Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix EXO deprecated alert policies in MS.EXO.16.1 #29

Closed
schrolla opened this issue Dec 22, 2022 · 5 comments
Closed

Fix EXO deprecated alert policies in MS.EXO.16.1 #29

schrolla opened this issue Dec 22, 2022 · 5 comments
Assignees
Labels
bug This issue or pull request addresses broken functionality
Milestone

Comments

@schrolla
Copy link
Collaborator

Defender2 9

Defender 2.9 was showing as a fail in the report and highlighted 2 policies.

  • "Malware campaign detected after delivery"
  • "Unusual increase in email reported as phish"

Both of these prebuilt alert policies have disappeared from the Alert Policy list and thus from current Provider exports.
I looked back at an older Provider JSON and found that policies were still there a little over month ago.

OctoberJson

The names of these policies are listed in EXO 2.16, so this will require both a baseline policy update and a Rego code change.

@schrolla schrolla added this to the Backlog milestone Dec 22, 2022
@schrolla schrolla added the baseline-document Issues relating to the text in the baseline documents themselves label Jan 10, 2023
@schrolla
Copy link
Collaborator Author

Baseline policy updates will happen as part of larger baseline updates, but this issue is related specifically to fixing the Rego to ensure it is fixed post baseline update.

@tkol2022
Copy link
Collaborator

Related #235

@schrolla schrolla changed the title Defender 2.9 (Mirror of EXO 2.16) Alert Policy Deprecation Fix Defender deprecated alert policies in EXO 2.16 Jun 12, 2023
@schrolla schrolla changed the title Fix Defender deprecated alert policies in EXO 2.16 Fix Defender deprecated alert policies in DEF 5/EXO 2.16 Jun 12, 2023
@schrolla
Copy link
Collaborator Author

This should be addressed as part of Defender and EXO policy updates noting that the associated Defender baseline policy item is now MS.DEFENDER.5.1v1.

buidav added a commit that referenced this issue Jul 13, 2023
@schrolla schrolla self-assigned this Jul 13, 2023
buidav added a commit that referenced this issue Jul 17, 2023
buidav added a commit that referenced this issue Jul 19, 2023
buidav added a commit that referenced this issue Jul 25, 2023
buidav added a commit that referenced this issue Jul 25, 2023
nanda-katikaneni pushed a commit that referenced this issue Jul 26, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
@schrolla schrolla removed the baseline-document Issues relating to the text in the baseline documents themselves label Jul 26, 2023
@schrolla schrolla changed the title Fix Defender deprecated alert policies in DEF 5/EXO 2.16 Fix EXO deprecated alert policies in MS.EXO.15.1 Jul 26, 2023
@schrolla schrolla changed the title Fix EXO deprecated alert policies in MS.EXO.15.1 Fix EXO deprecated alert policies in MS.EXO.16.1 Jul 26, 2023
@schrolla
Copy link
Collaborator Author

Latest EXO policy has now been merged to Emerald, so the referenced alerts are no longer indicated in the baselines. Code updates are pending to realign rego assessments with updated policy language. Removed baseline-document label since this is purely a Rego code update issue now. Issue is resolved when MS.EXO.16.1 assessment check updates its list of alerts to match the updated policy.

@buidav buidav assigned buidav and unassigned schrolla Aug 11, 2023
crutchfield pushed a commit that referenced this issue Aug 23, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
schrolla added a commit that referenced this issue Sep 1, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
@buidav
Copy link
Collaborator

buidav commented Oct 16, 2023

Code updates were made in #527

@buidav buidav closed this as completed Oct 16, 2023
schrolla added a commit that referenced this issue Nov 2, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
schrolla added a commit that referenced this issue Nov 2, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug This issue or pull request addresses broken functionality
Projects
None yet
Development

No branches or pull requests

3 participants