{"id":525,"date":"2023-01-09T01:15:46","date_gmt":"2023-01-09T00:15:46","guid":{"rendered":"https:\/\/mortenknudsen.net\/?p=525"},"modified":"2023-01-09T13:46:23","modified_gmt":"2023-01-09T12:46:23","slug":"sentinel-alert-rules-management-with-add-update-remove-alert-rule-action-automation","status":"publish","type":"post","link":"https:\/\/mortenknudsen.net\/?p=525","title":{"rendered":"Sentinel Alert Rules Management with Add \/ Update \/ Remove &#038; Alert Rule Action automation"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Do you want to automate alert rules including <strong>creating new alert rules<\/strong> and <strong>update existing<\/strong> &#8211; with <strong>checks every x hours<\/strong> so your environment is <strong>continuously updated<\/strong> to <strong>help<\/strong> <strong>detect new threats<\/strong>? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do you want to <strong>keep your Sentinel Alert Rules updated<\/strong> with<strong> latest Alert Rules templates from Microsoft <\/strong>so <strong>queries<\/strong>, <strong>entity-support gets updated<\/strong> and new features come into play?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do you want to <strong>support new rule types<\/strong> as they get released ?<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"313\" height=\"428\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/methods.jpg\" alt=\"\" class=\"wp-image-535\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/methods.jpg 313w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/methods-219x300.jpg 219w\" sizes=\"auto, (max-width: 313px) 100vw, 313px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Maybe you want to <strong>have a default alert rule action<\/strong> like &#8216;<strong>Send mail<\/strong>&#8216; linked to your alert rules in case you want to use a logic app to distribute the emails depending on who should receive the alert.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If yes, keep reading and get inspired with the possibilities and a few challenges \ud83d\ude42<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate-1024x589.jpg\" alt=\"\" class=\"wp-image-531\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate-1024x589.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate-300x172.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate-768x441.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate-1536x883.jpg 1536w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/AlertRulesTemplate.jpg 1698w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Solution objective<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned, it is crucial to stay updated with Sentinel Alert Rules, in order to detect new threats or critical vulnerabilities like Log4J. I recommend to check for new alert rules every 4-6 hours, so Sentinel is maximum 4-6 hours behind detecting new threats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft, 3rd party vendors or community will release <strong>new<\/strong> or <strong>updated alert rules<\/strong> as soon as a threat can be detected similar when support for detecting these threats were released very fast: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vulnerable Machines related to log4j CVE-2021-44228<\/li>\n\n\n\n<li>AV detections related to Ukraine threats<\/li>\n\n\n\n<li>KNOTWEED AV Detection<\/li>\n\n\n\n<li>Dev-0270 WMIC Discovery<\/li>\n\n\n\n<li>HAFNIUM New UM Service Child Process<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By implementing an automation for alert rules, you will be continuously having an updated SIEM environment being able to detect new use-cases.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ways you can do this ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft are providing multiple ways to achieve this including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Powershell modules<\/strong> and <strong>REST api<\/strong>, which can be accessed though a <strong>Powershell script<\/strong> running as part of your <strong>automation<\/strong><\/li>\n\n\n\n<li>Deploying <strong>custom content<\/strong> through your <strong>Github<\/strong> or <strong>Azure DevOps repository<\/strong>. This solution is currently in public preview and I urge you to try it out (<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/ci-cd?tabs=github\" target=\"_blank\" rel=\"noreferrer noopener\">link<\/a>)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This blog will focus on the <strong>script-method<\/strong>, as it can be used by companies of all sizes without deep knowledge of DevOps. This is a great &#8216;accelerator&#8217; to get up and running &#8211; and stay running &#8211; in a fast way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I will add an article on deploying custom content through Github and Azure DevOps later.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"799\" height=\"421\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3.jpg\" alt=\"\" class=\"wp-image-542\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3.jpg 799w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3-300x158.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3-768x405.jpg 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"388\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule-1-1024x388.jpg\" alt=\"\" class=\"wp-image-544\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule-1-1024x388.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule-1-300x114.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule-1-768x291.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule-1.jpg 1498w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Script overview<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Script will use templates, part of Sentinel (see list below). Currently there is no support for content hub.<\/li>\n\n\n\n<li>Script should run every x hours to check for changes.<\/li>\n\n\n\n<li>Script will check if alert rules templates have changed by Microsoft or other 3rd parties, part of the defined scope.\n<ul class=\"wp-block-list\">\n<li>Add\/create\n<ul class=\"wp-block-list\">\n<li>In case a new alert rule has been released, it will be created.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Update\n<ul class=\"wp-block-list\">\n<li>In case an existing alert rule has been updated, it will be updated (overwritten using 100% settings from alert rule template)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Remove\n<ul class=\"wp-block-list\">\n<li>In case of scope changes (excluded), script can automatically remove any orphaned alert rules that was used prior, where the connector now should be excluded. This parameter is configurable.<\/li>\n\n\n\n<li>In case of duplets based on displayname, script can remove these. This parameter is configurable.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Script can automatically add a default action to each alert rules, for example a logic app that will send an email. This is configurable using relevant parameters.<\/li>\n\n\n\n<li>Script will create issue-logfiles in case some alert rules cannot be created.\n<ul class=\"wp-block-list\">\n<li>This is typically caused by column, tables or normalization which is missing.<\/li>\n\n\n\n<li>You can then fix these issues. Next time it will retry any pending alert rules.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"134\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/error-create-1024x134.jpg\" alt=\"\" class=\"wp-image-532\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/error-create-1024x134.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/error-create-300x39.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/error-create-768x101.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/error-create.jpg 1366w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To get started, please look in the section &#8216;How to Get Started&#8217;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can download the <a href=\"https:\/\/github.com\/KnudsenMorten\/Sentinel_Alert_Rule_Management\" target=\"_blank\" rel=\"noreferrer noopener\">script from my Github<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<pre class=\"wp-block-code has-luminous-vivid-amber-to-luminous-vivid-orange-gradient-background has-background\"><code><strong>IMPORTANT REMARKS<\/strong>\nI have taken the assumption, that most of us wants a standard configuration, which potentially can be updated with a high frequency as new versions gets released.\n\nTherefore if you have made customizations to your alert rules, they will be overwritten by the latest configuration from the templates, when the update runs.\n\nIf an alert rule has been disabled, it will remain disabled even though alert rule will be updated.\n\nSolution can easily be enhanced in various ways adding more processes including test &amp; approval, exporting alert rule before updating, include-checks, etc. I might be adding these later.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Filtering \/ Scope definition Challenge<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To my knowledge, it is currently not possible to retrieve a complete list of the <strong>connected connectors<\/strong> using REST API and Powershell, so I am using a workaround outlined below.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, Microsoft will fix this, adding more features to the API every month. Latest API is from last month (<strong>2022-12-01-preview<\/strong>). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I will keep an eye on this <a href=\"https:\/\/learn.microsoft.com\/en-us\/rest\/api\/securityinsights\/preview\/data-connectors\/list?tabs=HTTP\" target=\"_blank\" rel=\"noreferrer noopener\">link<\/a> and update script accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Goal is to retrieve the list shown below with the 17 connected connectors.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"554\" height=\"591\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/connected_connectors-1.jpg\" alt=\"\" class=\"wp-image-528\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/connected_connectors-1.jpg 554w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/connected_connectors-1-281x300.jpg 281w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><strong># Method 1 (PS) - Get-AzSentinelDataConnector\n<\/strong>Get-AzSentinelDataConnector -ResourceGroupName $global:MainLogAnalyticsWorkspaceResourceGroup -workspaceName $global:MainLogAnalyticsWorkspaceName\n\n<strong>In my case, it returns 6 connectors - but I have 17 connected connectors.<\/strong><\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code><strong># Method 2 (REST API preview 2022-12-01-preview)<\/strong>\n    $baseUri = \"\/subscriptions\/$($global:MainLogAnalyticsWorkspaceSubId)\/resourceGroups\/$($global:MainLogAnalyticsWorkspaceResourceGroup)\/providers\/Microsoft.OperationalInsights\/workspaces\/$($global:MainLogAnalyticsWorkspaceName)\"\n    $connectedDataConnectorsUri = \"$baseUri\/providers\/Microsoft.SecurityInsights\/dataConnectors\/?api-version=2022-12-01-preview\"\n\n    $ConnectorsInUse = (Invoke-AzRestMethod -Path $connectedDataConnectorsUri -Method GET).Content | ConvertFrom-Json\t\t\t\n    $ConnectorsInUseList = $ConnectorsInUse.value\n\n<strong>In my environment, it returns 11 connectors - but I have 17 connected connectors.<\/strong><\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Temporary Workaround to define connectors in scope<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Until supported by API, I have chosen a fairly simple approach, where I define a list of <strong>connectors, which are excluded<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Someone might think, why are you not using include. The reason for that is, that I have seen connector-renames.