Analytic rule catalog
Netskope - High Severity DLP Alert
Back
| Id | 04e36dfa-05b3-45bd-b39f-28b6fac71337 |
| Rulename | Netskope - High Severity DLP Alert |
| Description | Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity. These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a DLP policy during upload, download, or sharing and may represent data exfiltration. |
| Severity | High |
| Tactics | Exfiltration Collection |
| Techniques | T1567 T1005 |
| Required data connectors | NetskopeAlertsEvents |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml |
| Version | 1.0.0 |
| Arm template | 04e36dfa-05b3-45bd-b39f-28b6fac71337.json |
NetskopeAlerts_CL
| where TimeGenerated > ago(1h)
| where alert_type =~ "dlp"
| where severity has_any ("high", "critical")
| summarize
AlertCount = count(),
DlpRules = make_set(dlp_rule, 20),
DlpProfiles = make_set(dlp_profile, 20),
Apps = make_set(app, 20),
FilePaths = make_set(file_path, 20),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity
| order by AlertCount desc
| project
LastSeen,
AlertName,
Severity,
User,
UserIp,
HostName,
AlertCount,
Apps,
DlpRules,
DlpProfiles,
FilePaths,
FirstSeen
name: Netskope - High Severity DLP Alert
triggerOperator: gt
query: |
NetskopeAlerts_CL
| where TimeGenerated > ago(1h)
| where alert_type =~ "dlp"
| where severity has_any ("high", "critical")
| summarize
AlertCount = count(),
DlpRules = make_set(dlp_rule, 20),
DlpProfiles = make_set(dlp_profile, 20),
Apps = make_set(app, 20),
FilePaths = make_set(file_path, 20),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity
| order by AlertCount desc
| project
LastSeen,
AlertName,
Severity,
User,
UserIp,
HostName,
AlertCount,
Apps,
DlpRules,
DlpProfiles,
FilePaths,
FirstSeen
queryFrequency: 1h
description: |
Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.
These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a
DLP policy during upload, download, or sharing and may represent data exfiltration.
id: 04e36dfa-05b3-45bd-b39f-28b6fac71337
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: NetskopeAlertsEvents
dataTypes:
- NetskopeAlerts_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml
relevantTechniques:
- T1567
- T1005
tactics:
- Exfiltration
- Collection
entityMappings:
- fieldMappings:
- identifier: Name
columnName: User
entityType: Account
- fieldMappings:
- identifier: Address
columnName: UserIp
entityType: IP
- fieldMappings:
- identifier: HostName
columnName: HostName
entityType: Host
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
"properties": {
"alertRuleTemplateName": "04e36dfa-05b3-45bd-b39f-28b6fac71337",
"customDetails": null,
"description": "Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.\nThese alerts indicate sensitive data (e.g. PII, source code, financial records) matched a\nDLP policy during upload, download, or sharing and may represent data exfiltration.\n",
"displayName": "Netskope - High Severity DLP Alert",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "User",
"identifier": "Name"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "UserIp",
"identifier": "Address"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "HostName",
"identifier": "HostName"
}
]
}
],
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml",
"query": "NetskopeAlerts_CL\n| where TimeGenerated > ago(1h)\n| where alert_type =~ \"dlp\"\n| where severity has_any (\"high\", \"critical\")\n| summarize\n AlertCount = count(),\n DlpRules = make_set(dlp_rule, 20),\n DlpProfiles = make_set(dlp_profile, 20),\n Apps = make_set(app, 20),\n FilePaths = make_set(file_path, 20),\n FirstSeen = min(TimeGenerated),\n LastSeen = max(TimeGenerated)\n by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity\n| order by AlertCount desc\n| project\n LastSeen,\n AlertName,\n Severity,\n User,\n UserIp,\n HostName,\n AlertCount,\n Apps,\n DlpRules,\n DlpProfiles,\n FilePaths,\n FirstSeen\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Collection",
"Exfiltration"
],
"techniques": [
"T1005",
"T1567"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}