Hunt Args
data class HuntArgs(val attackTactics: Output<List<Either<String, AttackTactic>>>? = null, val attackTechniques: Output<List<String>>? = null, val description: Output<String>? = null, val displayName: Output<String>? = null, val huntId: Output<String>? = null, val hypothesisStatus: Output<Either<String, HypothesisStatus>>? = null, val labels: Output<List<String>>? = null, val owner: Output<HuntOwnerArgs>? = null, val resourceGroupName: Output<String>? = null, val status: Output<Either<String, Status>>? = null, val workspaceName: Output<String>? = null) : ConvertibleToJava<HuntArgs>
Represents a Hunt in Azure Security Insights. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.
Example Usage
Creates or updates a hunt.
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var hunt = new AzureNative.SecurityInsights.Hunt("hunt", new()
{
AttackTactics = new[]
{
AzureNative.SecurityInsights.AttackTactic.Reconnaissance,
},
AttackTechniques = new[]
{
"T1595",
},
Description = "Log4J Hunt Description",
DisplayName = "Log4J new hunt",
HuntId = "163e7b2a-a2ec-4041-aaba-d878a38f265f",
HypothesisStatus = AzureNative.SecurityInsights.HypothesisStatus.Unknown,
Labels = new[]
{
"Label1",
"Label2",
},
Owner = new AzureNative.SecurityInsights.Inputs.HuntOwnerArgs
{
ObjectId = "873b5263-5d34-4149-b356-ad341b01e123",
},
ResourceGroupName = "myRg",
Status = AzureNative.SecurityInsights.Status.New,
WorkspaceName = "myWorkspace",
});
});
Content copied to clipboard
package main
import (
securityinsights "github.com/pulumi/pulumi-azure-native-sdk/securityinsights/v2"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := securityinsights.NewHunt(ctx, "hunt", &securityinsights.HuntArgs{
AttackTactics: pulumi.StringArray{
pulumi.String(securityinsights.AttackTacticReconnaissance),
},
AttackTechniques: pulumi.StringArray{
pulumi.String("T1595"),
},
Description: pulumi.String("Log4J Hunt Description"),
DisplayName: pulumi.String("Log4J new hunt"),
HuntId: pulumi.String("163e7b2a-a2ec-4041-aaba-d878a38f265f"),
HypothesisStatus: pulumi.String(securityinsights.HypothesisStatusUnknown),
Labels: pulumi.StringArray{
pulumi.String("Label1"),
pulumi.String("Label2"),
},
Owner: &securityinsights.HuntOwnerArgs{
ObjectId: pulumi.String("873b5263-5d34-4149-b356-ad341b01e123"),
},
ResourceGroupName: pulumi.String("myRg"),
Status: pulumi.String(securityinsights.StatusNew),
WorkspaceName: pulumi.String("myWorkspace"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.securityinsights.Hunt;
import com.pulumi.azurenative.securityinsights.HuntArgs;
import com.pulumi.azurenative.securityinsights.inputs.HuntOwnerArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var hunt = new Hunt("hunt", HuntArgs.builder()
.attackTactics("Reconnaissance")
.attackTechniques("T1595")
.description("Log4J Hunt Description")
.displayName("Log4J new hunt")
.huntId("163e7b2a-a2ec-4041-aaba-d878a38f265f")
.hypothesisStatus("Unknown")
.labels(
"Label1",
"Label2")
.owner(HuntOwnerArgs.builder()
.objectId("873b5263-5d34-4149-b356-ad341b01e123")
.build())
.resourceGroupName("myRg")
.status("New")
.workspaceName("myWorkspace")
.build());
}
}
Content copied to clipboard
Import
An existing resource can be imported using its type token, name, and identifier, e.g.
$ pulumi import azure-native:securityinsights:Hunt 163e7b2a-a2ec-4041-aaba-d878a38f265f /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/hunts/{huntId}
Content copied to clipboard
Constructors
Link copied to clipboard
constructor(attackTactics: Output<List<Either<String, AttackTactic>>>? = null, attackTechniques: Output<List<String>>? = null, description: Output<String>? = null, displayName: Output<String>? = null, huntId: Output<String>? = null, hypothesisStatus: Output<Either<String, HypothesisStatus>>? = null, labels: Output<List<String>>? = null, owner: Output<HuntOwnerArgs>? = null, resourceGroupName: Output<String>? = null, status: Output<Either<String, Status>>? = null, workspaceName: Output<String>? = null)
Properties
Link copied to clipboard
A list of mitre attack tactics the hunt is associated with
Link copied to clipboard
A list of a mitre attack techniques the hunt is associated with
Link copied to clipboard
The description of the hunt
Link copied to clipboard
The display name of the hunt
Link copied to clipboard
The hypothesis status of the hunt.
Link copied to clipboard
Describes a user that the hunt is assigned to
Link copied to clipboard
The name of the resource group. The name is case insensitive.
Link copied to clipboard
The name of the workspace.