Back
Id04e36dfa-05b3-45bd-b39f-28b6fac71337
RulenameNetskope - High Severity DLP Alert
DescriptionDetects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.

These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a

DLP policy during upload, download, or sharing and may represent data exfiltration.
SeverityHigh
TacticsExfiltration
Collection
TechniquesT1567
T1005
Required data connectorsNetskopeAlertsEvents
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml
Version1.0.0
Arm template04e36dfa-05b3-45bd-b39f-28b6fac71337.json
Deploy To Azure
NetskopeAlerts_CL
| where TimeGenerated > ago(1h)
| where alert_type =~ "dlp"
| where severity has_any ("high", "critical")
| summarize
    AlertCount = count(),
    DlpRules = make_set(dlp_rule, 20),
    DlpProfiles = make_set(dlp_profile, 20),
    Apps = make_set(app, 20),
    FilePaths = make_set(file_path, 20),
    FirstSeen = min(TimeGenerated),
    LastSeen = max(TimeGenerated)
    by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity
| order by AlertCount desc
| project
    LastSeen,
    AlertName,
    Severity,
    User,
    UserIp,
    HostName,
    AlertCount,
    Apps,
    DlpRules,
    DlpProfiles,
    FilePaths,
    FirstSeen
name: Netskope - High Severity DLP Alert
triggerOperator: gt
query: |
  NetskopeAlerts_CL
  | where TimeGenerated > ago(1h)
  | where alert_type =~ "dlp"
  | where severity has_any ("high", "critical")
  | summarize
      AlertCount = count(),
      DlpRules = make_set(dlp_rule, 20),
      DlpProfiles = make_set(dlp_profile, 20),
      Apps = make_set(app, 20),
      FilePaths = make_set(file_path, 20),
      FirstSeen = min(TimeGenerated),
      LastSeen = max(TimeGenerated)
      by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity
  | order by AlertCount desc
  | project
      LastSeen,
      AlertName,
      Severity,
      User,
      UserIp,
      HostName,
      AlertCount,
      Apps,
      DlpRules,
      DlpProfiles,
      FilePaths,
      FirstSeen
queryFrequency: 1h
description: |
  Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.
  These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a
  DLP policy during upload, download, or sharing and may represent data exfiltration.
id: 04e36dfa-05b3-45bd-b39f-28b6fac71337
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: NetskopeAlertsEvents
  dataTypes:
  - NetskopeAlerts_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml
relevantTechniques:
- T1567
- T1005
tactics:
- Exfiltration
- Collection
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: User
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: UserIp
  entityType: IP
- fieldMappings:
  - identifier: HostName
    columnName: HostName
  entityType: Host
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
      "properties": {
        "alertRuleTemplateName": "04e36dfa-05b3-45bd-b39f-28b6fac71337",
        "customDetails": null,
        "description": "Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.\nThese alerts indicate sensitive data (e.g. PII, source code, financial records) matched a\nDLP policy during upload, download, or sharing and may represent data exfiltration.\n",
        "displayName": "Netskope - High Severity DLP Alert",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "User",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "UserIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml",
        "query": "NetskopeAlerts_CL\n| where TimeGenerated > ago(1h)\n| where alert_type =~ \"dlp\"\n| where severity has_any (\"high\", \"critical\")\n| summarize\n    AlertCount = count(),\n    DlpRules = make_set(dlp_rule, 20),\n    DlpProfiles = make_set(dlp_profile, 20),\n    Apps = make_set(app, 20),\n    FilePaths = make_set(file_path, 20),\n    FirstSeen = min(TimeGenerated),\n    LastSeen = max(TimeGenerated)\n    by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity\n| order by AlertCount desc\n| project\n    LastSeen,\n    AlertName,\n    Severity,\n    User,\n    UserIp,\n    HostName,\n    AlertCount,\n    Apps,\n    DlpRules,\n    DlpProfiles,\n    FilePaths,\n    FirstSeen\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Collection",
          "Exfiltration"
        ],
        "techniques": [
          "T1005",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}