Skip to content

Fixed Bugs in SOC Handbook solution and updated workbooks#14671

Open
v-sabiraj wants to merge 7 commits into
masterfrom
v-sabiraj-AnalyticsEfficencyworkbook
Open

Fixed Bugs in SOC Handbook solution and updated workbooks#14671
v-sabiraj wants to merge 7 commits into
masterfrom
v-sabiraj-AnalyticsEfficencyworkbook

Conversation

@v-sabiraj

@v-sabiraj v-sabiraj commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

For Analytics Efficiency Workbook

  • Fix 'incedent' -> 'incident' typos in KQL queries and UI messages

  • Fix 'efficacy' -> 'efficiency' in workbook description

  • Update 'Azure Sentinel' -> 'Microsoft Sentinel' in text content

  • Add Reconnaissance, Resource Development, and Stealth to MITRE ATT&CK tactics

  • Remove hardcoded 24h timeContext overrides from several chart items

  • Bump workbook version to 1.2.1

    Required items, please complete

    Change(s):

    • See guidance below

    Reason for Change(s):

    • See guidance below

    Version Updated:

    • Required only for Detections/Analytic Rule templates
    • See guidance below

    Testing Completed:

    • See guidance below

    Checked that the validations are passing and have addressed any issues that are present:

    • See guidance below

Guidance <- remove section before submitting


Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:

Thank you for your contribution to the Microsoft Sentinel Github repo.

Details of the code changes in your submitted PR. Providing descriptions for pull requests ensures there is context to changes being made and greatly enhances the code review process. Providing associated Issues that this resolves also easily connects the reason.

Change(s):

  • Updated syntax for XYZ.yaml

Reason for Change(s):

Version updated:

  • Yes
  • Detections/Analytic Rule templates are required to have the version updated

The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly. If your submission requires a custom parser or function, it must be submitted with the PR.

Testing Completed:

  • Yes/No/Need Help

Note: If updating a detection, you must update the version field.

Before the submission has been made, please look at running the KQL and Yaml Validation Checks locally.
https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally

Checked that the validations are passing and have addressed any issues that are present:

  • Yes/No/Need Help

Note: Let us know if you have tried fixing the validation error and need help.

References:


- Fix 'incedent' -> 'incident' typos in KQL queries and UI messages
- Fix 'efficacy' -> 'efficiency' in workbook description
- Update 'Azure Sentinel' -> 'Microsoft Sentinel' in text content
- Add Reconnaissance, Resource Development, and Stealth to MITRE ATT&CK tactics
- Remove hardcoded 24h timeContext overrides from several chart items
- Bump workbook version to 1.2.1
@v-sabiraj
v-sabiraj requested review from a team as code owners July 13, 2026 12:40
@v-sabiraj v-sabiraj changed the title Fixed Bugs and updated Analytics Efficiency workbook Fixed Bugs in SOC Handbook solution and updated workbooks Jul 13, 2026
@v-atulyadav v-atulyadav self-assigned this Jul 13, 2026
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Jul 13, 2026
v-sabiraj and others added 6 commits July 14, 2026 16:50
Update the Security Alerts dashboard text to use Microsoft Sentinel wording and correct the Intsights IOC workbook item structure so that the results can load with selection of the severity
Adjust the SOC Handbook MITREAttack workbook query to normalize additional tactic names and include newer tactic categories in the tactic-level breakdown. This updates the KQL logic to better align workbook results with current MITRE ATT&CK tactic naming.
Update all references to 'Azure Sentinel' with 'Microsoft Sentinel' in the SentinelCentral workbook. This reflects the product rebranding from Azure Sentinel to Microsoft Sentinel across UI text, titles, link labels, and help documentation.
Bumps the SOC Handbook solution and ARM template versioning to 3.0.7, including updated workbook content versions and a new 3.0.7 package zip. The update also refreshes workbook/createUiDefinition text and serialized workbook content with wording, branding, and query/content improvements (for example Sentinel naming updates, wording fixes, and incident/tactics refinements).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content-Package Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants