Skip to content

Releases: lnfernux/log-baseline

Log Baseline 0.3.0

Choose a tag to compare

@lnfernux lnfernux released this 02 Oct 09:51
a488130

Separates security value from storage tier and records the rule behind each recommendation. Data 0.3.0, schema 1.2.0.

Changes

  • classification follows value rules C1-C9 mapped to ASD's priority logs for SIEM ingestion and CISA's M-21-31 guidance. recommendedTier follows tier rules T1-T5. Volume no longer sets the classification.
  • Reclassified 89 tables. 88 moved to primary, including all Entra ID sign-in log types, firewall, DNS, proxy, flow, storage access, database audit, security tool admin audit, and collaboration audit tables. DnsInventory moved to secondary.
  • Moved DNS and network session tables (DnsEvents, ASimDnsActivityLogs, ASimNetworkSessionLogs, ASimWebSessionLogs, and others) from Analytics to Data lake.
  • Recommended Analytics for 40 tables that previously recommended Data lake but do not support the Auxiliary/Lake plan. Validation now rejects that combination.
  • Added optional volumeClass, volumeDriver, valueRule, and tierRule fields and populated them for every classification.
  • Added 16 tables: Defender for Endpoint custom data collection, Intune, and Azure VMware Solution.
  • Added provenance for ASD, CISA, Microsoft Sentinel data lake documentation, the Azure Monitor table reference, the volume model, and the classification rules.
  • The review importer replaces changed records, adds reviewed source records, and regenerates the pre-made baselines.

Compatibility

The data contract is backward compatible: the new fields are optional and no existing field changed. The 89 reclassifications and 78 tier changes do change Log Horizon's per-table recommendations once it vendors 0.3.0.

Log Baseline 0.2.0

Choose a tag to compare

@lnfernux lnfernux released this 22 Sep 13:08
0184df8

What's Changed

  • feat: add the human review skill by @lnfernux in #1
  • feat: update data, add the pre-made baselines, update supporting file… by @lnfernux in #2

New Contributors

Full Changelog: v0.1.0...v0.2.0

Log Baseline 0.1.0

Choose a tag to compare

@lnfernux lnfernux released this 13 Sep 09:35