Skip to content

release: sync dev to main — AZ-KV-002, breach scenarios, network rules expansion#17

Merged
Vishnu2707 merged 10 commits into
mainfrom
dev
May 4, 2026
Merged

release: sync dev to main — AZ-KV-002, breach scenarios, network rules expansion#17
Vishnu2707 merged 10 commits into
mainfrom
dev

Conversation

@Vishnu2707
Copy link
Copy Markdown
Member

What this release includes

  • AZ-KV-002: Key Vault public access rule and remediation playbook
  • docs: real-world breach scenarios for all 10 starter rules
  • AZ-NET-003 to AZ-NET-010: 8 new network security rules and playbooks
  • fix: AZ-STOR-003 compliance mappings corrected to PR.DS-3

Closes #2, #7, #8

Vishnu2707 and others added 10 commits April 25, 2026 15:07
* feat: add sentinel/ingest.py — Log Analytics ingestion via HMAC-SHA256

* feat: add sentinel/__init__.py

* feat: add KQL rule — HIGH severity finding detected

* feat: add KQL rule — misconfiguration wave detection

* feat: add KQL rule — new resource type critical detection

* Delete sentinel/rules directory

* Create rules

* Delete sentinel/rules

* Add KQL rule for high severity findings

* Add Misconfiguration Wave detection rule

* Add KQL rule for persistent misconfiguration detection

* Add KQL rule for new critical resource types

This rule identifies new resource types with critical findings that have occurred in the last 24 hours, excluding known types from the last 30 days.

* Add script to generate test findings in JSON format

This script generates test findings related to security compliance and saves them in a JSON file.

* Add Sentinel integration test plan and results

Added a comprehensive test plan for Sentinel integration, detailing test objectives, results, and acceptance criteria for various KQL rules and data ingestion.

* docs: add sentinel integration setup guide

Added a comprehensive setup guide for integrating Sentinel with Azure, covering prerequisites, workspace creation, activation, environment variable setup, ingestion, log verification, KQL rules deployment, and incident verification.
@Vishnu2707 Vishnu2707 merged commit 6ddef94 into main May 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[SCANNER] Expand network security rules AZ-NET-003 to AZ-NET-010

3 participants