Analytic rule catalog
Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
Back
| Id | 231904f5-b670-4223-9bec-2e9aeca9cf5b |
| Rulename | Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host |
| Description | This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate host attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections marked as unresolved and prioritized (unresolved_priority = true). Vectra’s AI engine assigns priority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces host-based threats that require analyst attention. Incidents are grouped per host entity and remain open while the threat persists. Once all associated detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel. |
| Severity | High |
| Tactics | Discovery LateralMovement CredentialAccess Exfiltration CommandAndControl Persistence |
| Techniques | T1046 T1021 T1003 T1041 T1071 |
| Required data connectors | VectraRUXConnector |
| Kind | Scheduled |
| Query frequency | 10m |
| Query period | 10m |
| Trigger threshold | 0 |
| Trigger operator | GreaterThan |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml |
| Version | 1.0.0 |
| Arm template | 231904f5-b670-4223-9bec-2e9aeca9cf5b.json |
VectraDetectionsCombined
| where ["Entity Type"] == "host"
| summarize arg_max(TimeGenerated, *) by ["Detection ID"]
| where ["Investigation Status"] == "escalated" or ["Unresolved Priority"] == true
| extend
detection_name = ["D Type Vname"],
detection_category = ["Detection Category"],
entity_url = replace_string(replace_string(URL, "api/v3.4/", ""), "api/v3.5/", ""),
mitre_techniques = tostring(Mitre),
detection_tags = tostring(Tags),
assigned_to = ["Assigned To"],
entity_name = ["Entity Name"],
entity_uid = ["Entity UID"],
entity_id = ["Entity ID"],
detection_id = ["Detection ID"],
external_reference = ["External Reference ID"],
investigation_status = ["Investigation Status"],
entity_type = ["Entity Type"]
suppressionEnabled: false
alertDetailsOverride:
alertDisplayNameFormat: Vectra AI - {{detection_name}} on {{entity_name}}
alertDynamicProperties:
- alertProperty: AlertLink
value: entity_url
- alertProperty: Techniques
value: mitre_techniques
alertDescriptionFormat: |
Vectra AI has escalated detection {{detection_name}} ({{detection_category}}) on host or identified host {{entity_name}} as a priority threat. See custom details for full context.
kind: Scheduled
name: Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
suppressionDuration: PT1H
triggerThreshold: 0
eventGroupingSettings:
aggregationKind: AlertPerResult
status: Available
version: 1.0.0
customDetails:
entity_url: entity_url
mitre_techniques: mitre_techniques
detection_id: detection_id
category: detection_category
entity_type: entity_type
assigned_to: assigned_to
tags: detection_tags
external_reference: external_reference
entity_id: entity_id
detection_name: detection_name
investigation_status: investigation_status
entity_uid: entity_uid
description: |
This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra
(investigation_status = escalated). Escalation indicates that a human analyst or MDR service
has reviewed the detection and determined it requires immediate host attention or notification.
One incident is created per detection - grouping is based on alert display name so that
repeated rule evaluations against the same detection do not create duplicate incidents.
This query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections
marked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns
priority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces
host-based threats that require analyst attention.
Incidents are grouped per host entity and remain open while the threat persists. Once all associated
detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.
