Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI_Creation_Events #11754

Open
wants to merge 3 commits into
base: master
Choose a base branch
from
Open

AI_Creation_Events #11754

wants to merge 3 commits into from

Conversation

mgstate
Copy link

@mgstate mgstate commented Feb 3, 2025

Machine learning creation event

Required items, please complete

Change(s):

Added a new detection rule for Azure Machine Learning Write Operations.
Updated the YAML configuration to include tactics and techniques relevant to potential rogue access or resource creation.
Reason for Change(s):

To monitor and investigate write operations on Azure Machine Learning resources, ensuring that any unauthorized access or resource creation is detected.
Resolves ISSUE #1234 (if applicable).
Version Updated:

Yes
Detections/Analytic Rule templates are required to have the version updated.
Testing Completed:

Yes
The code has been tested in a Microsoft Sentinel environment to validate syntax and execution.
Checked that the validations are passing and have addressed any issues that are present:

Yes

Machine learning creation event
@mgstate mgstate requested review from a team as code owners February 3, 2025 18:21
@mgstate
Copy link
Author

mgstate commented Feb 3, 2025

@microsoft-github-policy-service agree

@v-prasadboke v-prasadboke added Solution Solution specialty review needed Hunting Hunting specialty review needed labels Feb 4, 2025
@v-shukore
Copy link
Contributor

Hi @mgstate, the key 'ID' is not present in this analytic rule. Please add it to the rule. You can refer any rule from our repo. Thanks.

@mgstate
Copy link
Author

mgstate commented Feb 4, 2025

Hi @mgstate, the key 'ID' is not present in this analytic rule. Please add it to the rule. You can refer any rule from our repo. Thanks.

I see - the appropriate modifications have been made @v-prasadboke @v-shukore

@mgstate
Copy link
Author

mgstate commented Feb 4, 2025

Hi @mgstate, the key 'ID' is not present in this analytic rule. Please add it to the rule. You can refer any rule from our repo. Thanks.

I see - the appropriate modifications have been made @v-prasadboke @v-shukore

sorry meant to put @v-shukore

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Hunting Hunting specialty review needed Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants