Solutions/AtlassianJiraAudit/Hunting Queries/JiraProjectVersionsReleased.yaml (24 lines of code) (raw):

id: 103ccb8d-f910-4978-aba7-1ad598db822b name: Jira - Project versions released description: | 'Query searches for project versions released.' severity: Medium requiredDataConnectors: - connectorId: JiraAuditAPI dataTypes: - JiraAudit tactics: - Impact relevantTechniques: - T1565 query: | JiraAudit | where TimeGenerated > ago(24h) | where EventMessage =~ 'Project version released' | project EventCreationTime, UserName, ObjectItemName, AssociatedItems | extend AccountCustomEntity = UserName entityMappings: - entityType: Account fieldMappings: - identifier: Name columnName: AccountCustomEntity