Back
Id231904f5-b670-4223-9bec-2e9aeca9cf5b
RulenameVectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
DescriptionThis query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra

(investigation_status = escalated). Escalation indicates that a human analyst or MDR service

has reviewed the detection and determined it requires immediate host attention or notification.

One incident is created per detection - grouping is based on alert display name so that

repeated rule evaluations against the same detection do not create duplicate incidents.



This query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections

marked as unresolved and prioritized (unresolved_priority = true). Vectra’s AI engine assigns

priority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces

host-based threats that require analyst attention.



Incidents are grouped per host entity and remain open while the threat persists. Once all associated

detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.
SeverityHigh
TacticsDiscovery
LateralMovement
CredentialAccess
Exfiltration
CommandAndControl
Persistence
TechniquesT1046
T1021
T1003
T1041
T1071
Required data connectorsVectraRUXConnector
KindScheduled
Query frequency10m
Query period10m
Trigger threshold0
Trigger operatorGreaterThan
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml
Version1.0.0
Arm template231904f5-b670-4223-9bec-2e9aeca9cf5b.json
Deploy To Azure
VectraDetectionsCombined
| where ["Entity Type"] == "host"
| summarize arg_max(TimeGenerated, *) by ["Detection ID"]
| where ["Investigation Status"] == "escalated" or ["Unresolved Priority"] == true
| extend
    detection_name     = ["D Type Vname"],
    detection_category = ["Detection Category"],
    entity_url         = replace_string(replace_string(URL, "api/v3.4/", ""), "api/v3.5/", ""),
    mitre_techniques   = tostring(Mitre),
    detection_tags     = tostring(Tags),
    assigned_to        = ["Assigned To"],
    entity_name = ["Entity Name"],
    entity_uid = ["Entity UID"],
    entity_id = ["Entity ID"],
    detection_id = ["Detection ID"],
    external_reference = ["External Reference ID"],
    investigation_status = ["Investigation Status"],
    entity_type = ["Entity Type"]
suppressionEnabled: false
alertDetailsOverride:
  alertDisplayNameFormat: Vectra AI - {{detection_name}} on {{entity_name}}
  alertDynamicProperties:
  - alertProperty: AlertLink
    value: entity_url
  - alertProperty: Techniques
    value: mitre_techniques
  alertDescriptionFormat: |
    Vectra AI has escalated detection {{detection_name}} ({{detection_category}}) on host or identified host {{entity_name}} as a priority threat. See custom details for full context.
kind: Scheduled
name: Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
suppressionDuration: PT1H
triggerThreshold: 0
eventGroupingSettings:
  aggregationKind: AlertPerResult
status: Available
version: 1.0.0
customDetails:
  entity_url: entity_url
  mitre_techniques: mitre_techniques
  detection_id: detection_id
  category: detection_category
  entity_type: entity_type
  assigned_to: assigned_to
  tags: detection_tags
  external_reference: external_reference
  entity_id: entity_id
  detection_name: detection_name
  investigation_status: investigation_status
  entity_uid: entity_uid
description: |
  This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra
  (investigation_status = escalated). Escalation indicates that a human analyst or MDR service
  has reviewed the detection and determined it requires immediate host attention or notification.
  One incident is created per detection - grouping is based on alert display name so that
  repeated rule evaluations against the same detection do not create duplicate incidents.

  This query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections
  marked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns
  priority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces
  host-based threats that require analyst attention.

