Solutions/AtlassianJiraAudit/Hunting Queries/JiraUpdatedProjectVersions.yaml (24 lines of code) (raw):

id: e78cb74b-576b-4e35-a46c-8d328b2d4040 name: Jira - Project versions description: | 'Query searches for project versions.' severity: Medium requiredDataConnectors: - connectorId: JiraAuditAPI dataTypes: - JiraAudit tactics: - Impact relevantTechniques: - T1565 query: | JiraAudit | where TimeGenerated > ago(24h) | where EventMessage =~ 'Project version created' | project EventCreationTime, UserName, SrcIpAddr, ObjectItemName, ChangedValues, AssociatedItems | extend AccountCustomEntity = UserName entityMappings: - entityType: Account fieldMappings: - identifier: Name columnName: AccountCustomEntity