queryFrequency: 10m
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml
id: 231904f5-b670-4223-9bec-2e9aeca9cf5b
tactics:
- Discovery
- LateralMovement
- CredentialAccess
- Exfiltration
- CommandAndControl
- Persistence
requiredDataConnectors:
- dataTypes:
- VectraDetectionsCombined
connectorId: VectraRUXConnector
severity: High
incidentConfiguration:
groupingConfiguration:
matchingMethod: Selected
groupByEntities:
- Host
lookbackDuration: P7D
reopenClosedIncident: false
groupByAlertDetails:
- DisplayName
enabled: true
createIncident: true
triggerOperator: GreaterThan
entityMappings:
- entityType: Host
fieldMappings:
- columnName: entity_name
identifier: HostName
relevantTechniques:
- T1046
- T1021
- T1003
- T1041
- T1071
queryPeriod: 10m
query: |
VectraDetectionsCombined
| where ["Entity Type"] == "host"
| summarize arg_max(TimeGenerated, *) by ["Detection ID"]
| where ["Investigation Status"] == "escalated" or ["Unresolved Priority"] == true
| extend
detection_name = ["D Type Vname"],
detection_category = ["Detection Category"],
entity_url = replace_string(replace_string(URL, "api/v3.4/", ""), "api/v3.5/", ""),
mitre_techniques = tostring(Mitre),
detection_tags = tostring(Tags),
assigned_to = ["Assigned To"],
entity_name = ["Entity Name"],
entity_uid = ["Entity UID"],
entity_id = ["Entity ID"],
detection_id = ["Detection ID"],
external_reference = ["External Reference ID"],
investigation_status = ["Investigation Status"],
entity_type = ["Entity Type"]
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/231904f5-b670-4223-9bec-2e9aeca9cf5b')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/231904f5-b670-4223-9bec-2e9aeca9cf5b')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "Vectra AI has escalated detection {{detection_name}} ({{detection_category}}) on host or identified host {{entity_name}} as a priority threat. See custom details for full context.\n",
"alertDisplayNameFormat": "Vectra AI - {{detection_name}} on {{entity_name}}",
"alertDynamicProperties": [
{
"alertProperty": "AlertLink",
"value": "entity_url"
},
{
"alertProperty": "Techniques",
"value": "mitre_techniques"
}
]
},
"alertRuleTemplateName": "231904f5-b670-4223-9bec-2e9aeca9cf5b",
"customDetails": {
"assigned_to": "assigned_to",
"category": "detection_category",
"detection_id": "detection_id",
"detection_name": "detection_name",
"entity_id": "entity_id",
"entity_type": "entity_type",
"entity_uid": "entity_uid",
"entity_url": "entity_url",
"external_reference": "external_reference",
"investigation_status": "investigation_status",
"mitre_techniques": "mitre_techniques",
"tags": "detection_tags"
},
"description": "This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra\n(investigation_status = escalated). Escalation indicates that a human analyst or MDR service\nhas reviewed the detection and determined it requires immediate host attention or notification.\nOne incident is created per detection - grouping is based on alert display name so that\nrepeated rule evaluations against the same detection do not create duplicate incidents.\n\nThis query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections\nmarked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns\npriority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces\nhost-based threats that require analyst attention.\n\nIncidents are grouped per host entity and remain open while the threat persists. Once all associated\ndetections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.\n",
"displayName": "Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host",
"enabled": true,
"entityMappings": [
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "entity_name",
"identifier": "HostName"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [
"DisplayName"
],
"groupByEntities": [
"Host"
],
"lookbackDuration": "P7D",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra%20XDR/Analytic%20Rules/Vectra_RUX_Incident_Detection_Host.yaml",
"query": "VectraDetectionsCombined\n| where [\"Entity Type\"] == \"host\"\n| summarize arg_max(TimeGenerated, *) by [\"Detection ID\"]\n| where [\"Investigation Status\"] == \"escalated\" or [\"Unresolved Priority\"] == true\n| extend\n detection_name = [\"D Type Vname\"],\n detection_category = [\"Detection Category\"],\n entity_url = replace_string(replace_string(URL, \"api/v3.4/\", \"\"), \"api/v3.5/\", \"\"),\n mitre_techniques = tostring(Mitre),\n detection_tags = tostring(Tags),\n assigned_to = [\"Assigned To\"],\n entity_name = [\"Entity Name\"],\n entity_uid = [\"Entity UID\"],\n entity_id = [\"Entity ID\"],\n detection_id = [\"Detection ID\"],\n external_reference = [\"External Reference ID\"],\n investigation_status = [\"Investigation Status\"],\n entity_type = [\"Entity Type\"]\n",
"queryFrequency": "PT10M",
"queryPeriod": "PT10M",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"CredentialAccess",
"Discovery",
"Exfiltration",
"LateralMovement",
"Persistence"
],
"techniques": [
"T1003",
"T1021",
"T1041",
"T1046",
"T1071"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}