Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Create Phising emails.txt

Open FabianBorz01 opened this issue 3 years ago • 19 comments

Required items, please complete

Change(s):

  • See guidance below

Reason for Change(s):

  • See guidance below

Version Updated:

  • Required only for Detections/Analytic Rule templates
  • See guidance below

Testing Completed:

  • See guidance below

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

Guidance <- remove section before submitting


Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:

Thank you for your contribution to the Microsoft Sentinel Github repo.

Details of the code changes in your submitted PR. Providing descriptions for pull requests ensures there is context to changes being made and greatly enhances the code review process. Providing associated Issues that this resolves also easily connects the reason.

Change(s):

  • Updated syntax for XYZ.yaml

Reason for Change(s):

  • New schema used for XYZ.yaml
  • Resolves ISSUE #1234

Version updated:

  • Yes
  • Detections/Analytic Rule templates are required to have the version updated

The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly. If your submission requires a custom parser or function, it must be submitted with the PR.

Testing Completed:

  • Yes/No/Need Help

Note: If updating a detection, you must update the version field.

Before the submission has been made, please look at running the KQL and Yaml Validation Checks locally. https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally

Checked that the validations are passing and have addressed any issues that are present:

  • Yes/No/Need Help

Note: Let us know if you have tried fixing the validation error and need help.

References:


FabianBorz01 avatar Jul 22 '22 08:07 FabianBorz01

@aprakash13 : Could you please review the Hunting queries. Thanks!

v-spadarthi avatar Jul 25 '22 12:07 v-spadarthi

@aprakash13 : Could you please review the Hunting queries. Thanks!

v-spadarthi avatar Aug 08 '22 14:08 v-spadarthi

@aprakash13 : Could you please review the Hunting queries. Thanks!

v-spadarthi avatar Sep 05 '22 11:09 v-spadarthi

@aprakash13 : Could you please review the Hunting queries. Thanks!

Hi, How should I review the hunting queries ? Thank you!

FabianBorz01 avatar Sep 05 '22 12:09 FabianBorz01

@aprakash13 : Could you please review the Hunting queries. Thanks!

v-laanjana avatar Sep 08 '22 10:09 v-laanjana

Hi, How should I review the hunting queries ? Thank you!

FabianBorz01 avatar Sep 08 '22 13:09 FabianBorz01

Hi @FabianBorz01 You don't need to review anything. Our team is review and will provide there update. Thanks

NikTripathi avatar Sep 08 '22 19:09 NikTripathi

@FabianBorz01 : Please follow the instructions suggested by @shainw and do the modifications accordingly.

v-spadarthi avatar Sep 15 '22 11:09 v-spadarthi

@FabianBorz01 : Please follow the instructions suggested by @shainw and do the modifications accordingly.

v-spadarthi avatar Sep 20 '22 05:09 v-spadarthi

@FabianBorz01 : Please follow the instructions suggested by @shainw and do the modifications accordingly.

v-spadarthi avatar Sep 22 '22 14:09 v-spadarthi

@FabianBorz01 : Please follow the instructions suggested by @shainw and do the modifications accordingly.

v-spadarthi avatar Sep 26 '22 09:09 v-spadarthi

@FabianBorz01 : Please follow the instructions suggested by @shainw and do the modifications accordingly.

v-spadarthi avatar Sep 28 '22 02:09 v-spadarthi

Hello sir Thank you for your advice. I will do the modifications Thank you so much

On Wed, Sep 28, 2022 at 5:05 AM v-spadarthi @.***> wrote:

@FabianBorz01 https://github.com/FabianBorz01 : Please follow the instructions suggested by @shainw https://github.com/shainw and do the modifications accordingly.

— Reply to this email directly, view it on GitHub https://github.com/Azure/Azure-Sentinel/pull/5686#issuecomment-1260294381, or unsubscribe https://github.com/notifications/unsubscribe-auth/AV7BLM326KR4XF3PSGRGXTDWAORVDANCNFSM54KRFCFQ . You are receiving this because you were mentioned.Message ID: @.***>

FabianBorz01 avatar Sep 28 '22 09:09 FabianBorz01

@FabianBorz01 : Please do the modifications and let us know

v-spadarthi avatar Sep 30 '22 04:09 v-spadarthi

Hi @FabianBorz01, Please refer the sample shared by @shainw and make necessary change to your query. Let us know if you need any help over there. Thanks

v-mchatla avatar Oct 04 '22 20:10 v-mchatla

Hi @FabianBorz01 , Please refer the sample shared by @shainw and make necessary changes to your query. Let us know if you need any help over there. Thanks

v-amolpatil avatar Oct 07 '22 04:10 v-amolpatil

Hi @FabianBorz01 , Please refer the sample shared by @shainw and make necessary changes to your query. Let us know if you need any help over there. Thanks

v-spadarthi avatar Oct 11 '22 07:10 v-spadarthi

Hi @FabianBorz01 , Please refer the sample shared by @shainw and make necessary changes to your query. Let us know if you need any help over there. Thanks

v-spadarthi avatar Oct 13 '22 14:10 v-spadarthi

Hi @FabianBorz01 , Please refer the sample shared by @shainw and make necessary changes to your query. Let us know if you need any help over there. Thanks

v-spadarthi avatar Oct 17 '22 07:10 v-spadarthi

Hi @FabianBorz01 , Please refer the sample shared by @shainw and make necessary changes to your query. Let us know if you need any help over there. Thanks

v-spadarthi avatar Oct 19 '22 05:10 v-spadarthi

@FabianBorz01 We wanted to check on the status of PR https://github.com/Azure/Azure-Sentinel/pull/5686 . PR is pending from more than 60 days. Let us know if any assistance is required for this PR. As Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR. Thank you for your cooperation.

v-spadarthi avatar Oct 20 '22 07:10 v-spadarthi

Waiting for the update from author

v-spadarthi avatar Oct 25 '22 07:10 v-spadarthi

Waiting for the update from author

v-spadarthi avatar Oct 28 '22 04:10 v-spadarthi

Waiting for the update from author

v-spadarthi avatar Oct 31 '22 05:10 v-spadarthi

Hi @FabianBorz01 Since we have not received response from last 7 days, we are closing your PR per our standard operating procedures. If you still need support for this issue you can re-open the PR at any time. If you do re-open, we simply request that you ensure the PR has response to the last request. Thank you for your cooperation.

v-spadarthi avatar Nov 01 '22 06:11 v-spadarthi