Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

RecordedFuture Threat Hunting IP All Actors

Back
Ide31bc14e-2b4c-42a4-af34-5bfd7d768aea
RulenameRecordedFuture Threat Hunting IP All Actors
DescriptionRecorded Future Threat Hunting IP correlation for all actors.
SeverityMedium
TacticsExfiltration
CommandAndControl
TechniquesT1041
T1568
Required data connectorsThreatIntelligenceUploadIndicatorsAPI
KindScheduled
Query frequency15m
Query period1d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded Future/Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingIPAllActors.yaml
Version1.1.0
Arm templatee31bc14e-2b4c-42a4-af34-5bfd7d768aea.json
Deploy To Azure
let ioc_lookBack = 1d;
// The source table (_Im_NetworkSession) is a ASIM parser table, but can be replaced by any infrastructure table containing ip data.
// The following workbook: Recorded Future - IP Correlation will help researching available data and selecting tables and columns
_Im_NetworkSession
| where isnotempty(DstIpAddr)
| join kind=inner (
ThreatIntelIndicators
// Only look for IOCs
| where ObservableKey == 'ipv4-addr:value'
| where isnotempty(ObservableValue)
// Only look at Recorded Future Threat Hunt Indicators.
| where Data.description startswith "Recorded Future - Threat Hunt"
// Only work with the latest indicators
| where TimeGenerated >= ago(ioc_lookBack)
| summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
| where IsActive == true and ValidUntil > now()
) on $left.DstIpAddr == $right.ObservableValue
// select column from the source table to match with Recorded Future ThreatIntelIndicators $left.DstIpAddr
| mv-expand RecordedFuturePortalLink=parse_json(tostring(parse_json(Tags)))['recordedfutureportallink']
| project NetworkIP=ObservableValue, Description=Data.description, Type, TimeGenerated, RecordedFuturePortalLink
id: e31bc14e-2b4c-42a4-af34-5bfd7d768aea
requiredDataConnectors:
- dataTypes:
  - ThreatIntelIndicators
  connectorId: ThreatIntelligenceUploadIndicatorsAPI
triggerOperator: gt
description: |
    'Recorded Future Threat Hunting IP correlation for all actors.'
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    enabled: true
    lookbackDuration: 1h
    reopenClosedIncident: false
    matchingMethod: AllEntities
entityMappings:
- fieldMappings:
  - columnName: NetworkIP
    identifier: Address
  entityType: IP
kind: Scheduled
relevantTechniques:
- T1041
- T1568
queryPeriod: 1d
severity: Medium
query: |
  let ioc_lookBack = 1d;
  // The source table (_Im_NetworkSession) is a ASIM parser table, but can be replaced by any infrastructure table containing ip data.
  // The following workbook: Recorded Future - IP Correlation will help researching available data and selecting tables and columns
  _Im_NetworkSession
  | where isnotempty(DstIpAddr)
  | join kind=inner (
  ThreatIntelIndicators
  // Only look for IOCs
  | where ObservableKey == 'ipv4-addr:value'
  | where isnotempty(ObservableValue)
  // Only look at Recorded Future Threat Hunt Indicators.
  | where Data.description startswith "Recorded Future - Threat Hunt"
  // Only work with the latest indicators
  | where TimeGenerated >= ago(ioc_lookBack)
  | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
  | where IsActive == true and ValidUntil > now()
  ) on $left.DstIpAddr == $right.ObservableValue
  // select column from the source table to match with Recorded Future ThreatIntelIndicators $left.DstIpAddr
  | mv-expand RecordedFuturePortalLink=parse_json(tostring(parse_json(Tags)))['recordedfutureportallink']
  | project NetworkIP=ObservableValue, Description=Data.description, Type, TimeGenerated, RecordedFuturePortalLink  
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded Future/Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingIPAllActors.yaml
alertDetailsOverride:
  alertDynamicProperties:
  - alertProperty: AlertLink
    value: RecordedFuturePortalLink
  alertDisplayNameFormat: '{{Description}}'
  alertDescriptionFormat: '**{{Description}}**\n\nCorrelation found on {{NetworkIP}} from the {{Type}} table.\n'
triggerThreshold: 0
name: RecordedFuture Threat Hunting IP All Actors
tactics:
- Exfiltration
- CommandAndControl
queryFrequency: 15m
eventGroupingSettings:
  aggregationKind: AlertPerResult
customDetails:
  ActorInformation: RecordedFuturePortalLink
version: 1.1.0