Skip to content

Commit cd9d247

Browse files
fix: validation errors
1 parent f269f7a commit cd9d247

File tree

2 files changed

+1
-5
lines changed

2 files changed

+1
-5
lines changed

Solutions/Recorded Future Identity/Analytic Rules/IncidentCreation/RecordedFutureIdentityExposure.yaml

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,6 @@ description: |
44
'Creates incidents when Recorded Future Identity detects compromised credentials for users in your organization'
55
severity: High
66
status: Available
7-
requiredDataConnectors:
8-
- connectorId: RecordedFutureIdentity
9-
dataTypes:
10-
- RecordedFutureIdentity_PlaybookAlertResults_CL
117
queryFrequency: 15m
128
queryPeriod: 15m
139
triggerOperator: gt

Solutions/Recorded Future Identity/Playbooks/RFI-Playbook-Alert-Importer-LAW-Sentinel/azuredeploy.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"contentVersion": "1.2.0.0",
44
"metadata": {
55
"title": "RFI-Playbook-Alert-Importer-LAW-Sentinel (DEPRECATED)",
6-
"description": "DEPRECATED: This playbook creates incidents via the Azure Sentinel Logic Apps connector, which do not appear in the unified Microsoft Defender portal. Use RFI-Playbook-Alert-Importer-LAW instead and create incidents using a Scheduled Analytics Rule. This playbook fetches identity compromises from Recorded Future, places users in a security group and confirms them as 'risky users' in Entra ID.",
6+
"description": "DEPRECATED: This playbook creates incidents via the Azure Microsoft Sentinel Logic Apps connector, which do not appear in the unified Microsoft Defender portal. Use RFI-Playbook-Alert-Importer-LAW instead and create incidents using a Scheduled Analytics Rule. This playbook fetches identity compromises from Recorded Future, places users in a security group and confirms them as 'risky users' in Entra ID.",
77
"prerequisites": [
88
"First install the RFI-CustomConnector-0-2-0 custom connector",
99
"To use the Recorded Future Identity connector, you will need a valid API token from Recorded Future as described in the [documentation](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future%20Identity/Playbooks/readme.md#how-to-obtain-recorded-future-api-token)"

0 commit comments

Comments
 (0)