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As part of the variables, you define a list of data-connectors, which are NOT part of the scope of the <strong>required data connectors<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I have made the assumption, that I am only excluding alert rules, which are having a explicit requirement for a data connector. I have decided to enable the alert rules, which are having more than 1 data connector, where one of them are on the exclude list. Many alert rules are doing lookups in multiple tables, including 1 which is excluded. These are included.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example below where script will exclude all alert rules being dependent on one of the below data connectors.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>    $global:Sentinel_DataConnectors_ExcludeAlertRules               = @(\n                                                                        \"AIVectraStream\"\n                                                                        \"AWS\"\n                                                                        \"AWSS3\"\n                                                                        \"Barracuda\"\n                                                                        \"CEF\"\n                                                                        \"CheckPoint\"\n                                                                        \"CiscoASA\"\n                                                                        \"CiscoUmbrellaDataConnector\"\n                                                                        \"Corelight\"\n                                                                        \"Dynamics365\"\n                                                                        \"F5\"\n                                                                        \"Fortinet\"\n                                                                        \"GCPDNSDataConnector\"\n                                                                        \"InfobloxNIOS\"\n                                                                        \"IoT\"\n                                                                        \"MicrosoftSysmonForLinux\"\n                                                                        \"NXLogDnsLogs\"\n                                                                        \"PaloAltoNetworks\"\n                                                                        \"ProofpointPOD\"\n                                                                        \"PulseConnectSecure\"\n                                                                        \"QualysVulnerabilityManagement\"\n                                                                        \"SquidProxy\"\n                                                                        \"Syslog\"\n                                                                        \"ThreatIntelligence\"\n                                                                        \"ThreatIntelligenceTaxii\"\n                                                                        \"TrendMicro\"\n                                                                        \"WAF\"\n                                                                        \"Zscaler\"                                                                        \n                                                                        )\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The complete list of standard connectors per Jan 9, 2023.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>AIVectraStream\nAWS\nAWSS3\nAzureActiveDirectory\nAzureActiveDirectoryIdentityProtection\nAzureActivity\nAzureAdvancedThreatProtection\nAzureFirewall\nAzureKeyVault\nAzureMonitor(IIS)\nAzureMonitor(VMInsights)\nAzureMonitor(WireData)\nAzureNSG\nAzureSecurityCenter\nBarracuda\nBehaviorAnalytics\nCEF\nCheckPoint\nCiscoASA\nCiscoUmbrellaDataConnector\nCorelight\nDNS\nDynamics365\nF5\nFortinet\nGCPDNSDataConnector\nInfobloxNIOS\nIoT\nMicrosoftCloudAppSecurity\nMicrosoftDefenderAdvancedThreatProtection\nMicrosoftSysmonForLinux\nMicrosoftThreatProtection\nNXLogDnsLogs\nOffice365\nOfficeATP\nOfficeIRM\nPaloAltoNetworks\nProofpointPOD\nPulseConnectSecure\nQualysVulnerabilityManagement\nSecurityEvents\nSquidProxy\nSyslog\nThreatIntelligence\nThreatIntelligenceTaxii\nTrendMicro\nWAF\nWindowsFirewall\nWindowsForwardedEvents\nWindowsSecurityEvents\nZscaler<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Alert Rules with no requirement for a data connector<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Right now, there are <strong>54 alert rules<\/strong> in the templates with<strong> no requirement for a data connector<\/strong>. Personally I think that some of them are mistakes, which I have escalated to the product-team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I have made support to also add these alert rules, even though some of them might be of the grid of what you need.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Suspicious link sharing pattern\nExternal User Access Enabled\nUser login from different countries within 3 hours (Uses Authentication Normalization)\nSUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)\nBase64 encoded Windows process command-lines (Normalized Process Events)\nUnusual Anomaly\nSign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)\nPotential re-named sdelete usage (ASIM Version)\nAzure DevOps PAT used with Browser.\nVulnerable Machines related to OMIGOD CVE-2021-38647\nExchange Server Suspicious File Downloads.\nGitHub Activites from a New Country\nZoom E2E Encryption Disabled\nHAFNIUM Suspicious UM Service Error\nAppServices AV Scan Failure\nSdelete deployed via GPO and run recursively (ASIM Version)\nTrust Monitor Event\nAzure DevOps Build Variable Modified by New User.\nDev-0228 File Path Hashes November 2021 (ASIM Version)\nNOBELIUM - suspicious rundll32.exe execution of vbscript (Normalized Process Events)\nAppServices AV Scan with Infected Files\nHAFNIUM Suspicious File Downloads.\nAzure DevOps Retention Reduced\nPotential Password Spray Attack (Uses Authentication Normalization)\nNRT GitHub Two Factor Auth Disable\nNRT Azure DevOps Audit Stream Disabled\nNew PA, PCA, or PCAS added to Azure DevOps\nMalware in the recycle bin (Normalized Process Events)\nAzure DevOps Service Connection Addition\/Abuse - Historic allow list\nAzure DevOps Variable Secret Not Secured\nAzure DevOps Service Connection Abuse\nProbable AdFind Recon Tool Usage (Normalized Process Events)\nAdvanced Multistage Attack Detection\nSUNBURST suspicious SolarWinds child processes (Normalized Process Events)\nAzure DevOps Personal Access Token (PAT) misuse\nAzure DevOps Pipeline modified by a new user.\nAzure DevOps Audit Stream Disabled\nUser joining Zoom meeting from suspicious timezone\nPotential Fodhelper UAC Bypass (ASIM Version)\nAzure DevOps Agent Pool Created Then Deleted\nBrute force attack against user credentials (Uses Authentication Normalization)\nNew Agent Added to Pool by New User or Added to a New OS Type.\nVulnerable Machines related to log4j CVE-2021-44228\nExternal Upstream Source Added to Azure DevOps Feed\nAzure DevOps Pull Request Policy Bypassing - Historic allow list\nAzure DevOps New Extension Added\nAzure DevOps Administrator Group Monitoring\nUsers searching for VIP user activity\nOMI Vulnerability Exploitation\nMissing Domain Controller Heartbeat\nGitHub Two Factor Auth Disable\nAzure DevOps Pipeline Created and Deleted on the Same Day\nWazuh - Large Number of Web errors from an IP\nGitHub Security Vulnerability in Repository<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can I build a list of possible data connectors to make my exclude list ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In case you want to adopt the script and want to keep the exclude-list up-to-date, you can run the below REST API command to list all possible data connectors. Then you can adjust you exclude list.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$baseUri = \"\/subscriptions\/$($global:MainLogAnalyticsWorkspaceSubId)\/resourceGroups\/$($global:MainLogAnalyticsWorkspaceResourceGroup)\/providers\/Microsoft.OperationalInsights\/workspaces\/$($global:MainLogAnalyticsWorkspaceName)\"\n$Uri = \"$baseUri\/providers\/Microsoft.SecurityInsights\/alertRuleTemplates\/?api-version=2022-12-01-preview\"\n\n$AllAlertRuleFromTemplatesApi = (Invoke-AzRestMethod -Path $Uri -Method GET).Content | ConvertFrom-Json\n$AllAlertRuleFromTemplates = $AllAlertRuleFromTemplatesApi.value\n$CompleteConnectorList = $AllAlertRuleFromTemplates.properties.RequiredDataConnectors.ConnectorId | Sort-Object -Unique\n\nWrite-Output \"Complete list of Data Connectors defined in alert rules templates\"\n$CompleteConnectorList<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can I get started ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can download the <a href=\"https:\/\/github.com\/KnudsenMorten\/Sentinel_Alert_Rule_Management\" target=\"_blank\" rel=\"noreferrer noopener\">script from my Github<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to get familiar with the script, I propose that you use your test-environment, where you can run the script to test its functionality.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider to setup a test-environment with a basic Sentinel environment and some basic connectors.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Connectivity to Azure<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">For demo purpose, I have just added a simple <strong>Connect-AzAccount<\/strong> in the script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remember to change this into using for example connection using certificate and Azure App registration &#8211; or alternative approach. I will not be covering this topic, but there are many great samples of this on the internet.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Connect-AzAccount -CertificateThumbprint $global:HighPriv_Modern_CertificateThumbprint_Azure -TenantId $global:AzureTenantId -Application $global:HighPriv_Modern_ApplicationID_Azure\n<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Variables<\/strong><\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Before running the script, please adjust It is rather simple to get the script configured, as you just have to define the below variables:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>###############################################################\n# LogAnalytics Workspaces\n###############################################################\n\n$global:MainLogAnalyticsWorkspaceName  = \"log-srvnetworkcloud-p\"\n$global:MainLogAnalyticsWorkspaceSubId   = \"xxxxxxxxxxc6-43fb-94d8-bf1701b862c3\"\n$global:MainLogAnalyticsWorkspaceResourceGroup  = \"rg-logworkspaces\"\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>###############################################################\n# Sentinel\n###############################################################\n\n$global:Sentinel_DataConnectors_ExcludeAlertRules               = @(\n                                                                    \"AIVectraStream\"\n                                                                    \"AWS\"\n                                                                    \"AWSS3\"\n                                                                    \"Barracuda\"\n                                                                    \"CEF\"\n                                                                    \"CheckPoint\"\n                                                                    \"CiscoASA\"\n                                                                    \"CiscoUmbrellaDataConnector\"\n                                                                    \"Corelight\"\n                                                                    \"Dynamics365\"\n                                                                    \"F5\"\n                                                                    \"Fortinet\"\n                                                                    \"GCPDNSDataConnector\"\n                                                                    \"InfobloxNIOS\"\n                                                                    \"IoT\"\n                                                                    \"MicrosoftSysmonForLinux\"\n                                                                    \"NXLogDnsLogs\"\n                                                                    \"PaloAltoNetworks\"\n                                                                    \"ProofpointPOD\"\n                                                                    \"PulseConnectSecure\"\n                                                                    \"QualysVulnerabilityManagement\"\n                                                                    \"SquidProxy\"\n                                                                    \"Syslog\"\n                                                                    \"ThreatIntelligence\"\n                                                                    \"ThreatIntelligenceTaxii\"\n                                                                    \"TrendMicro\"\n                                                                    \"WAF\"\n                                                                    \"Zscaler\"                                                                        \n                                                                    )\n\n# Sentinel Alert Management\n$global:Sentinel_DeleteExcludedAlertRulesFromTemplateIfFound    = $false\n$global:Sentinel_DeleteDupletAlertsRulesIfFound = $false\n$global:Sentinel_CreateUpdateAlertRulesWithNoDataConnectorReq  = $true\n\n# Sentinel Alert Rule Action (default)\n$global:SentinelAlertingEnableLogicAppAction = $true\n$global:SentinelAlertingForceSetExistingRules  = $true\n\n$global:SentinelAlertingLogicAppActionName = \"SendEmail\"\n$global:SentinelAlertingLogicAppActionRG = \"AzureRG3-Management-WestEurope\"\n$global:SentinelAlertingLogicAppActionTriggerName  = \"When_a_response_to_an_Azure_Sentinel_alert_is_triggered\"\n\n# Sentinel Alert Rule management logging\n$global:Sentinel_Issues_List = \"D:\\SRIPTS\\OUTPUT\\SENTINEL_AlertRules_Issues_List.txt\"\n$global:Sentinel_Issues_Detailed= \"D:\\SCRIPTS\\OUTPUT\\SENTINEL_AlertRules_Issues_Detailed.txt\"\n\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"388\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule2-1024x388.jpg\" alt=\"\" class=\"wp-image-545\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule2-1024x388.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule2-300x114.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule2-768x291.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/CreateAlertRule2.jpg 1498w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Automatic update (overwrite) of existing alert rules when new version is released.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"534\" height=\"154\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/alert-rule-action.jpg\" alt=\"\" class=\"wp-image-534\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/alert-rule-action.jpg 534w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/alert-rule-action-300x87.jpg 300w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><figcaption class=\"wp-element-caption\">Automatic check if alert rule action has been set on the alert rule.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"573\" height=\"494\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/setting-alertrule.jpg\" alt=\"\" class=\"wp-image-569\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/setting-alertrule.jpg 573w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/setting-alertrule-300x259.jpg 300w\" sizes=\"auto, (max-width: 573px) 100vw, 573px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Do you want to automate alert rules including creating new alert rules and update existing &#8211; with checks every x &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Sentinel Alert Rules Management with Add \/ Update \/ Remove &#038; Alert Rule Action automation\" class=\"read-more button\" href=\"https:\/\/mortenknudsen.net\/?p=525#more-525\" aria-label=\"Read more about Sentinel Alert Rules Management with Add \/ Update \/ Remove &#038; Alert Rule Action automation\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":542,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"ngg_post_thumbnail":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[55,58],"tags":[106,107,109,110,111,24,108],"class_list":["post-525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","category-sentinel","tag-alert-rules","tag-create","tag-manage","tag-management","tag-remove","tag-sentinel","tag-update","infinite-scroll-item","resize-featured-image"],"featured_image_src":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3.jpg","author_info":{"display_name":"Morten Knudsen","author_link":"https:\/\/mortenknudsen.net\/?author=1"},"jetpack_featured_media_url":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/UpdateAlertRule-3.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=525"}],"version-history":[{"count":24,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/525\/revisions"}],"predecessor-version":[{"id":573,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/525\/revisions\/573"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/media\/542"}],"wp:attachment":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}