Sentinel-As-Code Toolkit 26.10.2

Toolkit 26.10.2 reports connector and MITRE problems in the Problems panel, keeps NRT rules as NRT when you decompile ARM templates, and validates or formats a whole folder of rules in one run. Upgrade to see connector problems in your existing rules.

Before you upgrade

  • Fix Field Order moves to Shift+Alt+O, leaving Ctrl+Shift+F (Cmd+Shift+F on macOS) to Find in Files.
  • The Problems panel shows more. Unknown tactics and techniques, and field-order hints, appear as information items. Turn the hints off with sentinelAsCode.fieldOrdering.showOrderHints.
  • sentinelAsCode.mitre.version is removed. The extension ships ATT&CK v16.
  • VS Code 1.134 or later is required.

Connector and MITRE problems in the Problems panel

Rule validation reports unknown connectors in strict and workspace mode, deprecated connectors, and any table a connector does not provide, each on its own line. Unknown tactics and techniques appear as information items, or as errors with sentinelAsCode.mitre.strictValidation on. Field-order hints cover top-level keys.

The validation, formatting and IntelliSense settings control all of this, including validation.onType, formatting.enabled and intellisense.enabled, and changing one re-validates your open files. The Configuration docs describe each one.

NRT rules and techniques in ARM decompilation

Decompile ARM to YAML writes near-real-time rules as kind: NRT, without scheduling or trigger fields, to match the NRT template. Techniques go under relevantTechniques, with sub-techniques such as T1078.004 folded in from the ARM subTechniques property. See armToYamlConverter.ts.

Bulk Maintenance & Validation

Bulk Maintenance & Validation validates, formats, or writes a Markdown report for every analytics rule in a folder, skipping templates and excluded files. Run it from the Command Palette, or right-click a folder in the Explorer. See bulkValidationCommand.ts.

Workspace connector text is untrusted

Connector hover text can come from a repository's .sentinel-connectors.json, so the hover renders it as untrusted markdown: links in it cannot run VS Code commands. This release also clears the open dependency advisories, including two high-severity ones in js-yaml, and connector data refreshes go through a reviewed pull request.

Also in this release

Format Content explains when YAML content is not reformatted and leaves unrelated JSON alone. Validate Rule passes clean rules. Populate Required Data Connectors suggests each table's native connector first. Content conversion asks before overwriting a file, and Fix Field Order works in .sentinel.yml files. The changelog has the full list.

Thanks

Thanks to @gatko711 for issue #51, which pointed out that Decompile ARM to YAML should write relevantTechniques, as the documented schema does.

Upgrade

Update from the VS Code Marketplace, or download the VSIX from the v26.10 release. Report problems on the issue tracker.