Solutions/AtlassianJiraAudit/Hunting Queries/JiraUpdatedProjects.yaml (24 lines of code) (raw):

id: eb409b8b-0267-4e95-b3a9-ee1a72c32409 name: Jira - Updated projects description: | 'Query searches for updated projects.' severity: Medium requiredDataConnectors: - connectorId: JiraAuditAPI dataTypes: - JiraAudit tactics: - Impact relevantTechniques: - T1565 query: | JiraAudit | where TimeGenerated > ago(24h) | where EventMessage =~ 'Project updated' | project EventCreationTime, UserName, SrcIpAddr, ObjectItemName, ChangedValues, AssociatedItems | extend AccountCustomEntity = UserName entityMappings: - entityType: Account fieldMappings: - identifier: Name columnName: AccountCustomEntity