Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Machine_Learning_Creation.yaml #11766

Open
wants to merge 6 commits into
base: master
Choose a base branch
from
Open

Conversation

mgstate
Copy link
Contributor

@mgstate mgstate commented Feb 5, 2025

Machine learning creation event analytic

Required items, please complete

Change(s):

Added a new detection rule for Azure Machine Learning Write Operations.
Updated the YAML configuration to include tactics and techniques relevant to potential rogue access or resource creation.
Reason for Change(s):

To monitor and investigate write operations on Azure Machine Learning resources, ensuring that any unauthorized access or resource creation is detected.
Resolves ISSUE #1234 (if applicable).
Version Updated:

Yes
Detections/Analytic Rule templates are required to have the version updated.
Testing Completed:

Yes
The code has been tested in a Microsoft Sentinel environment to validate syntax and execution.
Checked that the validations are passing and have addressed any issues that are present:

Yes

Machine Learning Analytic rule creation
@mgstate mgstate requested review from a team as code owners February 5, 2025 13:50
@v-prasadboke v-prasadboke self-assigned this Feb 6, 2025
@v-prasadboke v-prasadboke added Solution Solution specialty review needed Analytic Rules labels Feb 6, 2025
@mgstate
Copy link
Contributor Author

mgstate commented Feb 6, 2025

Not exactly sure why ran against detecction and workbook template, anything specific i need to change? mine looks exacly like the current yaml files in analytics

@mgstate
Copy link
Contributor Author

mgstate commented Feb 11, 2025

@v-prasadboke anything I need to change here
Confused on the template failures for the workbook template and so forth

@v-prasadboke
Copy link
Contributor

Please add field query period. you can refer to any of the analytic rule from the solution. you keep it null as well.

also please take a look at failing validation for api in workbook

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Analytic Rules Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants