{"id":1661,"date":"2023-05-23T08:01:03","date_gmt":"2023-05-22T23:01:03","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=1661"},"modified":"2023-05-23T08:04:39","modified_gmt":"2023-05-22T23:04:39","slug":"mc559251-update-your-custom-detections-to-leverage-new-actiontypes-in-devicenetworkevents","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-05-23-mc559251-update-your-custom-detections-to-leverage-new-actiontypes-in-devicenetworkevents","title":{"rendered":"MC559251 | Update your custom detections to leverage new ActionTypes in DeviceNetworkEvents"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC559251 | Update your custom detections to leverage new ActionTypes in DeviceNetworkEvents<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>planForChange<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>05\/22\/2023 22:53:02<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>05\/22\/2023 22:52:16<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>08\/31\/2023 07:00:00<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<p>On July 18, 2023, Microsoft will be retiring a subset of signatures found in the &#8220;NetworkSignaturesInspected&#8221; action type of Advanced Hunting. With the recent integration of Zeek providing advanced protocol parsing capabilities, which result in better visibility   into full network sessions compared to the raw packet bytes found in the &#8220;NetworkSignaturesInspected&#8221; action type of Advanced Hunting today, the effort to consolidate will provide a better overall experience for our customers by reducing the signatures that   serve similar functions without the added benefits provided by the new Zeek alternative.<\/p>\n<p>[When this will happen:]<\/p>\n<p>July 18, 2023<\/p>\n<p>[How this affects your organization:]<\/p>\n<p>For customers currently using the &#8220;NetworkSignaturesInspected&#8221; action type, here is a list of signatures that will be deprecated, referenced alongside their alternatives available in Advanced Hunting:&nbsp;<\/p>\n<p>  <\/p>\n<table>  <\/p>\n<tbody>\n<tr>  <\/p>\n<th>Protocol \/ Signature Name<\/th>\n<p>  <\/p>\n<th>Old Action Type<\/th>\n<p>  <\/p>\n<th>New Action Type<\/th>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>SSH<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>SshConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>FTP_Upload<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>FtpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>FFP_Client<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>FtpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_Client<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_Server<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_RequestBodyParameters<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTPS_Client<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>SslConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>DNS_Request<\/td>\n<p>  <\/p>\n<td>NetworkSignatureInspected<\/td>\n<p>  <\/p>\n<td>DnsConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/tbody>\n<\/table>\n<p>  <\/p>\n<p>[What you can do to prepare:]<\/p>\n<p>Your organization might be using a &#8220;NetworkSignatureInspected&#8221; action type in your Advanced Hunting queries and custom detections. Particularly, you might be using a Signature Name that is going to be deprecated soon. Please update your queries with the   new action types so that you can leverage this valuable data and avoid breaking your current custom detections.  <\/p>\n<p>An example of your old query:  <\/p>\n<p style=\"margin-left: 25px;\">DeviceNetworkEvents&nbsp;&nbsp;  <\/p>\n<p style=\"margin-left: 25px;\">| where ActionType == &#8220;NetworkSignatureInspected&#8221;  <\/p>\n<p style=\"margin-left: 25px;\">| extend AdditionalFields = todynamic(AdditionalFields)  <\/p>\n<p style=\"margin-left: 25px;\">| where AdditionalFields.SignatureName == &#8220;SSH&#8221;  <\/p>\n<p>Your new query:  <\/p>\n<p style=\"margin-left: 25px;\">DeviceNetworkEvents&nbsp;&nbsp;  <\/p>\n<p style=\"margin-left: 25px;\">| where ActionType == &#8220;SshConnectionInspected&#8221;  <\/p>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<p>2023 \u5e74 7 \u6708 18 \u65e5\u306b\u3001Microsoft \u306f\u9ad8\u5ea6\u306a\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0\u306e &#8220;\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f&#8221; \u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e\u3067\u898b\u3064\u304b\u3063\u305f\u7f72\u540d\u306e\u30b5\u30d6\u30bb\u30c3\u30c8\u3092\u5ec3\u6b62\u3057\u307e\u3059\u3002\u9ad8\u5ea6\u306a\u30d7\u30ed\u30c8\u30b3\u30eb\u89e3\u6790\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308bZeek\u306e\u6700\u8fd1\u306e\u7d71\u5408\u306b\u3088\u308a\u3001\u4eca\u65e5\u306e\u9ad8\u5ea6\u306a\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0\u306e\u300cNetworkSignaturesInspected\u300d\u30a2\u30af\u30b7\u30e7\u30f3\u30bf\u30a4\u30d7\u306b\u898b\u3089\u308c\u308b\u751f\u306e\u30d1\u30b1\u30c3\u30c8\u30d0\u30a4\u30c8\u3068\u6bd4\u8f03\u3057\u3066\u3001\u5b8c\u5168\u306a\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30bb\u30c3\u30b7\u30e7\u30f3\u306e\u53ef\u8996\u6027\u304c\u5411\u4e0a\u3057\u3001\u7d71\u5408\u306e\u53d6\u308a\u7d44\u307f\u306b\u3088\u308a\u3001\u65b0\u3057\u3044Zeek\u306e\u4ee3\u66ff\u306b\u3088\u3063\u3066\u63d0\u4f9b\u3055\u308c\u308b\u8ffd\u52a0\u306e\u5229\u70b9\u306a\u3057\u306b\u3001\u540c\u69d8\u306e\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b\u30b7\u30b0\u30cd\u30c1\u30e3\u3092\u6e1b\u3089\u3059\u3053\u3068\u306b\u3088\u308a\u3001\u304a\u5ba2\u69d8\u306b\u5168\u4f53\u7684\u306a\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u304c\u5411\u4e0a\u3057\u307e\u3059\u3002<\/p>\n<p>[\u3053\u308c\u304c\u8d77\u3053\u308b\u3068\u304d:]<\/p>\n<p>2023\u5e747\u670818\u65e5<\/p>\n<p>[\u3053\u308c\u304c\u7d44\u7e54\u306b\u4e0e\u3048\u308b\u5f71\u97ff:]<\/p>\n<p>\u73fe\u5728 &#8220;NetworkSignaturesInspected&#8221; \u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u304a\u5ba2\u69d8\u306e\u5834\u5408\u306f\u3001\u975e\u63a8\u5968\u306b\u306a\u308b\u7f72\u540d\u306e\u4e00\u89a7\u3092\u6b21\u306b\u793a\u3057\u307e\u3059\u3002&nbsp;<\/p>\n<p>  <\/p>\n<table>  <\/p>\n<tbody>\n<tr>  <\/p>\n<th>\u30d7\u30ed\u30c8\u30b3\u30eb\/\u7f72\u540d\u540d<\/th>\n<th>\u53e4\u3044<\/th>\n<p>  \u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e  <\/p>\n<th>\u65b0\u3057\u3044\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e<\/th>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>\u30c6\u30a3\u30c3\u30ab\u30fc<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>Ssh\u63a5\u7d9a\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>FTP_Upload<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>Ftp\u63a5\u7d9a\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>FFP_Client<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>Ftp\u63a5\u7d9a\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_Client<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_Server<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTP_RequestBodyParameters<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>HttpConnectionInspected<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>HTTPS_Client<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>Ssl\u63a5\u7d9a\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/tr>\n<p>  <\/p>\n<tr>  <\/p>\n<td>DNS_Request<\/td>\n<p>  <\/p>\n<td>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/p>\n<td>Dns\u63a5\u7d9a\u691c\u67fb\u6e08\u307f<\/td>\n<p>  <\/tr>\n<p>  <\/tbody>\n<\/table>\n<p>  <\/p>\n<p>\u3010\u6e96\u5099\u3067\u304d\u308b\u3053\u3068:\u3011<\/p>\n<p>\u7d44\u7e54\u3067\u306f\u3001\u9ad8\u5ea6\u306a\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0 \u30af\u30a8\u30ea\u3068\u30ab\u30b9\u30bf\u30e0\u691c\u51fa\u3067 &#8220;\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7f72\u540d\u691c\u67fb\u6e08\u307f&#8221; \u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u7279\u306b\u3001\u307e\u3082\u306a\u304f\u5ec3\u6b62\u3055\u308c\u308b\u7f72\u540d\u540d\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u8cb4\u91cd\u306a\u30c7\u30fc\u30bf\u3092\u6d3b\u7528\u3057\u3001\u73fe\u5728\u306e\u30ab\u30b9\u30bf\u30e0\u691c\u51fa\u3092\u58ca\u3055\u306a\u3044\u3088\u3046\u306b\u3001\u65b0\u3057\u3044\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u7a2e\u985e\u3067\u30af\u30a8\u30ea\u3092\u66f4\u65b0\u3057\u3066\u304f\u3060\u3055\u3044\u3002  <\/p>\n<p>\u53e4\u3044\u30af\u30a8\u30ea\u306e\u4f8b:  <\/p>\n<p style=\"margin-left: 25px;\">\u30c7\u30d0\u30a4\u30b9 \u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30a4\u30d9\u30f3\u30c8&nbsp;&nbsp;  <\/p>\n<p style=\"margin-left: 25px;\">|\u3053\u3053\u3067\u3001ActionType == &#8220;NetworkSignatureInspected&#8221;  <\/p>\n<p style=\"margin-left: 25px;\">|\u62e1\u5f35\u8ffd\u52a0\u30d5\u30a3\u30fc\u30eb\u30c9 = \u52d5\u7684(\u8ffd\u52a0\u30d5\u30a3\u30fc\u30eb\u30c9)  <\/p>\n<p style=\"margin-left: 25px;\">|\u3053\u3053\u3067\u3001AdditionalFields.SignatureName == &#8220;SSH&#8221;  <\/p>\n<p>\u65b0\u3057\u3044\u30af\u30a8\u30ea:  <\/p>\n<p style=\"margin-left: 25px;\">\u30c7\u30d0\u30a4\u30b9 \u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30a4\u30d9\u30f3\u30c8&nbsp;&nbsp;  <\/p>\n<p style=\"margin-left: 25px;\">|\u3053\u3053\u3067\u3001ActionType == &#8220;SshConnectionInspected&#8221;  <\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC559251 | Update your custom detections to leverage new ActionTypes in DeviceNetworkEvents Classification pla [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1661","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/1661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=1661"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/1661\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=1661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=1661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=1661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}