Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Cisco SE - Malware outbreak

Back
Id225053c7-085b-4fca-a18f-c367f9228bf3
RulenameCisco SE - Malware outbreak
DescriptionDetects possible malware outbreak.
SeverityHigh
TacticsInitialAccess
TechniquesT1190
T1133
Required data connectorsCiscoSecureEndpoint
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco Secure Endpoint/Analytic Rules/CiscoSEMalwareOutbreak.yaml
Version1.0.0
Arm template225053c7-085b-4fca-a18f-c367f9228bf3.json
Deploy To Azure
let threshold = 2;
CiscoSecureEndpoint
| where isnotempty(ThreatName)
| summarize infected = makeset(DstHostname) by ThreatName, bin(TimeGenerated, 10m)
| where array_length(infected) >= threshold
| extend MalwareCustomEntity = ThreatName
requiredDataConnectors:
- connectorId: CiscoSecureEndpoint
  dataTypes:
  - CiscoSecureEndpoint
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco Secure Endpoint/Analytic Rules/CiscoSEMalwareOutbreak.yaml
triggerThreshold: 0
status: Available
relevantTechniques:
- T1190
- T1133
queryPeriod: 1h
name: Cisco SE - Malware outbreak
entityMappings:
- entityType: Malware
  fieldMappings:
  - columnName: MalwareCustomEntity
    identifier: Name
queryFrequency: 1h
triggerOperator: gt
kind: Scheduled
description: |
    'Detects possible malware outbreak.'
tactics:
- InitialAccess
severity: High
version: 1.0.0
query: |
  let threshold = 2;
  CiscoSecureEndpoint
  | where isnotempty(ThreatName)
  | summarize infected = makeset(DstHostname) by ThreatName, bin(TimeGenerated, 10m)
  | where array_length(infected) >= threshold
  | extend MalwareCustomEntity = ThreatName  
id: 225053c7-085b-4fca-a18f-c367f9228bf3