Skip to content

feat: Enhance UEBA Essentials with multi-cloud detection capabilities#13065

Merged
v-atulyadav merged 6 commits into
Azure:masterfrom
ofirga-ms:update-ueba-essentials
Nov 12, 2025
Merged

feat: Enhance UEBA Essentials with multi-cloud detection capabilities#13065
v-atulyadav merged 6 commits into
Azure:masterfrom
ofirga-ms:update-ueba-essentials

Conversation

@ofirga-ms
Copy link
Copy Markdown
Contributor

  • Add customer-facing blog post for release communication

Total: 26 hunting queries (increased from 20)
Version: 3.0.1

Required items, please complete

Change(s):

  • Add 6 new hunting queries for AWS, GCP, and Okta anomaly detection

  • Add Anomalous AWS Console Login Without MFA from Uncommon Country

  • Add Anomalous First-Time Device Logon (MDE integration)

  • Add Anomalous GCP IAM Activity detection

  • Add Anomalous High-Privileged Role Assignment

  • Add Anomalous Okta First-Time or Uncommon Actions

  • Add UEBA Multi-Source Anomalous Activity Overview

  • Enhance existing queries with improved entity mappings

  • Update Anomalous connection from highly privileged user

  • Update Dormant Local Admin Logon with better accuracy

  • Fix typos: BlasrRadius -> BlastRadius in multiple files

  • Rename queries for consistency and clarity

  • Update package templates with new query definitions

  • Clean up orphaned files and maintain solution integrity

  • Add comprehensive documentation for changes

    Reason for Change(s):

    • Enhanced UEBA Essentials solution with 6 new multi-cloud hunting queries (AWS, GCP, Okta) to provide comprehensive threat detection across hybrid cloud environments, addressing the modern enterprise need for unified security monitoring beyond Azure-only coverage.

    Version Updated:

    • Changed from 3.01 to 4.0

    Testing Completed:

    • No. Need help.

    Checked that the validations are passing and have addressed any issues that are present:
    -Need help verifying

- Add 6 new hunting queries for AWS, GCP, and Okta anomaly detection
- Add Anomalous AWS Console Login Without MFA from Uncommon Country
- Add Anomalous First-Time Device Logon (MDE integration)
- Add Anomalous GCP IAM Activity detection
- Add Anomalous High-Privileged Role Assignment
- Add Anomalous Okta First-Time or Uncommon Actions
- Add UEBA Multi-Source Anomalous Activity Overview

- Enhance existing queries with improved entity mappings
- Update Anomalous connection from highly privileged user
- Update Dormant Local Admin Logon with better accuracy

- Fix typos: BlasrRadius -> BlastRadius in multiple files
- Rename queries for consistency and clarity
- Update package templates with new query definitions
- Clean up orphaned files and maintain solution integrity

- Add comprehensive documentation for changes
- Add customer-facing blog post for release communication

Total: 26 hunting queries (increased from 20)
Version: 3.0.1
- Update solution version from 3.0.1 to 4.0
- Create new Package/4.0_extracted directory with updated templates
- Update mainTemplate.json with version 4.0
- Update all hunting query template descriptions to version 4.0
- Update customer blog post and documentation to reflect v4.0
- Maintain backward compatibility and existing functionality

This version bump reflects the significant multi-cloud enhancements
and expanded detection capabilities in this release.
@ofirga-ms ofirga-ms requested review from a team as code owners November 4, 2025 07:54
@v-maheshbh v-maheshbh added the Hunting Hunting specialty review needed label Nov 4, 2025
@ofirga-ms
Copy link
Copy Markdown
Contributor Author

ofirga-ms commented Nov 4, 2025 via email

ofirga-ms and others added 4 commits November 4, 2025 11:07
- Fix multiline key mapping error in YAML structure
- Properly indent KQL query under query: | block
- Resolves YAML parsing error at line 26, column 15
@v-atulyadav v-atulyadav merged commit c8e0034 into Azure:master Nov 12, 2025
32 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Hunting Hunting specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants