Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat][New Module] Add support for Microsoft MTP / 365 Defender #21446

Merged
merged 22 commits into from
Oct 6, 2020

Conversation

P1llus
Copy link
Member

@P1llus P1llus commented Oct 1, 2020

What does this PR do?

This PR adds support for Microsoft 365 Defender (Microsoft Threat Protection), this builds upon the already existing module for Microsoft ATP (Microsoft Defender for Endpoint).

Why is it important?

Adds support for new products in beats.

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works
  • I have added an entry in CHANGELOG.next.asciidoc or CHANGELOG-developer.next.asciidoc.

Author's Checklist

The list of fields related to MTP is documented here: https://docs.microsoft.com/en-us/microsoft-365/security/mtp/api-list-incidents?view=o365-worldwide

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot added needs_team Indicates that the issue/PR needs a Team:* label and removed needs_team Indicates that the issue/PR needs a Team:* label labels Oct 1, 2020
@P1llus P1llus changed the title Filebeat mtp mvp [Filebeat][New Module] Add support for Microsoft MTP / 365 Defender Oct 1, 2020
@elasticmachine
Copy link
Collaborator

elasticmachine commented Oct 1, 2020

💚 Build Succeeded

Pipeline View Test View Changes Artifacts preview

Expand to view the summary

Build stats

  • Build Cause: [Pull request #21446 updated]

  • Start Time: 2020-10-06T08:47:35.720+0000

  • Duration: 62 min 18 sec

Test stats 🧪

Test Results
Failed 0
Passed 4417
Skipped 564
Total 4981

@P1llus
Copy link
Member Author

P1llus commented Oct 1, 2020

jenkins, test this

@P1llus P1llus requested a review from marc-gr October 1, 2020 20:01

beta[]

To configure access for filebeat to Microsoft 365 Defender you will have to create a new Azure Application registration, this will again return
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
To configure access for filebeat to Microsoft 365 Defender you will have to create a new Azure Application registration, this will again return
To configure access for Filebeat to Microsoft 365 Defender you will have to create a new Azure Application registration, this will again return.

@marc-gr marc-gr merged commit 804db76 into elastic:master Oct 6, 2020
@marc-gr marc-gr added the v7.10.0 label Oct 6, 2020
marc-gr pushed a commit to marc-gr/beats that referenced this pull request Oct 6, 2020
…lastic#21446)

* Initial commit for mtp mvp

* first finished MVP version of MTP module

* updating m365_defender with new fields and new name

* reverting some files that shouldnt be added

* removing dhcp generated logs from PR

* converting two fields to strings and updating some default template configurations

* adding changelog entry

* Initial commit for mtp mvp

* first finished MVP version of MTP module

* updating m365_defender with new fields and new name

* reverting some files that shouldnt be added

* removing dhcp generated logs from PR

* converting two fields to strings and updating some default template configurations

* adding changelog entry

* updating typo

Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
(cherry picked from commit 804db76)
v1v added a commit to v1v/beats that referenced this pull request Oct 6, 2020
* upstream/master:
  [CI] Setup git config globally (elastic#21562)
  docs: update generate_fields_docs.py (elastic#21359)
  Add support for additional fields from V2 ALB logs (elastic#21540)
  Move Prometheus query & remote_write to GA (elastic#21507)
  feat: add a new step to run the e2e tests for certain parts of Beats (elastic#21100)
  [Elastic Agent] Add elastic agent ID and version to events from filebeat and metricbeat. (elastic#21543)
  Release cloudfoundry input and processor as GA (elastic#21525)
  [Packetbeat] New SIP protocol (elastic#21221)
  [Filebeat][New Module] Add support for Microsoft MTP / 365 Defender (elastic#21446)
  [Beats][pytest] Asserting if filebeat logs include errors (elastic#20999)
  junipersrx-module initial release (elastic#20017)
  Add a persistent cache for cloudfoundry metadata based on badger (elastic#20775)
  Add missing changelog entry for cisco umbrella (elastic#21550)
  [Elastic Agent] Add upgrade CLI to initiate upgrade of Agent locally (elastic#21425)
  Enable filestream input (elastic#21533)
  Add filestream input reader (elastic#21481)
  [CI] fix 'no matches found within 10000' (elastic#21466)
  Fix billing.go aws.GetStartTimeEndTime (elastic#21531)
marc-gr added a commit that referenced this pull request Oct 6, 2020
…21446) (#21555)

* Initial commit for mtp mvp

* first finished MVP version of MTP module

* updating m365_defender with new fields and new name

* reverting some files that shouldnt be added

* removing dhcp generated logs from PR

* converting two fields to strings and updating some default template configurations

* adding changelog entry

* Initial commit for mtp mvp

* first finished MVP version of MTP module

* updating m365_defender with new fields and new name

* reverting some files that shouldnt be added

* removing dhcp generated logs from PR

* converting two fields to strings and updating some default template configurations

* adding changelog entry

* updating typo

Co-authored-by: Marc Guasch <marc-gr@users.noreply.github.com>
(cherry picked from commit 804db76)

Co-authored-by: Marius Iversen <pillus@chasenet.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants