What Changed
Maintenance updates across three solutions addressing outdated reference links and MITRE ATT&CK technique accuracy:
Microsoft Business Applications: Corrected MITRE technique in Dataverse identity management hunting query from T0819 → T1190 Microsoft Defender XDR: Updated SUNSPOT malware detection with current Microsoft blog link and bumped version to 1.0.3 Windows Security Events: Updated device join detection reference link and bumped version to 1.0.6
All changes are documentation/metadata updates with no impact to detection logic or KQL queries. Version bumps follow repository standards for detection template modifications.
Affected Files
Solutions/Microsoft Business Applications/Hunting Queries/Dataverse - Identity management changes without MFA.yaml
Solutions/Microsoft Defender XDR/Analytic Rules/SUNSPOTHashes.yaml
Solutions/Microsoft Defender XDR/Hunting Queries/Campaigns/JudgementPandaExfilActivity.yaml
Solutions/Windows Security Events/Analytic Rules/LocalDeviceJoinInfoAndTransportKeyRegKeysAccess.yaml