TrendMicro_XDR_WORKBENCH_CL
| extend Severity = case(severity_s == "low", "Informational",
severity_s == "medium", "Low",
severity_s == "high", "Medium",
"High"
)
| extend
UserAccountName_s = todynamic(column_ifexists("UserAccountName_s", "[]")),
UserAccountNTDomain_s = todynamic(column_ifexists("UserAccountNTDomain_s", "[]")),
FileName_s = todynamic(column_ifexists("FileName_s", "[]")),
FileDirectory_s = todynamic(column_ifexists("FileDirectory_s", "[]")),
ProcessCommandLine_s = todynamic(column_ifexists("ProcessCommandLine_s", "[]")),
RegistryKey_s = todynamic(column_ifexists("RegistryKey_s", "[]")),
RegistryValue_s = todynamic(column_ifexists("RegistryValue_s", "[]")),
RegistryValueName_s = todynamic(column_ifexists("RegistryValueName_s", "[]"))
alertDetailsOverride:
alertSeverityColumnName: Severity
alertDescriptionFormat: '{{description_s}}'
alertDisplayNameFormat: '{{workbenchName_s}}'
relevantTechniques:
name: Create Incident for XDR Alerts
queryFrequency: 5m
version: 1.0.4
incidentConfiguration:
groupingConfiguration:
matchingMethod: Selected
enabled: true
groupByCustomDetails:
- WorkbenchID
lookbackDuration: 5m
reopenClosedIncident: false
createIncident: true
triggerThreshold: 0
severity: High
requiredDataConnectors:
- connectorId: TrendMicroXDR
dataTypes:
- TrendMicro_XDR_WORKBENCH_CL
tactics:
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Trend Micro Vision One/Analytic Rules/Create Incident for XDR Alerts.yaml
alertRuleTemplateName:
query: |
TrendMicro_XDR_WORKBENCH_CL
| extend Severity = case(severity_s == "low", "Informational",
severity_s == "medium", "Low",
severity_s == "high", "Medium",
"High"
)
| extend
UserAccountName_s = todynamic(column_ifexists("UserAccountName_s", "[]")),
UserAccountNTDomain_s = todynamic(column_ifexists("UserAccountNTDomain_s", "[]")),
FileName_s = todynamic(column_ifexists("FileName_s", "[]")),
FileDirectory_s = todynamic(column_ifexists("FileDirectory_s", "[]")),
ProcessCommandLine_s = todynamic(column_ifexists("ProcessCommandLine_s", "[]")),
RegistryKey_s = todynamic(column_ifexists("RegistryKey_s", "[]")),
RegistryValue_s = todynamic(column_ifexists("RegistryValue_s", "[]")),
RegistryValueName_s = todynamic(column_ifexists("RegistryValueName_s", "[]"))
kind: Scheduled
entityMappings:
- fieldMappings:
- columnName: UserAccountName_s
identifier: Name
- columnName: UserAccountNTDomain_s
identifier: NTDomain
entityType: Account
- fieldMappings:
- columnName: FileName_s
identifier: Name
- columnName: FileDirectory_s
identifier: Directory
entityType: File
- fieldMappings:
- columnName: ProcessCommandLine_s
identifier: CommandLine
entityType: Process
- fieldMappings:
- columnName: RegistryKey_s
identifier: Key
entityType: RegistryKey
- fieldMappings:
- columnName: ProcessCommandLine_s
identifier: Name
- columnName: RegistryValue_s
identifier: Value
entityType: RegistryValue
queryPeriod: 5m
triggerOperator: gt
customDetails:
WorkbenchID: workbenchId_s
WorkbenchName: workbenchName_s
WorkbenchLink: workbenchLink_s
Provider: alertProvider_s
Severity: severity_s
CreatedAt: createdTime_t
PriorityScore: priorityScore_d
XDRCustomerID: xdrCustomerID_g
ImpactScopeSummary: impactScope_Summary_s
suppressionEnabled: false
eventGroupingSettings:
aggregationKind: AlertPerResult
id: 0febd8cc-1b8d-45ed-87b3-e1e8a57d14cd
suppressionDuration: 5h
status: Available
description: |
'This Query creates an incident based on Trend Vision One Workbench Alerts and maps the impacted entities for Microsoft Sentinel usage.'