- add
Sonicwall FW
package, version 3.1.1 f3bce66 - bump package template version to 3.0.1 + update embedded rules cbac931
- bump package template version to 3.0.3 0908383
- bump package template version to 3.0.3 a53b71f
- bump package template version to 3.0.9 + update embedded rules d92914e
- bump
AWS
package template version to 3.0.3 + update embedded rules 7175582 - bump
AWS
package template version to 3.0.4 + update embedded rules a7f49af - bump
Entra ID
package template version to 3.2.10 + update embedded rules 59455e7 - bump
Okta
package template version to 3.1.0 + update embedded rules 65b38f2 - bump
Okta
package template version to 3.1.1 f19dd21 - bump
SentinelOne
package template version to 3.0.3 72b09ea - bump
Sonicwall FW
package template version to 3.1.2 + update embedded rules e1dbbd7 - bump
Threat Intelligence
package template version to 3.0.8 b583915
- deps: update dependency opentofu to v1.8.8 034f42f
- deps: update dependency opentofu to v1.9.0 fee3490
- deps: update dependency tflint to v0.55.0 53bd9f7
- deps: update dependency trivy to v0.58.1 fc5735b
- deps: update dependency trivy to v0.58.2 40bf80e
- deps: update pre-commit hook alessandrojcm/commitlint-pre-commit-hook to v9.20.0 1fb1fac
- deps: update tools 7cbe176
- update tflint config for v0.55.0 939add7
- add
Cloudflare
package. Version 3.0.1 61b51d5 - add
Sophos Endpoint
package. Version : 3.0.5 7cb5043 - bump
Fortigate
package template version to 3.0.7 8a51888 - bump
Microsoft XDR
package template version to 3.0.10 d7de871 - bump
Okta
package template version to 3.0.10 e1697b8 - bump
Threat Intelligence
package template version to 3.0.7 + update embedded rules 913b73c
- deps: update dependency opentofu to v1.8.6 99e7f43
- deps: update dependency tflint to v0.54.0 383b037
- deps: update dependency trivy to v0.57.1 02fdf23
- deps: update pre-commit hook alessandrojcm/commitlint-pre-commit-hook to v9.19.0 4124ae5
- deps: update tools 4acfc46
- bump
Google Workspace
package template version to 3.0.0 + update embedded rule 15d5871 - bump
Okta
package template version to 3.0.9 aa9f128 - bump
Windows Security
package template version to 3.0.9 61282ae
- deps: update dependency opentofu to v1.8.4 f358bf1
- deps: update dependency pre-commit to v4.0.1 a18555d
- deps: update dependency trivy to v0.56.2 946d03a
- deps: update pre-commit hook tofuutils/pre-commit-opentofu to v2.1.0 ab51515
- remove deprecated rule
TI Map URL Entity to OfficeActivity Data
b83a6c8 - update examples structure 9a2b948
- update submodule READMEs with terraform-docs abf7aae
- deps: update dependency opentofu to v1.8.3 757793b
- deps: update dependency pre-commit to v4 f74756a
- deps: update dependency trivy to v0.56.1 765df25
- deps: update pre-commit hook pre-commit/pre-commit-hooks to v5 d501092
- prepare for new examples structure 80dd516
- add
Azure Activity
package. Version 3.0.2 0deec06 - add
Azure Key Vault
package. Version 3.0.2 3ae0f95 - add
Azure Network Security Groups
package. Version 2.0.2 6141676 - add
CyberArk PAM
package. Version 3.0.2 43dbcb8 - add
Darktrace
package. Version 2.0.1 df38dc5 - bump
Microsoft XDR
package template version to 3.0.9 63db4a8 - bump
Threat Intelligence
package template version to 3.0.6 + update embedded rules ba84cd1
- bump
Microsoft 365
package template version to 3.0.4 + update embedded rules 090edd3 - bump
SentinelOne
package template version to 3.0.2 + update embedded rules 10dc65c - bump
Syslog
package template version to 3.0.6 + update embedded rules dda103d - bump
Threat Intelligence
package template version to 3.0.5 3e9fa2a - use Claranet "azurecaf" provider eb71b6b
- update README badge to use OpenTofu registry b6c4c50
- deps: update dependency opentofu to v1.8.2 146f426
- deps: update dependency terraform-docs to v0.19.0 7159978
- deps: update dependency trivy to v0.55.0 61750a5
- deps: update dependency trivy to v0.55.1 bf6f91a
- deps: update dependency trivy to v0.55.2 f228f5b
- deps: update pre-commit hook alessandrojcm/commitlint-pre-commit-hook to v9.18.0 34775f2
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.94.1 f556d6a
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.94.2 3c8d2c4
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.94.3 b46eca9
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.95.0 d611135
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.96.0 8bd13a6
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.96.1 5c28e54
- bump
Cisco Meraki
package template version to 3.0.2 dd2e59b - bump
Fortinet Fortigate
package template version to 3.0.6 e487159 - bump
Microsoft Entra ID
package template version to 3.2.9 + update embedded rules bba0ca4 - bump
Okta
package template version to 3.0.8 ca5d4ba - bump
Zscaler Private Access
package template version to 3.0.0 + update embedded rules a40fc3d
- deps: update pre-commit hook alessandrojcm/commitlint-pre-commit-hook to v9.17.0 8cc2704
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.92.3 20c8d0d
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.93.0 03fd14c
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.94.0 c984e94
- bump
Threat Intelligence
package template version to 3.0.4 + update embedded rules 81ff4ba - bump
Zscaler Internet Access
package template version to 3.0.2 + update embedded rules 5aef988
- deps: update dependency tflint to v0.53.0 535588f
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.92.2 86935b5
- bump
Microsoft Entra ID
package template version to 3.2.8 + update embedded rules 82884f0 - bump
Syslog
package template version to 3.0.5 45d88b6 - bump
Windows Security
package template version to 3.0.8 739d088 - bump
Zscaler Internet Access
package template version to 3.0.1 + update embedded rules fc0eacc
- deps: update dependency opentofu to v1.8.0 69d26c7
- deps: update dependency opentofu to v1.8.1 c85bff5
- deps: update dependency pre-commit to v3.8.0 6f4a906
- deps: update dependency trivy to v0.54.1 0d22701
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.92.1 91f6afe
- bump
Azure WAF
package template version to 3.0.1 + update embedded rules 2cc051d - bump
Common Event Format
package template version to 3.0.1 2a9b3b5 - bump
Microsoft 365
package template version to 3.0.3 + update embedded rules e43c20e - bump
Microsoft Entra ID
package template version to 3.2.7 + update embedded rules 952d148 - bump
Microsoft XDR
package template version to 3.0.8 + update embedded rules 1f42c19 - bump
Syslog
package template version to 3.0.4 + update embedded rules bc263d8 - bump
Windows Security
package template version to 3.0.7 + update embedded rules bded994
- deps: update dependency opentofu to v1.7.3 fb63ed5
- deps: update dependency tflint to v0.51.2 3d59089
- deps: update dependency tflint to v0.52.0 36530ed
- deps: update dependency trivy to v0.52.1 eb5088b
- deps: update dependency trivy to v0.52.2 4e10ecc
- deps: update dependency trivy to v0.53.0 95b6470
- deps: update pre-commit hook antonbabenko/pre-commit-terraform to v1.92.0 084770f
- bump
Common Event Format
package template version to 3.0.0 d04d177 - bump
Microsoft Entra ID
package template version to 3.2.5 + update embedded rules c5d25a1 - bump
Microsoft XDR
package template version to 3.0.7 + update embedded rules 4961083
- correct entity for rule
External user added and removed in short timeframe
efca180
- deps: update dependency opentofu to v1.7.2 b7fe26e
- deps: update dependency trivy to v0.52.0 4ffbdf9
- bump
Windows Security
package template version to 3.0.6 + update embedded rules 0b5a022
- correct entity for rule
External user added and removed in short timeframe
61c8b82
- deps: update dependency terraform-docs to v0.18.0 fa9ebd8
- deps: update dependency trivy to v0.51.4 1f803aa
- AZ-1411: add
Azure Web Application Firewall
package f521366 - bump
Microsoft 365
package template version to 3.0.2 + update embedded rules 0bce161 - bump
Microsoft XDR
package template version to 3.0.6 + update embedded rules cf38130
- deps: update dependency trivy to v0.51.2 fc7cca0
- bump
Microsoft XDR
package template version to 3.0.5 + update embedded rules 7d3b911 - bump
SentinelOne
package template version to 3.0.1 727ccfa
- correct entities for rule
Possible Phishing with CSL and Network Sessions
08a77e2
- deps: update dependency opentofu to v1.7.1 3c72b13
- deps: update dependency pre-commit to v3.7.1 9af19df
- deps: update dependency tflint to v0.51.1 b37351d
- deps: update dependency trivy to v0.51.0 bdb8b0a
- deps: update dependency trivy to v0.51.1 d20e8ba
- bump
Azure Firewall
package template version to 3.0.4 + update embedded rules c27111b - bump
Microsoft XDR
package template version to 3.0.4 + update embedded rules ed2e42d - bump
Okta
package template version to 3.0.7 97743f5 - bump
Syslog
package template version to 3.0.3 + update embedded rules 812f234 - bump
Threat Intelligence
package template version to 3.0.3 + update embedded rules 54c5260 - bump
Windows Security
package template version to 3.0.5 + update embedded rules ffeef41
- deps: update dependency opentofu to v1.7.0 8764e9f
- deps: update dependency tflint to v0.51.0 850b5e8
- AzAPI: provider pinned
< v1.13
to avoid breaking changes 3e7b40a
- deps: update dependency trivy to v0.50.2 dfc9c23
- deps: update dependency trivy to v0.50.4 19a428a
- deps: update renovate config for azure one + automerge 7d44cdf
- pre-commit: update commitlint hook acba527
- release: remove legacy
VERSION
file 1defa8b
- AZ-1389: remove duplicate MITRE Technique value on these 2 rules:
AWS Config Service Resource Deletion Attempts
andSuspicious AWS CLI Command Execution
3dab5f2 - AZ-1389: update AWS package template to 3.0.2 version 65beebc
- AZ-1391: enable semantic-release [skip ci] 4b3f1de
- AZ-1391: update semantic-release config [skip ci] 6c928b7
Changed
- AZ-1389: Add
incidentConfiguration
block +CloudApplication
entity for these 2 rules:NRT New access credential added to Application or Service Principal
andNRT First access credential added to Application or Service Principal where no credential was present
Fixed
- AZ-1387: README typos
Added
- AZ-1365: Microsoft Sentinel Content module first release