Forum Discussion
M365 Defender custom queries host in Azure Devops repo
Custom detection rules are rules you can design and tweak using advanced hunting queries. These rules let you proactively monitor various events and system states, including suspected breach activity and misconfigured endpoints.
*To create a custom detection rule, you need to prepare the query in the Microsoft 365 Defender portal, go to Advanced hunting and select an existing query or create a new query. Then you need to provide alert details, choose the impacted entities, specify actions, set the rule scope, and review and turn on the rule.
* To manage custom detections, you need to be assigned one of these roles: Security settings (manage), Security administrator, or Security operator.
* Defender for DevOps allows you to manage your connected environments and provides your security teams with a high level overview of discovered issues that may exist within them through the Defender for DevOps console.
documentation and articles
- Create and manage custom detection rules in Microsoft 365 Defender. https://learn.microsoft.com/en-us/microsoft-365/security/defender/custom-detection-rules?view=o365-worldwide.
- Microsoft Defender for DevOps - the benefits and features. https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction.
- Create and manage custom detections rules - GitHub. https://github.com/MicrosoftDocs/microsoft-365-docs/blob/public/microsoft-365/security/defender/custom-detection-rules.md.
- JiriLiskaJul 11, 2023Copper ContributorThanks but what you have posted here has actually nothing to do with my question :). I'm looking for more like "TH rules as code" approach, I'm fully aware how to create custom rule..
- H2OJul 11, 2023Iron Contributor- Rules as Code’ will let computers apply laws and regulations. But. https://theconversation.com/rules-as-code-will-let-computers-apply-laws-and-regulations-but-over-rigid-interpretations-would-undermine-our-freedoms-149992.
- Four things you should know about Rules as Code. https://govinsider.asia/inclusive-gov/four-things-you-should-know-about-rules-as-code/.
- Cracking the Code: Rulemaking for humans and machines. https://oecd-opsi.org/publications/cracking-the-code/.- JiriLiskaJul 11, 2023Copper Contributor
???? WHAT???! This is not even touching the topic.....