Sonrai Ticket Escalation Executed
| Id | 0d29c93e-b83f-4dfb-bbbb-76824b77eeca |
| Rulename | Sonrai Ticket Escalation Executed |
| Description | Checks if Sonrai tickets have had a comment added. It uses the action type to check if a ticket has had a comment added |
| Severity | Medium |
| Tactics | Collection CommandAndControl CredentialAccess DefenseEvasion Discovery Execution Exfiltration Impact InitialAccess LateralMovement Persistence PrivilegeEscalation |
| Techniques | T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499 |
| Required data connectors | SonraiDataConnector |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SonraiSecurity/Analytic Rules/SonraiTicketCommentAdded.yaml |
| Version | 1.0.2 |
| Arm template | 0d29c93e-b83f-4dfb-bbbb-76824b77eeca.json |
Sonrai_Tickets_CL
| where action_d == 9
id: 0d29c93e-b83f-4dfb-bbbb-76824b77eeca
requiredDataConnectors:
- connectorId: SonraiDataConnector
dataTypes:
- Sonrai_Tickets_CL
entityMappings:
- fieldMappings:
- identifier: Name
columnName: digest_criticalResourceName_s
entityType: CloudApplication
query: |
Sonrai_Tickets_CL
| where action_d == 9
triggerThreshold: 0
kind: Scheduled
severity: Medium
queryPeriod: 5m
customDetails:
ticketSeverity: digest_severityCategory_s
resourceLabel: digest_resourceLabel_s
ticketOrg: digest_org_s
ticketName: digest_title_s
ticketStatus: digest_status_s
criticalResource: digest_criticalResourceName_s
resourceType: digest_resourceType_s
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Execution
- Exfiltration
- Impact
- InitialAccess
- LateralMovement
- Persistence
- PrivilegeEscalation
queryFrequency: 5m
status: Available
relevantTechniques:
- T1566
- T1059
- T1547
- T1548
- T1562
- T1003
- T1087
- T1021
- T1119
- T1071
- T1041
- T1499
triggerOperator: gt
alertDetailsOverride:
alertDisplayNameFormat: Comment Added - {{digest_ticketSrn_s}} - {{digest_ticketKeyName_s}}
alertSeverityColumnName: digest_severityCategory_s
alertDescriptionFormat: digest_ticketKeyDescription_s
eventGroupingSettings:
aggregationKind: AlertPerResult
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SonraiSecurity/Analytic Rules/SonraiTicketCommentAdded.yaml
description: |
'Checks if Sonrai tickets have had a comment added.
It uses the action type to check if a ticket has had a comment added'
name: Sonrai Ticket Escalation Executed
version: 1.0.2