briandelmsft / SentinelAutomationModules

The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
MIT License
201 stars 55 forks source link

STAT v2 Preview - Problems with the Sample-STAT-Triage Playbooks #425

Closed lorisAmbrozzo closed 12 months ago

lorisAmbrozzo commented 1 year ago

Describe the bug I'm testing STAT v2. So far it looks very nice. Thank you for this big update! 💯 I have discovered the following bug. I am deploying the version 2 module with a user-assigned managed identity. When I deploy the sample STAT triage playbook and run it on a playbook, I get the following error (picture 1 and picture 2) for all three modules (AAD Risks Module / Related Alerts Module / Threat Intel Module) in the playbook.

But when I create a new clean playbook and rebuild the hole sample playbook in this new playbook. The modules run without this errors (see third screenshot).

Module Name AAD Risks Module / Related Alerts Module / Threat Intel Module

To Reproduce Deploy Stat Version 2 with a user-assigned managed identity. Run the Sample Playbook on an incident.

Expected behavior Call the different modules with no errors

Screenshots Sample-STAT-Triage error: image Sample-STAT-Triage error: image New created playbook: image

briandelmsft commented 1 year ago

@lorisAmbrozzo thanks for the detailed description. I will take a look into it

briandelmsft commented 12 months ago

Fixed in latest preview deployment update: https://github.com/briandelmsft/SentinelAutomationModules/tree/statv2_preview/Deploy