  Incidents are grouped per host entity and remain open while the threat persists. Once all associated
  detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.
queryFrequency: 10m
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml
id: 231904f5-b670-4223-9bec-2e9aeca9cf5b
tactics:
- Discovery
- LateralMovement
- CredentialAccess
- Exfiltration
- CommandAndControl
- Persistence
requiredDataConnectors:
- dataTypes:
  - VectraDetectionsCombined
  connectorId: VectraRUXConnector
severity: High
incidentConfiguration:
  groupingConfiguration:
    matchingMethod: Selected
    groupByEntities:
    - Host
    lookbackDuration: P7D
    reopenClosedIncident: false
    groupByAlertDetails:
    - DisplayName
    enabled: true
  createIncident: true
triggerOperator: GreaterThan
entityMappings:
- entityType: Host
  fieldMappings:
  - columnName: entity_name
    identifier: HostName
relevantTechniques:
- T1046
- T1021
- T1003
- T1041
- T1071
queryPeriod: 10m
query: |
  VectraDetectionsCombined
  | where ["Entity Type"] == "host"
  | summarize arg_max(TimeGenerated, *) by ["Detection ID"]
  | where ["Investigation Status"] == "escalated" or ["Unresolved Priority"] == true
  | extend
      detection_name     = ["D Type Vname"],
      detection_category = ["Detection Category"],
      entity_url         = replace_string(replace_string(URL, "api/v3.4/", ""), "api/v3.5/", ""),
      mitre_techniques   = tostring(Mitre),
      detection_tags     = tostring(Tags),
      assigned_to        = ["Assigned To"],
      entity_name = ["Entity Name"],
      entity_uid = ["Entity UID"],
      entity_id = ["Entity ID"],
      detection_id = ["Detection ID"],
      external_reference = ["External Reference ID"],
      investigation_status = ["Investigation Status"],
      entity_type = ["Entity Type"]
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/231904f5-b670-4223-9bec-2e9aeca9cf5b')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/231904f5-b670-4223-9bec-2e9aeca9cf5b')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Vectra AI has escalated detection {{detection_name}} ({{detection_category}}) on host or identified host {{entity_name}} as a priority threat. See custom details for full context.\n",
          "alertDisplayNameFormat": "Vectra AI - {{detection_name}} on {{entity_name}}",
          "alertDynamicProperties": [
            {
              "alertProperty": "AlertLink",
              "value": "entity_url"
            },
            {
              "alertProperty": "Techniques",
              "value": "mitre_techniques"
            }
          ]
        },
        "alertRuleTemplateName": "231904f5-b670-4223-9bec-2e9aeca9cf5b",
        "customDetails": {
          "assigned_to": "assigned_to",
          "category": "detection_category",
          "detection_id": "detection_id",
          "detection_name": "detection_name",
          "entity_id": "entity_id",
          "entity_type": "entity_type",
          "entity_uid": "entity_uid",
          "entity_url": "entity_url",
          "external_reference": "external_reference",
          "investigation_status": "investigation_status",
          "mitre_techniques": "mitre_techniques",
          "tags": "detection_tags"
        },
        "description": "This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra\n(investigation_status = escalated). Escalation indicates that a human analyst or MDR service\nhas reviewed the detection and determined it requires immediate host attention or notification.\nOne incident is created per detection - grouping is based on alert display name so that\nrepeated rule evaluations against the same detection do not create duplicate incidents.\n\nThis query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections\nmarked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns\npriority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces\nhost-based threats that require analyst attention.\n\nIncidents are grouped per host entity and remain open while the threat persists. Once all associated\ndetections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.\n",
        "displayName": "Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "entity_name",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [
              "DisplayName"
            ],
            "groupByEntities": [
              "Host"
            ],
            "lookbackDuration": "P7D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml",
        "query": "VectraDetectionsCombined\n| where [\"Entity Type\"] == \"host\"\n| summarize arg_max(TimeGenerated, *) by [\"Detection ID\"]\n| where [\"Investigation Status\"] == \"escalated\" or [\"Unresolved Priority\"] == true\n| extend\n    detection_name     = [\"D Type Vname\"],\n    detection_category = [\"Detection Category\"],\n    entity_url         = replace_string(replace_string(URL, \"api/v3.4/\", \"\"), \"api/v3.5/\", \"\"),\n    mitre_techniques   = tostring(Mitre),\n    detection_tags     = tostring(Tags),\n    assigned_to        = [\"Assigned To\"],\n    entity_name = [\"Entity Name\"],\n    entity_uid = [\"Entity UID\"],\n    entity_id = [\"Entity ID\"],\n    detection_id = [\"Detection ID\"],\n    external_reference = [\"External Reference ID\"],\n    investigation_status = [\"Investigation Status\"],\n    entity_type = [\"Entity Type\"]\n",
        "queryFrequency": "PT10M",
        "queryPeriod": "PT10M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "CredentialAccess",
          "Discovery",
          "Exfiltration",
          "LateralMovement",
          "Persistence"
        ],
        "techniques": [
          "T1003",
          "T1021",
          "T1041",
          "T1046",
          "T1071"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}