Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve Microsoft Sentinel export process #17

Merged
merged 3 commits into from
Sep 19, 2024
Merged

Conversation

0xFustang
Copy link
Collaborator

Description

In this PR, we're improving Microsoft Sentinel export process but also:

  • Ability to export rules to a restricted list of Microsoft Sentinel workspaces (--mssp and --export mode)
  • When possible, add the MITRE ATT&CK tactics and techniques to the rule
  • Add new environment variables to override the authentication mode for Microsoft Sentinel and Microsoft XDR

Documentation updated: https://certeu.github.io/droid-docs/platforms/microsoft_sentinel/

@0xFustang 0xFustang self-assigned this Sep 19, 2024
@0xFustang 0xFustang merged commit a14f018 into main Sep 19, 2024
2 checks passed
@0xFustang 0xFustang deleted the sentinel-export-feature branch September 19, 2024 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant