-
Notifications
You must be signed in to change notification settings - Fork 3.5k
Gravityzone Solution v3.0.0 #13299
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Gravityzone Solution v3.0.0 #13299
Conversation
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-11T13:56:42.474Z |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-12T03:15:51.630Z |
|
Hi @gbarbieru, |
|
@v-atulyadav i will open a separate PR for the ASIM rules |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:29:05.729Z |
d349653 to
a845d85
Compare
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:31:01.249Z |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:31:28.024Z |
|
#13330 PR for ASim parsers |
|
Hi @gbarbieru,
|
|
hi @v-atulyadav |
|
Qs about: https://github.com/Azure/Azure-Sentinel/actions/runs/20306048443/job/58524457107
|
|
not sure what to do about this one https://github.com/Azure/Azure-Sentinel/actions/runs/20306048361/job/58524455490?pr=13299 . should i wait for the ASIM pr merge ? |
|
Hi @gbarbieru,
https://github.com/Azure/Azure-Sentinel/wiki/Query-Style-Guide |
|
hi @v-atulyadav
|
|
Minor fix for tactics field |
|
Hi @gbarbieru,
|
|
Fixed branding issue |








Change(s):
- Creating a Sentinel solution for Bitdefender GravityZone. This solution uses a push-based approach using just a DCR, a DCE, custom table and an App registration with credentials to push data to Sentinel. An analytic rule that uses custom ASIM parsers is used to generate Incidents.
Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present:
Before going into this topic I want to disclose that development in my team is done on Linux workstations and the available tooling and guides offered by Microsoft kinda lack in this department. Local YAML testing was eventually achieved, but KQL validation failed. Due to time constraints additional effort in making them work Linux environments was abandoned and testing was eventually done on Microsoft Sentinel accounts via end-to-end testing.