Theom - Overprovisioned Roles Shadow DB
| Id | fb7769d0-e622-4479-95b4-f6266a5b41e2 |
| Rulename | Theom - Overprovisioned Roles Shadow DB |
| Description | “Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0034 (Theom has observed shadow (or clone) databases/tables. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)” |
| Severity | High |
| Tactics | Collection PrivilegeEscalation |
| Techniques | T1560 T1530 T1078 |
| Required data connectors | Theom |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0034_Overprovisioned_Roles_Shadow_DB.yaml |
| Version | 1.0.2 |
| Arm template | fb7769d0-e622-4479-95b4-f6266a5b41e2.json |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
relevantTechniques:
- T1560
- T1530
- T1078
queryFrequency: 5m
description: |
"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0034 (Theom has observed shadow (or clone) databases/tables. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)"
severity: High
entityMappings:
- fieldMappings:
- identifier: Name
columnName: customProps_AssetName_s
entityType: CloudApplication
- fieldMappings:
- identifier: Url
columnName: deepLink_s
entityType: URL
triggerThreshold: 0
tactics:
- Collection
- PrivilegeEscalation
requiredDataConnectors:
- dataTypes:
- TheomAlerts_CL
connectorId: Theom
eventGroupingSettings:
aggregationKind: AlertPerResult
queryPeriod: 5m
id: fb7769d0-e622-4479-95b4-f6266a5b41e2
triggerOperator: gt
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0034_Overprovisioned_Roles_Shadow_DB.yaml
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
alertDetailsOverride:
alertDisplayNameFormat: 'Theom Alert ID: {{id_s}} '
alertDescriptionFormat: |2
Summary: {{summary_s}}
Additional info: {{details_s}}
Please investigate further on Theom UI at {{deepLink_s}}
name: Theom - Overprovisioned Roles Shadow DB
version: 1.0.2
kind: Scheduled
status: Available