Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
{
"Properties": [
{
"Name": "TenantId",
"Type": "string"
},
{
"Name": "SourceSystem",
"Type": "string"
},
{
"Name": "MG",
"Type": "string"
},
{
"Name": "ManagementGroupName",
"Type": "string"
},
{
"Name": "TimeGenerated",
"Type": "datetime"
},
{
"Name": "Computer",
"Type": "string"
},
{
"Name": "RawData",
"Type": "string"
},
{
"Name": "censys_url_s",
"Type": "string"
},
{
"Name": "count_d",
"Type": "real"
},
{
"Name": "fields_s",
"Type": "string"
},
{
"Name": "values_s",
"Type": "string"
},
{
"Name": "ioc_s",
"Type": "string"
},
{
"Name": "values_g",
"Type": "string"
},
{
"Name": "Type",
"Type": "string"
},
{
"Name": "_ResourceId",
"Type": "string"
}
],
"Name": "CensysRelatedInfrastructure_CL"
}
11 changes: 0 additions & 11 deletions Sample Data/Custom/CensysRelatedAssetsDetails_CL.csv

This file was deleted.

11 changes: 11 additions & 0 deletions Sample Data/Custom/CensysRelatedInfrastructure_CL.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
TenantId,SourceSystem,MG,ManagementGroupName,"TimeGenerated [UTC]",Computer,RawData,"censys_url_s","count_d","fields_s","values_s","ioc_s","values_g",Type,"_ResourceId"
Copy link

Copilot AI Apr 8, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CSV header includes a UTF-8 BOM character before TenantId (visible as an extra character at the start). This can cause schema/parsing mismatches in tooling that expects exact column names; please remove the BOM so the first header is exactly TenantId.

Suggested change
TenantId,SourceSystem,MG,ManagementGroupName,"TimeGenerated [UTC]",Computer,RawData,"censys_url_s","count_d","fields_s","values_s","ioc_s","values_g",Type,"_ResourceId"
TenantId,SourceSystem,MG,ManagementGroupName,"TimeGenerated [UTC]",Computer,RawData,"censys_url_s","count_d","fields_s","values_s","ioc_s","values_g",Type,"_ResourceId"

Copilot uses AI. Check for mistakes.
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.endpoints.http.html_title%3D%22MoonTV%22&org=e48bb962-9a41-4a49-9912-55205baecd12",3201,"host.services.endpoints.http.html_title",MoonTV,"146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.tls.ja3s%3D%2215af977ce25de452b96affa2addb1036%22&org=e48bb962-9a41-4a49-9912-55205baecd12",19727607,"host.services.tls.ja3s",,"146.235.236.104","15af977c-e25d-e452-b96a-ffa2addb1036","CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.tls.ja4s%3D%22t130200_1302_a56c5b993250%22&org=e48bb962-9a41-4a49-9912-55205baecd12",19727607,"host.services.tls.ja4s","t130200_1302_a56c5b993250","146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.cert.parsed.subject.common_name%3D%22Common%20Name%22&org=e48bb962-9a41-4a49-9912-55205baecd12",4805,"host.services.cert.parsed.subject.common_name","Common Name","146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.endpoints.http.html_title%3D%22400%20Bad%20Request%22&org=e48bb962-9a41-4a49-9912-55205baecd12",2523637,"host.services.endpoints.http.html_title","400 Bad Request","146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.endpoints.http.html_title%3D%22PanSou%20%E7%9B%98%E6%90%9C%22&org=e48bb962-9a41-4a49-9912-55205baecd12",1110,"host.services.endpoints.http.html_title","PanSou 盘搜","146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.cert.parsed.issuer.common_name%3D%22Common%20Name%22&org=e48bb962-9a41-4a49-9912-55205baecd12",4791,"host.services.cert.parsed.issuer.common_name","Common Name","146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.cert.parsed.issuer.locality%3D%22City%22&org=e48bb962-9a41-4a49-9912-55205baecd12",423057,"host.services.cert.parsed.issuer.locality",City,"146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.cert.parsed.subject.organization%3D%22Organization%22&org=e48bb962-9a41-4a49-9912-55205baecd12",391915,"host.services.cert.parsed.subject.organization",Organization,"146.235.236.104",,"CensysRelatedInfrastructure_CL",
"e67ced1f-ebf3-4c52-b4cc-46585da300ec",RestAPI,,,"4/3/2026, 10:37:09.271 AM",,,"https://platform.censys.io/search?q=host.services.cert.parsed.ja4x%3D%222166164053c1_2166164053c1_795797892f9c%22&org=e48bb962-9a41-4a49-9912-55205baecd12",163472,"host.services.cert.parsed.ja4x","2166164053c1_2166164053c1_795797892f9c","146.235.236.104",,"CensysRelatedInfrastructure_CL",
1 change: 1 addition & 0 deletions Solutions/Censys/Data/Solution_Censys.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@
"Playbooks/CensysHostHistory/azuredeploy.json",
"Playbooks/CensysIncidentEnrichment/azuredeploy.json",
"Playbooks/CensysIOCLookup/azuredeploy.json",
"Playbooks/CensysRelatedInfrastructure/azuredeploy.json",
"Playbooks/CensysRescan/azuredeploy.json"
Comment on lines 13 to 17
Copy link

Copilot AI Apr 8, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a new playbook to the solution manifest should generally be accompanied by a solution version bump and consistent release notes entry for that bumped version (to ensure packaging/update flows can detect and distribute the new content correctly). Right now the release notes attempt to document the change under the existing 3.0.0, which is problematic.

Copilot uses AI. Check for mistakes.
],
"Workbooks": [
Expand Down
Binary file modified Solutions/Censys/Package/3.0.0.zip
Binary file not shown.
2 changes: 1 addition & 1 deletion Solutions/Censys/Package/createUiDefinition.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"config": {
"isWizard": false,
"basics": {
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Censys.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Censys/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nLeverage playbooks to enrich alerts and incidents with Censys Internet data. Analyst can lookup known information about IPs, domains, certificate SHAs in Censys.\n\n**Workbooks:** 1, **Playbooks:** 10\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Censys.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Censys/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nLeverage playbooks to enrich alerts and incidents with Censys Internet data. Analyst can lookup known information about IPs, domains, certificate SHAs in Censys.\n\n**Workbooks:** 1, **Playbooks:** 11\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"subscription": {
"resourceProviders": [
"Microsoft.OperationsManagement/solutions",
Expand Down
Loading
Loading