Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

OCI - Multiple instances terminated

Back
Id252e651d-d825-480c-bdeb-8b239354577d
RulenameOCI - Multiple instances terminated
DescriptionDetects when multiple instances were terminated.
SeverityHigh
TacticsImpact
TechniquesT1529
Required data connectorsOracleCloudInfrastructureLogsConnector
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Oracle Cloud Infrastructure/Analytic Rules/OCIMultipleInstancesTerminated.yaml
Version1.0.1
Arm template252e651d-d825-480c-bdeb-8b239354577d.json
Deploy To Azure
let threshold = 5;
OCILogs
| where data_eventName_s =~ 'TerminateInstance'
| summarize count() by SrcIpAddr, bin(TimeGenerated, 10m)
| where count_ >= threshold
| extend IPCustomEntity = SrcIpAddr
name: OCI - Multiple instances terminated
severity: High
queryFrequency: 1h
query: |
  let threshold = 5;
  OCILogs
  | where data_eventName_s =~ 'TerminateInstance'
  | summarize count() by SrcIpAddr, bin(TimeGenerated, 10m)
  | where count_ >= threshold
  | extend IPCustomEntity = SrcIpAddr  
description: |
    'Detects when multiple instances were terminated.'
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Oracle Cloud Infrastructure/Analytic Rules/OCIMultipleInstancesTerminated.yaml
triggerOperator: gt
status: Available
triggerThreshold: 0
queryPeriod: 1h
requiredDataConnectors:
- dataTypes:
  - OCILogs
  connectorId: OracleCloudInfrastructureLogsConnector
entityMappings:
- entityType: IP
  fieldMappings:
  - columnName: IPCustomEntity
    identifier: Address
version: 1.0.1
tactics:
- Impact
relevantTechniques:
- T1529
kind: Scheduled
id: 252e651d-d825-480c-bdeb-8b239354577d