-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sensor SSH Cowrie solution #11155
base: master
Are you sure you want to change the base?
Sensor SSH Cowrie solution #11155
Commits on Sep 19, 2024
-
As part of Hackathon 2024 a team developed a 1 click deploy solution that will deploy a debain vm, install cowrie, create ama dcr, dce, and association, and create a custom table to collect cowrie events. Solution contains a workbook (under development), 1 parser and 5 detection rules . The goal is make this a framework for others and community to create other 1 click deploy for other types of interactive honeypots. Can be used publicly for TI or privately as a detection tripwire
Configuration menu - View commit details
-
Copy full SHA for 32c524a - Browse repository at this point
Copy the full SHA 32c524aView commit details -
fixing yaml spacing intial validation tests failed.
Configuration menu - View commit details
-
Copy full SHA for 1712052 - Browse repository at this point
Copy the full SHA 1712052View commit details
Commits on Sep 20, 2024
-
Configuration menu - View commit details
-
Copy full SHA for d758d78 - Browse repository at this point
Copy the full SHA d758d78View commit details -
fixed some kql, data connector, workbook validation errors, still researching the permissions on data connector does not match.
Configuration menu - View commit details
-
Copy full SHA for 948d8a6 - Browse repository at this point
Copy the full SHA 948d8a6View commit details -
made a change to fix kql validation removing commas after each extend and new line | extend, also removed txt based parser.
Configuration menu - View commit details
-
Copy full SHA for a8d6828 - Browse repository at this point
Copy the full SHA a8d6828View commit details -
updated to include the vm ext ama
added vm ext ama for linux in deployment.
Configuration menu - View commit details
-
Copy full SHA for 42e025b - Browse repository at this point
Copy the full SHA 42e025bView commit details -
Configuration menu - View commit details
-
Copy full SHA for af08d18 - Browse repository at this point
Copy the full SHA af08d18View commit details -
Configuration menu - View commit details
-
Copy full SHA for ff930f6 - Browse repository at this point
Copy the full SHA ff930f6View commit details -
Configuration menu - View commit details
-
Copy full SHA for 4b1096f - Browse repository at this point
Copy the full SHA 4b1096fView commit details -
fixing detections validation error SourceIP custom colum name to sentinel recognized field Address
Configuration menu - View commit details
-
Copy full SHA for 4d37e6f - Browse repository at this point
Copy the full SHA 4d37e6fView commit details -
Merge branch 'cowrie-nates' of https://github.com/swiftsolves-msft/Az…
…ure-Sentinel into cowrie-nates
Configuration menu - View commit details
-
Copy full SHA for 8d22c73 - Browse repository at this point
Copy the full SHA 8d22c73View commit details
Commits on Sep 22, 2024
-
minor fixes to validation errors
minor fixes to validation errors
Configuration menu - View commit details
-
Copy full SHA for 6079fe0 - Browse repository at this point
Copy the full SHA 6079fe0View commit details
Commits on Sep 23, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 9741efc - Browse repository at this point
Copy the full SHA 9741efcView commit details -
Configuration menu - View commit details
-
Copy full SHA for c84624d - Browse repository at this point
Copy the full SHA c84624dView commit details
Commits on Sep 24, 2024
-
created new kql validator for cowrie
created new kql validator for cowrie
Configuration menu - View commit details
-
Copy full SHA for 0fd490c - Browse repository at this point
Copy the full SHA 0fd490cView commit details -
added | extend for beinging of query line 25
Configuration menu - View commit details
-
Copy full SHA for 8cb08d0 - Browse repository at this point
Copy the full SHA 8cb08d0View commit details
Commits on Sep 25, 2024
-
updated deploy to azure button links and data connector permissions reqs
Configuration menu - View commit details
-
Copy full SHA for 881cc4a - Browse repository at this point
Copy the full SHA 881cc4aView commit details -
changes to data connector to pass kql validations
Configuration menu - View commit details
-
Copy full SHA for 04309df - Browse repository at this point
Copy the full SHA 04309dfView commit details -
Configuration menu - View commit details
-
Copy full SHA for 290ea00 - Browse repository at this point
Copy the full SHA 290ea00View commit details
Commits on Sep 26, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 6291b96 - Browse repository at this point
Copy the full SHA 6291b96View commit details -
Configuration menu - View commit details
-
Copy full SHA for afb1a5a - Browse repository at this point
Copy the full SHA afb1a5aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 432258c - Browse repository at this point
Copy the full SHA 432258cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 9865d7f - Browse repository at this point
Copy the full SHA 9865d7fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 89192e2 - Browse repository at this point
Copy the full SHA 89192e2View commit details -
Configuration menu - View commit details
-
Copy full SHA for ed56e33 - Browse repository at this point
Copy the full SHA ed56e33View commit details -
Configuration menu - View commit details
-
Copy full SHA for c02f6b8 - Browse repository at this point
Copy the full SHA c02f6b8View commit details
Commits on Oct 15, 2024
-
create a custom sample data for Sensor SSH Cowrie solution.
Configuration menu - View commit details
-
Copy full SHA for 0e54dc4 - Browse repository at this point
Copy the full SHA 0e54dc4View commit details -
Merge branch 'cowrie-nates' of https://github.com/swiftsolves-msft/Az…
…ure-Sentinel into cowrie-nates
Configuration menu - View commit details
-
Copy full SHA for 9606399 - Browse repository at this point
Copy the full SHA 9606399View commit details
Commits on Oct 23, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 5c5bab9 - Browse repository at this point
Copy the full SHA 5c5bab9View commit details -
Configuration menu - View commit details
-
Copy full SHA for f762a03 - Browse repository at this point
Copy the full SHA f762a03View commit details
Commits on Nov 7, 2024
-
change solution name to match and added workbook metadata in
Configuration menu - View commit details
-
Copy full SHA for 970fd36 - Browse repository at this point
Copy the full SHA 970fd36View commit details -
Merge branch 'cowrie-nates' of https://github.com/swiftsolves-msft/Az…
…ure-Sentinel into cowrie-nates
Configuration menu - View commit details
-
Copy full SHA for 225b7dd - Browse repository at this point
Copy the full SHA 225b7ddView commit details -
update images for preview for workbook
Configuration menu - View commit details
-
Copy full SHA for 004e725 - Browse repository at this point
Copy the full SHA 004e725View commit details