11-19-2018 02:03 PM - edited 11-19-2018 02:10 PM
Just started going through the new miners and looking over docs, we are not in production on our deployment for O365 yet. I understand there are app-Id's that would catch most of these, but I noticed that the URL Minemeld feed for the "any-any" version includes quite a few URLS....specifically including:
I understand that the best way to police this type of access is to use app-id and decryption in a single ruleset that would include these lists. I just don't understand why items like the above are in this list getting mined directly from microsoft.....
I'm guessing that SSL decryption is absolutely essential before allowing anything out to these lists, and that you would only use these lists in your O365 app-id rulesets?- not the dependencies?
It appears that in the ruleset setup in the below article banking on the dependencies for O365-SSL and Web-browsing, as the firewall would read-down the ruleset, it would see your O365 enterprise-access custom app- and hit that rule, and then proceed to your dependencies. The catch all dependencies rule, just makes me a bit nervous,
Long story short- are people creating exclude lists, to Omit some of these IP/URL's that they don't want to mine?
11-20-2018 05:42 AM
you can generate a feed with 3rd party removed by using the output o365-api.feed-no-3rdparty prototype: https://github.com/PaloAltoNetworks/minemeld-node-prototypes/blob/master/prototypes/o365-api.yml#L50...
It applies some dump heuristics to detect if the IP Address/URLs belongs to MSFT or to 3rd parties.
11-20-2018 11:26 AM - edited 11-20-2018 11:29 AM
If I'm reading this right, that miner is keying off of the keyword "integration" in the link that Microsoft provides, right? Is this marked experimental due to that- or that they could change that keyword at any time?
PS- Thank you Lmori for the quick replies. Your a wizard on this.
11-30-2018 08:25 AM
We've run into the same 3rd party issue. Therefore, per this thread, we implemented the "...no-3rdparty" output but it is not removing the 3rd parties like Dropbox.com. The thread also mentioned an issue with this output, is there an ETA on when the issue will be resolved? Thanks
12-06-2018 02:14 AM
We have added a new feature that will be shipped in the next release (0.9.52 - by the end of the week). The O365 Miners now have an "Integrations" flag on the WebUI. By disabling the Integrations, 3rd party URLs will be removed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!