Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Cyble Vision Alerts Vulnerability

Back
Id0e0cdda9-4536-4cc9-91cf-736e8957ed26
RulenameCyble Vision Alerts Vulnerability
DescriptionDetects SSL/TLS and application vulnerabilities from CybleVision. Extracts host, IP, port, severity, vulnerability ID and first-seen metadata using the Alerts_Vulnerability parser. Incidents grouped per service.
SeverityLow
TacticsReconnaissance
Execution
Discovery
TechniquesT1595
T1203
T1046
Required data connectorsCybleVisionAlerts
KindScheduled
Query frequency30m
Query period30m
Trigger threshold0
Trigger operatorGreaterThan
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyble Vision/Analytic Rules/Alerts_Vulnerability.yaml
Version1.0.0
Arm template0e0cdda9-4536-4cc9-91cf-736e8957ed26.json
Deploy To Azure
Alerts_vulnerability 
| where Service == "vulnerability" 
| extend MappedSeverity = Severity
relevantTechniques:
- T1595
- T1203
- T1046
entityMappings:
- entityType: Host
  fieldMappings:
  - columnName: V_Host
    identifier: HostName
- entityType: IP
  fieldMappings:
  - columnName: V_IP
    identifier: Address
eventGroupingSettings:
  aggregationKind: AlertPerResult
version: 1.0.0
query: |
  Alerts_vulnerability 
  | where Service == "vulnerability" 
  | extend MappedSeverity = Severity  
id: 0e0cdda9-4536-4cc9-91cf-736e8957ed26
suppressionDuration: PT5H
severity: Low
kind: Scheduled
queryFrequency: 30m
description: |
    'Detects SSL/TLS and application vulnerabilities from CybleVision. Extracts host, IP, port, severity, vulnerability ID and first-seen metadata using the Alerts_Vulnerability parser. Incidents grouped per service.'
requiredDataConnectors:
- connectorId: CybleVisionAlerts
  dataTypes:
  - CybleVisionAlerts_CL
subTechniques: []
triggerOperator: GreaterThan
name: Cyble Vision Alerts Vulnerability
tactics:
- Reconnaissance
- Execution
- Discovery
alertDetailsOverride:
  alertDescriptionFormat: |
        A vulnerability was detected for host {{V_Host}} (IP {{V_IP}}, Port {{V_Port}}).
  alertDynamicProperties: []
  alertDisplayNameFormat: CybleVision Vulnerability {{V_Title}}
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyble Vision/Analytic Rules/Alerts_Vulnerability.yaml
triggerThreshold: 0
queryPeriod: 30m
enabled: true
status: Available
customDetails:
  V_Confidence: V_Confidence
  V_FirstSeen: V_FirstSeen
  V_Type: V_Type
  V_LastSeen: V_LastSeen
  V_Port: V_Port
  Status: Status
  Service: Service
  MappedSeverity: Severity
  Title: V_Title
  AlertID: AlertID
  V_VulnID: V_VulnID
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    lookbackDuration: PT5H
    enabled: false
    reopenClosedIncident: false
    matchingMethod: AllEntities