From 89fbe86373147a91e46d456e259378a3d945f96f Mon Sep 17 00:00:00 2001 From: v-sabiraj Date: Thu, 23 Jun 2022 12:09:56 +0530 Subject: [PATCH] updating text --- .../Morphisec/Data Connectors/Morphisec.json | 8 ++++---- Solutions/Morphisec/Package/2.0.0.zip | Bin 6787 -> 6901 bytes Solutions/Morphisec/Package/mainTemplate.json | 16 ++++++++-------- 3 files changed, 12 insertions(+), 12 deletions(-) diff --git a/Solutions/Morphisec/Data Connectors/Morphisec.json b/Solutions/Morphisec/Data Connectors/Morphisec.json index 6db41416676..9907f67ad0d 100644 --- a/Solutions/Morphisec/Data Connectors/Morphisec.json +++ b/Solutions/Morphisec/Data Connectors/Morphisec.json @@ -2,7 +2,7 @@ "id": "MorphisecUTPP", "title": "Morphisec UTPP", "publisher": "Morphisec", - "descriptionMarkdown": "Integrate vital insights from your security products with the Morphisec Data Connector for Azure Sentinel and expand your analytical capabilities with search and correlation, threat intelligence, and customized alerts. Morphisec's Data Connector provides visibility into today's most advanced threats including sophisticated fileless attacks, in-memory exploits and zero days. With a single, cross-product view, you can make real-time, data-backed decisions to protect your most important assets", + "descriptionMarkdown": "Integrate vital insights from your security products with the Morphisec Data Connector for Microsoft Sentinel and expand your analytical capabilities with search and correlation, threat intelligence, and customized alerts. Morphisec's Data Connector provides visibility into today's most advanced threats including sophisticated fileless attacks, in-memory exploits and zero days. With a single, cross-product view, you can make real-time, data-backed decisions to protect your most important assets", "additionalRequirementBanner": "These queries and workbooks are dependent on Kusto functions based on Kusto to work as expected. Follow the steps to use the Kusto functions alias \"Morphisec\" \nin queries and workbooks. [Follow steps to get this Kusto function.](https://aka.ms/sentinel-morphisecutpp-parser)", "graphQueries": [{ "metricName": "Total data received", @@ -61,13 +61,13 @@ }, "instructionSteps": [{"description":"These queries and workbooks are dependent on Kusto functions based on Kusto to work as expected. Follow the steps to use the Kusto functions alias \"Morphisec\" \nin queries and workbooks. [Follow steps to get this Kusto function.](https://aka.ms/sentinel-morphisecutpp-parser)"},{ "title": "1. Linux Syslog agent configuration", - "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Azure Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace", + "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Microsoft Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace", "innerSteps": [{ "title": "1.1 Select or create a Linux machine", - "description": "Select or create a Linux machine that Azure Sentinel will use as the proxy between your security solution and Azure Sentinel this machine can be on your on-prem environment, Azure or other clouds." + "description": "Select or create a Linux machine that Microsoft Sentinel will use as the proxy between your security solution and Microsoft Sentinel this machine can be on your on-prem environment, Azure or other clouds." }, { "title": "1.2 Install the CEF collector on the Linux machine", - "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Azure Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", + "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Microsoft Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", "instructions": [{ "parameters": { "fillWith": [ diff --git a/Solutions/Morphisec/Package/2.0.0.zip b/Solutions/Morphisec/Package/2.0.0.zip index ed221f12f7be97a172ca315ec14ead0d8b15bb82..e1116444631535fb22497a4f4b44b8aca9185525 100644 GIT binary patch delta 4840 zcmV`~YMoTGE@nm;b-t z5k^tW-Uu?A5y4O^P-}2~hFQ2BvjG3KGp)2{ykpvTCX=`QYp*T2V`YAA8?@w~%zPvP zMwR*>^DFW!q48Qqfq=ba86z*EAmf5xe@e0d+ldku&C`IGWVZ|ewMpg=Uuy?RO+xrI6KdTFdpiXOSiNcZ=sikA1H%`gSf2tsC50v!E z3Q_9TG73YM%tR6H%6QNYL5^TkquwS~i2byX;&Xe6RXDBKOEV5SDkIipvJuQnvmz)p z5*V7~Hj>LS$E|S|MgnfGUlx+DD3rZRe)K;KTU#i@?v396ZMC9M`3;n#=_Z_h)3(qr zScxE$Wl1Q0NGgL?_dQ)$GseA^&WKYo6!H`dbZMw`Qro9jdUM~A8Tqi;usRJpmom??a%BT$4Zb#}gq zB#p7Ipf*Y$rPrXcaJtlrML# zV5bG4QqtgBOrhs&#o%1M#wEu*g2Bk;dzNu5sW>nl>Tf)&XOo` z^EW4N3gRW9Ct4svMZA*Y2220RBfyI7MYsCUQWesM1BEU`QNlZbq^0zdtpkyEfNasEu% zFAJZlX~q+rXrV&)-(WhmDIU>yIN5%Ep#GUk1%ACX{#cxsA9{_-!!IG!fSZTJ5uERx z7pW_xf0Ba}A7k-!Q4pSxZ^?gP2cAK;flEaps7wGo_dO^&+9u}zTPeB8^$z)J#S@do zVexldF4p5{)cBYRiJ|RP;TzoM+^rGhDFm2z)U8pS#XTl+Fw^y-qz9JgoRBh^tPPKr~)6LLvo!Cd{^o@4|W z_$m^*I^pNR9Hvf+BShB*deudz{AT>%bBkY@>g+$)6`fP|P9pgXpVq0g1T~yk9aZ|2 zf9aenoOhEi_gCcp^Rs-D)PLJ*JiuklY%M~9BJi=@f z99xOl<9V)qo^wm@&RH*b3pm5YMJ)r%KzXJmaU3Q2JEE)z*Ac+F%G0~f2+4Ohf7tjv zSR0jOeE8k>6S7!~7!pKC?1kD%1*u@6g&y(eRuR??dh`{qZu2W^V*B%bSc(!4_`v|r z5#Y@V39e|cgf(^VT@jYtL>W)erBBH-^u)+ChpB<}nCGFGdo#nX5V(Qt4~S7>Trg;% z(N$z5v2=N>ov>+FGJ2t-4Hny;T@|iK$)&zaZL2Ex4P4&(G*W~o@q_DyLIeCEM^t85lk`3!JParP+fsb)TBY(Z&b0;&N0R! z5Ba1yUuU$gN2DI>#;a4yfADg``Z@<(f(c^%w14tqfc?;~b8Y2_lPrRx-5PR`4&ySH z`%qQC;H-YZV$}CndE(wn)V|1y7Bo%cb=%~g3|T^XxETH2cb z!`?^oVgF;Vkh}btzRC)~Ay3!%Npx9>P#^Y+not!F+J(d7`MHV$M-pTV9t3wsAN>yY$O=?X!oKEU$~x#8 zrVutOAsJc;ofn#5SVcahdeq=5;j-jxN-~FYtCnn}p{7y-e|++5#6&g6T_R#rRp9t2udXHm9=shw_S+MRRwOz9XtYM1z25>fyTaJ3PChN%USrJFK25kE39H zrp)@yaaG;=f3|hvSB{ZkI2aOEzMd03pzdilddkth+3MH0(G+t_ymvv@lrJE(mfwc? z93aN06XtVI(4=DYPR#^oJ5z#>v&JHgBk6}@D+~={3MUgce5n`816(WolUm7VkEO3I zEihfw+6GZ_6Ec{oI-=3l^X4v)x`Kulw=eFM%$PUDf84fQYG)rBs`fUDEu;E-EDlR{ z@m{{>=H|W4)Iho-PcdiSfUtYDUbtv3 z?gR<+dOG_@%Tt#3H-IK?pr`!Kf!zIPa|cQ~H6o`*H`+z)4LuVqX4 z;wJ`M>=H*X44&vev-iUhyI_bz1@fD~58nl!UG_qBmNIMTko{9WNkH^q%Ug!1*^L;EUXwGi6y ze=7aB&jBv`5$D;5^V~QN{;u$xy*N&{S=<9|^LK{VbUg#;mF@lDG9U4n4~ac_I6US+ z=!sK{@EQy`84NcWjsGCgragXI=uRbyez3vdPd{4E)HnI!W9tK{U*-ouPxO~| zOL13xc>xICPbI2H<(l9&pZ&Cle-@tr_3DND6Tx5BM?d|F^AKPA^oshvKJ)3-f8Edg z8=phIQ3Gt?eMVtyPu;dhz(|lp=I%^smmR zF+MNp?2K5VE3ThBFBIm${Upc)=4Y{nbM%n4o@SqAXG!aDiZ{*E?C0zz3fOBfe4de~ zPa&-;F;u#nO6EeckTjFzDdevdf4B_T7+ae&+ZW=hBt!Vp7)WF^kmECafSt*w<2V2J z-*5kIayFXoPoI_f)^{dr6qw$1TpP?B@Hk&3=g}p57YQkV1GNr(JP)%&>U1`mOuFbz zd<{5gN(_wQ1rPHWF+SB&>rMS@)&xuG7Y0-#*=!t2RI`FA>EIA=Z${{_f6!V7G1Ige zLCd*2Xj-j9$)02!YxRrhDxne&G&a>{<6xo+Anu`AZyQPy(Mt)>S@(yM(o!q-!$;TGY3L+}JY>b_h6HLY{p6gk zw!*)=J~3xfJ!kRAS9CHlf7ecV9JE#6vdrTGrdOAv4Bje&KfdNyy!4`z$&R;O((3na zbiLT;NvF&9uAHjb-BGma%~MkQg_do~FZcOtOlq73-uF^c|L=pTQ7{1fliKf_sde$Z znbMP27lV7=@EiIv+rT#gH-2TsT&~*a;~Rd})rV*L72ojloLiige~f?cFKu}bVOt-7 z{AX|HfoIS`r|*C>@L=XSlng=`3*aw;W4}M*l{{|WV_Ob2LIwA~v z6W*e+S*`q&OZ>M__&XB)trGmlch0T$-}IgH&(DW=?afle_Oqrg%`$eeP|uKFcaia1 zkn^`0Yldw6{ zDR?!xUiXOSGR>ua>ix$*z@PsIlj#{z8!utkRF~cC27(d*0B?c-01*HH000000096X OlT{ih23r~c0000{e_O!- delta 4725 zcmV-*5{m8hHG?&?MVi^XEGFZ>RC z_t|d<+4-Ferff!c9+RDEn$G3p{eAt(ct&G-&1Ni4$MkKMuyG(}=9%1oba43B(ZLs^ zgTwuhf6XJYz;>r>Hjik^#{ZQf{_W0C4G@Spg=eo=BDsihoWt<}{%4-gSV}{hA_wpA z1New$=~N`x^o2;~Q!ZJc8!K`%97^KTiHNckh?3L{Os+&iiayxoy&h#w6AB{%6V5o1 z2q^Y1K7tR^#hf8=nI=5Gw&NnBJbupN>vRfFe-Dd~Lv}^8D1AkvO!YfUm=swOuzw^X zn-BKJc9aX3R&COTmJAX;H$3fpCsLA077oc}mXesUkcA`_WKN|dG?|Uk^akcGQ}WYu zGstK%6gn@u=KaC0bkr5utl+h5Wl61<*Pj@1@k#icbk!ABIayR9{ zf0S@ZLYDAb81gC+Gu8b0Q<8U3(#4|Pt^yYBT5rza<`UrZ+XmVI6BbC#1G>=sXUL8>(=zBJ2aI@;Ac4hOq4 zJEigWa|WvjL}+vzOMX2~<$f*~xjQ88D(0lsGTH$%ek9^6etjGsmaGm=rI<#gf0a8A z=aD-RTtIjbgFcDmNE^cTFX0~8CM?Jj zo-T3{C9aT+Gb!KXOG{O5)FqlWnOJW%nX}+Kn98ARLp-w^?vBD>v^&gV{&U9krXBQ~ zf{zX37!PyLm^T9+BT;Yh0-j_sT^e@Z5gD9RmE zdhNI<_0g1vA&W=SxVzjR)Ll@6vnf%p6Ek8zHB$WAonqlm3-;!T03A)a>qncMdA_X( zN{s}TCb{G3G>>shoP}J%hYJ*DnL^&$6RE7A4Ewiw{a4irqw-5AN7YO;+D&(de!@xw zkt~Zt`F&h$X!W_rDtgwif9!C(1*ld`|`t5m|c0+V8`uGNgj<`&F_6%BDB(u>l2bW3^bX8&q3DU&DbqxcMV2UmeKe~UkuB%!$-wB$9r z;^rKUENU6@G^*HtH>;>JoLxp-LSEPy%2gUWd-?@UZbEUVqJo7xqQnKC}q$EaQ7ollM)HkeHzN?hCb&R25!`o|Lfl~WiV^M7pbG)>|1GWrxyoWy zdXeOkLgA};e*k~5Gw_3=0d841CeK6^i94lIP}Z8O$=J$Pl^%^a^gS;W{(Og=$2@N4 zZ%ob%@tp8AOMx(yP0EzV7X#~m=nXg@$T*DZj`HG2md@uR9kTCvL+68W#o`U0{dvxR7U@2MgsN z6M2?@ig=<#TvG7FYz;Y7Vvtj_1p|?Rnq4l)6x6$Aaz8gt>^ycG{g23OHUk^|mXTA~ zS@QK$wSQUoL=7|8!+|EsZT}O7Q;Xse&G5eG2kM`wFyP_l_=CxnH$6vX;iuqcz|2F? z2*!8qe@W`Pu62-RR4&|6kXd(V;lapf<}-h;9%YiN^;q2mM@nvIGEWyU8v@J_aHtK zQ*nqs7Dq67ST(wmC~f$8ERCDD((p^~)|Bx*e`BdOJq7t376O*du0t=Gg17!JdTWPc z=vSrm6`|K+@cBXLlQxKU{biuHlt(%SL;dlH84fpSn#t0!S)~P+CniI9Os;4oSyQ`a zOR@ve_l!$jneg*q6R8uEKC~^MS6y_tZ~OPoS^UaWX8&tl%{hfCJ(35r7wWJCHJmsN ze^vOD=$I=Ux05&g8rn8O$ZHv`on-*IP5lJ}t)dZbClT1exe5DKAJ%MhaK zys5usqoS(^!-rCgeL01d48LWIwRFVQ3Pb;#L->3BI5L5AVG zJ_7|R5#&;kLpCWMr_kh=OAd$!`{8bF?!XYV>9B;VZPf5T_6 z+o0+(IQr(<9+@m;1OXz1@)El0bQiYc9RNg-D&RXrrSvk!$mJ^nND>ZvKAi$7WhgMK zRAnAyFHukn49?+~OU%Q;V1!V}&{?^HQo!#8F2WyIajYA3=xVD7%eAn>@gYn_i3V(7 zfH?$MG9$ei4W=;1wvAt3k}hgme@2!1l@bgVC7}9%A_1%QW&x5)?-+|Km9iYBf{Rn3 zqe>5UAS~~Iu!SK2upcO}&IpTdc_Lyo<3rOQm=!QAupEgjlw)r+*yi?@kohBG6&EK9 znrHPB8PQ6y#tOK!3rx!k?P0LM_EhZ(E0^->)OS+8Zs6^pEC=ghScI?|fAUvvEACuFX1kAsr`Z%WqgQ{V^Jp6*39-WwdcL=3Otl&w_Eoc@N_NH*0 zO->eok5kO*lAW1GhE+ku|COp;;cp0+1NI-2x$ZME$1P@%M`QADpgMz+mL?4*Y4_l!gL}X??A7BW;gHHLAm(V< zSnWwvg(9R=EJ9s>nZ?a(iJHe9??C7CXi?v8kNZp^PiA*;iOC%nIY-}0 z#(#J4p1eDJ-znra8&=8qkHma|r!3Evz}vfd1GSbsy0xEQ65x2*(auV{E#^@yhWD z9Ik|r$%7y3AwV#0f6t87_QyqbWLL96q>VgBCx7zRPtrxh?Cr(nP=kH=+8vQx)0n^2Fb=2XTtqxr z;HEy0&z=|6f2^-+C$`EkGIR%h+{zbYqC1o=%~Gct^$%<9Dj!tE{O&%HH2KR0Js>@g z5YN*J>A5Eul6{+_v;_eaOYrz=05v~e0u$DN;Tk^(z}QA;PbX{#xK>!FPXjk!nwl|w zbr_?cQZpfok1C@Vn_Awk1D`WAw79+KDa(v~E6jtmf3Vuwg?uW#dE&~b{LV_lPHy5o zf2HkRPo{d(mDwC)<|PRGAY}UF;)EtC!grcmMLfPKAujdk<~1zf5|;0Sws?Nza673+?C;9xYA)p`9 zHpt-z4K=*zFUAh!cU^p|A-x|8;oV)XSsls!e^3bSmFLh0sr{e`?KZ`0$FTabtL>Q8 z%4>YB7}Z|b)W#CkJz-Hdgh5>id)gD8w+t+=6Jy$qE$zaT)@vHWO)X#tW^{`cT>~S! z3FYg+f_7EIE?TTgH^#Gv$=+f*yD*(g`@vrgcC!<+*}Nt00i*dV!Dcqq{5xfOKN!p{ zfA;d@!(R4;nfQ<9`@&0lLreN&D*It6+ps4Ogq{3UFq3}7$x>*Ol>rX*rCbO5xU`f0 z7%`6bk8NC9Y+DTDuMNZ4!>KffBz>GoFGtb?o9Ocko5Lc0LKsBPD};T$z*3gI7q)O| ztMp-G2$#hUwv{XS$AFY5-C9+<3~hUDf6xlo2CavK+SvV`o;yxIiHkkW4Z69w*SP{w z-6W<7u5z8H+x?@s+S98S%~$_^T9`h#&*@?YprxamYJAY_AeeqezW~@8t#Q_!D}Z|hPOKofJ6c(O@nhhuujq^gR}qq?c$Gn=R3p0;nVz@ z#&2xYC^5Wi`B`FQD4J!n_%**`e{Z-^|&E^hg&bpaNPJf%Ext5;g1Lqw8zbpWl#~-W3Uyo^+Gzcy*}h`ZycvH5QM2 zMJMZX-H@lV%+vO6PGcFoRs`R^(q~?9(ZOWPn=Q`wX|%n>=Lx6t=WQ`nkD}Fb?+E_V zUr$ov%>NEb%lEvLC|Iz4fBAc4N=#u6Ggk@;|6WnbC1eOM_%zqj5? zU)#4#t^9)v{8tb7TLS%+0{rd!Hejq zF9BH=W7SmwTDQp5-@WuKDU{M)p2+k>-`N1`!3v`VAcil?o7kGY>KZqed@mZ3Z{DC* zp};fnhSD@3j}5wPFa%dbt1qU5h!VentqO!|ESKDS#8pCWxppfTyc%53dk3xuoo8^x z0iJq)_8a)~f0J7pQ5(5v)>MLs1{x3&002jV000pH00000000000F%cWC Notice that the data from all regions will be stored in the selected workspace", + "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Microsoft Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace", "innerSteps": [ { "title": "1.1 Select or create a Linux machine", - "description": "Select or create a Linux machine that Azure Sentinel will use as the proxy between your security solution and Azure Sentinel this machine can be on your on-prem environment, Azure or other clouds." + "description": "Select or create a Linux machine that Microsoft Sentinel will use as the proxy between your security solution and Microsoft Sentinel this machine can be on your on-prem environment, Azure or other clouds." }, { "title": "1.2 Install the CEF collector on the Linux machine", - "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Azure Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", + "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Microsoft Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", "instructions": [ { "parameters": { @@ -286,7 +286,7 @@ "connectorUiConfig": { "title": "Morphisec UTPP", "publisher": "Morphisec", - "descriptionMarkdown": "Integrate vital insights from your security products with the Morphisec Data Connector for Azure Sentinel and expand your analytical capabilities with search and correlation, threat intelligence, and customized alerts. Morphisec's Data Connector provides visibility into today's most advanced threats including sophisticated fileless attacks, in-memory exploits and zero days. With a single, cross-product view, you can make real-time, data-backed decisions to protect your most important assets", + "descriptionMarkdown": "Integrate vital insights from your security products with the Morphisec Data Connector for Microsoft Sentinel and expand your analytical capabilities with search and correlation, threat intelligence, and customized alerts. Morphisec's Data Connector provides visibility into today's most advanced threats including sophisticated fileless attacks, in-memory exploits and zero days. With a single, cross-product view, you can make real-time, data-backed decisions to protect your most important assets", "graphQueries": [ { "metricName": "Total data received", @@ -355,15 +355,15 @@ "description": "These queries and workbooks are dependent on Kusto functions based on Kusto to work as expected. Follow the steps to use the Kusto functions alias \"Morphisec\" \nin queries and workbooks. [Follow steps to get this Kusto function.](https://aka.ms/sentinel-morphisecutpp-parser)" }, { - "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Azure Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace", + "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Microsoft Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace", "innerSteps": [ { "title": "1.1 Select or create a Linux machine", - "description": "Select or create a Linux machine that Azure Sentinel will use as the proxy between your security solution and Azure Sentinel this machine can be on your on-prem environment, Azure or other clouds." + "description": "Select or create a Linux machine that Microsoft Sentinel will use as the proxy between your security solution and Microsoft Sentinel this machine can be on your on-prem environment, Azure or other clouds." }, { "title": "1.2 Install the CEF collector on the Linux machine", - "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Azure Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", + "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Microsoft Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python -version.\n\n> 2. You must have elevated permissions (sudo) on your machine.", "instructions": [ { "parameters": {