From f52cfb3729c4c5fa43002965653029203785e0cd Mon Sep 17 00:00:00 2001 From: James Valente <65730960+jvalente-salemstate@users.noreply.github.com> Date: Mon, 13 Jan 2025 08:40:34 -0500 Subject: [PATCH] [Rule: Tuning] - Azure blob permission modification tagging - Correct tags (#4371) * Remove `Data Source: Elastic Defend` tag * Update metadata --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> --- .../defense_evasion_azure_blob_permissions_modified.toml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/rules/integrations/azure/defense_evasion_azure_blob_permissions_modified.toml b/rules/integrations/azure/defense_evasion_azure_blob_permissions_modified.toml index 7802a541a..7c4271d1f 100644 --- a/rules/integrations/azure/defense_evasion_azure_blob_permissions_modified.toml +++ b/rules/integrations/azure/defense_evasion_azure_blob_permissions_modified.toml @@ -2,7 +2,7 @@ creation_date = "2021/09/22" integration = ["azure"] maturity = "production" -updated_date = "2024/05/21" +updated_date = "2025/01/11" [rule] author = ["Austin Songer"] @@ -32,8 +32,7 @@ tags = [ "Domain: Cloud", "Data Source: Azure", "Use Case: Identity and Access Audit", - "Tactic: Defense Evasion", - "Data Source: Elastic Defend", + "Tactic: Defense Evasion" ] timestamp_override = "event.ingested" type = "query"