-
Notifications
You must be signed in to change notification settings - Fork 3.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Outdated hunting query for AzureRunCommandMDELinked #11686
Comments
Hi @mgijo , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks! |
@mgijo, To help us investigate and resolve the problem, could you please share the relevant logs from your environment? Specifically, we need logs that include: |
@mgijo , Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive response by 10-02-2025, we will close this issue. |
Sure, I can share. Could you provide a secure upload location for these logs? I am not comfortable uploading raw logs to public Github. Thanks! |
@mgijo, Thanks for your reply! |
@mgijo, Colud you please share relevant logs ASAP! |
@mgijo , Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive response by 18-02-2025, we will close this issue. |
@mgijo , Since we have not received a response in the last 5 days, we are closing your issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation! |
Describe the bug
The existing hunting query for Azure VM Run Command linked with MDE located here is outdated https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/MultipleDataSources/AzureRunCommandMDELinked.yaml
To Reproduce
I tried executing this in my environment and don't see any results. I have made few changes to the query that helped me get some results. But again the KQL line that mentions | where PowershellFileCreatedTimestamp between (StartTime .. EndTime) probably needs fixing. Some other fixes I found that needs to be done with this hunting query:-
This query seems to be outdated since it was built 4 years ago. I would recommend a review and fix on this.
The text was updated successfully, but these errors were encountered: