Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Cyble Vision Alerts Github

Back
Id117e8f7c-8f44-4061-bcc2-b444b98a3838
RulenameCyble Vision Alerts Github
DescriptionThis alert generates incidents for Github
SeverityLow
TacticsCollection
CredentialAccess
TechniquesT1213
T1530
T1552
Required data connectorsCybleVisionAlerts
KindScheduled
Query frequency30m
Query period30m
Trigger threshold0
Trigger operatorGreaterThan
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyble Vision/Analytic Rules/Alerts_github.yaml
Version1.0.1
Arm template117e8f7c-8f44-4061-bcc2-b444b98a3838.json
Deploy To Azure
Alerts_github
| where Service contains "github"
| extend MappedSeverity = Severity
customDetails:
  GitURl: git_url
  Owner: owner_login
  OriginalSeverity: Severity
  Service: Service
  URL: html_url
  Status: Status
  Repository: repo_full_name
  AlertID: AlertID
  FileName: file_name
  MappedSeverity: Severity
  SHA: sha
  Score: score
kind: Scheduled
severity: Low
requiredDataConnectors:
- connectorId: CybleVisionAlerts
  dataTypes:
  - CybleVisionAlerts_CL
description: |
    'This alert generates incidents for Github'
triggerOperator: GreaterThan
alertDetailsOverride:
  alertDynamicProperties: []
  alertDisplayNameFormat: Cyble Vision Alert for Github
  alertDescriptionFormat: This Rule generate incidents for Serviec Github
status: Available
enabled: true
query: |
  Alerts_github
  | where Service contains "github"
  | extend MappedSeverity = Severity  
triggerThreshold: 0
relevantTechniques:
- T1213
- T1530
- T1552
version: 1.0.1
queryFrequency: 30m
subTechniques: []
suppressionDuration: PT5H
queryPeriod: 30m
tactics:
- Collection
- CredentialAccess
name: Cyble Vision Alerts Github
id: 117e8f7c-8f44-4061-bcc2-b444b98a3838
eventGroupingSettings:
  aggregationKind: AlertPerResult
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: owner_login
  entityType: Account
- fieldMappings:
  - identifier: Url
    columnName: html_url
  entityType: URL
- fieldMappings:
  - identifier: Name
    columnName: file_name
  - identifier: Directory
    columnName: file_path
  entityType: File
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyble Vision/Analytic Rules/Alerts_github.yaml
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    matchingMethod: AllEntities
    enabled: false
    reopenClosedIncident: false
    lookbackDuration: PT5H