Closed NobleWolf closed 4 weeks ago
@NobleWolf at present we don't support that module as an input to the score (https://github.com/briandelmsft/SentinelAutomationModules/wiki/Modules#supported-module-inputs)
We didn't really have have a good approach to using the out of office information to impact the score. We mainly intended it as information to the analyst, for example if their message says they're travelling on business that may be useful to know in some incidents.
We can easily make the scoring module not fail when it's added but not have an impact on the score. If you have thoughts on how it should influence the score we'd love to hear them
@briandelmsft thank you for the explination. I can see scenarios when being Out of Office and your account being used would be suspicious, but if you left your computer on and Outlook syncs it could create an authentication log. So I guess being OOO + suspicious activity would still be a human decision. So I understand why this decision was made.
It would be helpful if the error message could be updated.
Current error in Risk Scoring Module:
{
"statusCode": 400,
"headers": {
"Transfer-Encoding": "chunked",
"Date": "Fri, 04 Oct 2024 20:53:30 GMT",
"Content-Type": "application/json",
"Content-Length": "1678"
},
"body": {
"Error": "Failed to score the module None with label Out of Office",
"InvocationId": "62d87bbf-6a6c-437c-a67a-db5815043563",
"SourceError": {
"Error": "Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: None"
},
"Traceback": [
"Traceback (most recent call last):\n",
" File \"/home/site/wwwroot/modules/scoring.py\", line 21, in execute_scoring_module\n score_module(score, module, module_body, per_item, multiplier, label)\n",
" File \"/home/site/wwwroot/modules/scoring.py\", line 82, in score_module\n raise STATError(f'Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: {module}')\n",
"classes.STATError: Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: None\n",
"\nDuring handling of the above exception, another exception occurred:\n\n",
"Traceback (most recent call last):\n",
" File \"/home/site/wwwroot/modules/__init__.py\", line 19, in main\n return_data = coordinator.initiate_module(module_name=module_name, req_body=req_body)\n",
" File \"/home/site/wwwroot/shared/coordinator.py\", line 13, in initiate_module\n return_data = scoring.execute_scoring_module(req_body)\n",
" File \"/home/site/wwwroot/modules/scoring.py\", line 23, in execute_scoring_module\n raise STATError(f'Failed to score the module {module} with label {label}', {'Error': str(e)})\n",
"classes.STATError: ('Failed to score the module None with label Out of Office', {'Error': 'Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: None'})\n"
]
}
}
I think a more descriptive error would be helpful.
Current error message: Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: None
Possible Updated message: Incorrectly formatted data or data from an unsupported module was passed to the Scoring Module, module name: Out of Office Module. See Risk Scoring Module's Supported Module Input list.
I understand the updated message suggestion does duplicate the "unsupported module" information, but my first instinct was to assume the error was due to "incorrectly formatted data" because the original message ended with ... module name: None
making me think it was an input data error.
@NobleWolf thanks, we'll fix that
issue is the module class doesn't define a name like other modules do, so it's missing on the output
Steps to repeat:
Risk Scoring Module ScoringData field:
Result: