. As you noted, those two macros evaluate to different sourcetypes. The fields presented in each sourcetype are different, however, AAD data can be ingested with either of those sourcetypes. Detections written against one won't necessarily work against the other without modifying the field names.
cc: @mvelazc0
from security_content.
Thanks @ljstella
I think we should be good with this one. In v4.19.0, all Azure AD correlations were updated to use sourcetype = azure:monitor:aad
from security_content.
Related Issues (20)
- [BUG] ESCU - Detect Excessive Account Lockouts From Endpoint HOT 3
- [BUG] O365 Mailbox Inbox Folder Shared with All Users. Field "object" doesn't exist. HOT 1
- pre trained Deep Learning models for ESCU - Support for DSDL Version 5.1.1 HOT 1
- [BUG] - Unknown Process Using The Kerberos Protocol is too noisy HOT 3
- [BUG] Linux Service Started Or Enabled triggering on Windows events HOT 2
- [BUG] Build is not working HOT 6
- Consider adding Scope for search Azure AD Tenant Wide Admin Consent Granted HOT 1
- [BUG] DNS Query Length With High Standard Deviation HOT 1
- [BUG] Datasource is set incorrectly on this detection
- [BUG] ESCU - Get ADUser with PowerShell - Rule has no Adaptive Reponse Actions HOT 3
- Scheduled Task Initiation on Remote Endpoint - Update Analytics
- Azure AD Multi-Source Failed Authentications Spike - Missing ADFSSignInLogs category
- Minor malicious_powershell_process___encoded_command search update
- [BUG] Detections with joins failed to properly translate to Sigma
- [BUG] Missing Wildcards in Splunk Rule for Detecting Known Services Killed by Ransomware
- [BUG] Incorrect logic statement in detection search "Detect Renamed PSExec"
- [BUG] please, fix links in wiki: https://github.com/splunk/security_content/wiki/Detection-Analytic-Types HOT 1
- [BUG] browser_app_list lookup doesn't exist in indexers, causing query to fail in "Windows Credential Access From Browser Password Store"
- [BUG] `Message` vs. `ScriptBlockText` for Powershell rules HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from security_content.