July 3, 2024 - Content Release
This content release includes new and updated rules, log mappers, and parsers. Details are enumerated below.
Rules​
- [Updated] MATCH-S00139 Abnormal Parent-Child Process Combination
- Removed leading backslash from like matches
Log Mappers​
- [New] ApplicationGatewayAccessLog
- [New] ApplicationGatewayFirewallLog
- [New] Citrix NetScaler - TCP-CONN_TERMINATE
- [New] Google G Suite - login - password_change/recovery_info_change
- [New] Google G Suite - login-blocked_sender_change
- [New] JFrog Artifactory - Access logs
- [New] JFrog Artifactory - Login Access logs
- [New] JFrog Artifactory - Request Logs
- [New] Synergis Genetec - all
- [Updated] AWS EKS - Custom Parser
- Keys updated:
'srcDevice_ip'
,'http_response_statusCode'
,'http_url'
,'http_userAgent'
,'user_username'
,'user_userId'
,'action'
,'device_k8s_namespace'
- Keys updated:
- [Updated] Abnormal Security Threats
- Keys updated:
'threat_referenceUrl'
,'email_subject'
,'resource'
,'email_sender'
,'user_email'
,'user_username'
,'targetUser_email'
,'action'
,'threat_identifier'
,'user_authDomain'
,'srcDevice_ip'
,'email_messageId'
,'srcDevice_hostname'
,'threat_name'
,'threat_category'
,'timestamp'
- Keys updated:
- [Updated] Cisco ASA 305011-12 JSON
- Keys updated:
'user_authDomain'
,'user_username'
- Keys updated:
- [Updated] GitHub JSON
- Keys updated:
'user_username'
,'user_role'
,'user_userId'
,'description'
,'http_url'
,'device_hostname'
- Keys updated:
- [Updated] SentinelOne Logs - Syslog Custom Parser
- Keys updated:
'srcDevice_osName'
- Keys updated:
Parsers​
- [New] /Parsers/System/Atlassian/Atlassian Jira
- [New] /Parsers/System/Genetec/Genetec Synergis
- [New] /Parsers/System/Github/Github
- [New] /Parsers/System/JFrog/JFrog Artifactory
- [Updated] /Parsers/System/AWS/AWS EKS
- [Updated] /Parsers/System/Abnormal Security/Abnormal Security
- [Updated] /Parsers/System/Cisco/Cisco ASA
- [Updated] /Parsers/System/Citrix/Citrix NetScaler Syslog
- [Updated] /Parsers/System/Cylance/Cylance Syslog
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
- [Updated] /Parsers/System/Orca Security/Orca Security
- [Updated] /Parsers/System/SentinelOne/SentinelOne CEF