Updated Microsoft Defender XDR to 3.0.16 and aligns the affected analytic and hunting queries - #14838
Conversation
Updates Microsoft Defender XDR to 3.0.16 and aligns the affected analytic and hunting queries, package template, and generated solution package with the new versions.
|
Hello how are you I am GitHub bot |
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Updates the Microsoft Defender XDR solution package version to 3.0.16 and increments the affected detection/hunting content versions while adjusting KQL output fields for the “Anomalous…FileDeletion” content.
Changes:
- Bumped solution package version from 3.0.15 → 3.0.16.
- Updated KQL projection ordering in the affected analytic + hunting queries.
- Removed several extended alias columns in the hunting query and bumped rule/query versions 1.0.1 → 1.0.2.
Reviewed changes
Copilot reviewed 3 out of 5 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| Solutions/Microsoft Defender XDR/Hunting Queries/Impact/AnomalousVoulmeOfFileDeletion.yaml | KQL output adjustments; removed alias columns; version bump to 1.0.2 |
| Solutions/Microsoft Defender XDR/Data/Solution_Microsoft Defender XDR.json | Solution package version bump to 3.0.16 |
| Solutions/Microsoft Defender XDR/Analytic Rules/Impact/AnomalousVoulmeOfFileDeletion.yaml | KQL output adjustments; version bump to 1.0.2 |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Updates Microsoft Defender XDR to 3.0.16 and aligns the affected analytic and hunting queries, package template, and generated solution package with the new versions.
Required items, please complete
Change(s):
Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present:
Guidance <- remove section before submitting
Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:
Thank you for your contribution to the Microsoft Sentinel Github repo.
Change(s):
Reason for Change(s):
Version updated:
Testing Completed:
Note: If updating a detection, you must update the version field.
Checked that the validations are passing and have addressed any issues that are present:
Note: Let us know if you have tried fixing the validation error and need help.