Back
Id279316e8-8965-47d2-9788-b94dc352c853
RulenameSlackAudit - Public link created for file which can contain sensitive information.
DescriptionDetects public links created for files that may contain sensitive data such as passwords, authentication tokens,

secret keys, or private configuration files. Tune exclusions using the SlackAuditSensitiveFile_Allowlist_File and SlackAuditSensitiveFile_Allowlist_Account

watchlists when known benign files or accounts generate expected public-link activity.
SeverityMedium
TacticsExfiltration
TechniquesT1048
T1567.002
Required data connectorsSlackAuditAPI
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SlackAudit/Analytic%20Rules/SlackAuditSensitiveFile.yaml
Version1.0.1
Arm template279316e8-8965-47d2-9788-b94dc352c853.json
Deploy To Azure
let AllowedFiles = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_File') | summarize make_set(tostring(SearchKey)));
let AllowedUsers = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_Account') | summarize make_set(tostring(SearchKey)));
SlackAudit
| where Action =~ 'file_public_link_created'
| extend FileNameLower = tolower(EntityFileName), UserLower = tolower(SrcUserName)
| where EntityFileName in~ ('id_rsa')
    or FileNameLower has_any ('password', 'secret', 'token', 'credential', 'private key', 'api key')
    or FileNameLower has_any ('.ssh', '.npmrc', '.muttrc', '.gitconfig', '.netrc', 'package.json', 'Gemfile', 'bower.json', 'config.gypi', 'travis.yml', 'config.json')
| where isempty(AllowedFiles) or EntityFileName !in~ (AllowedFiles)
| where isempty(AllowedUsers) or UserLower !in~ (AllowedUsers)
| extend AccountCustomEntity = SrcUserName
| extend IPCustomEntity = SrcIpAddr
name: SlackAudit - Public link created for file which can contain sensitive information.
triggerOperator: gt
query: |
  let AllowedFiles = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_File') | summarize make_set(tostring(SearchKey)));
  let AllowedUsers = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_Account') | summarize make_set(tostring(SearchKey)));
  SlackAudit
  | where Action =~ 'file_public_link_created'
  | extend FileNameLower = tolower(EntityFileName), UserLower = tolower(SrcUserName)
  | where EntityFileName in~ ('id_rsa')
      or FileNameLower has_any ('password', 'secret', 'token', 'credential', 'private key', 'api key')
      or FileNameLower has_any ('.ssh', '.npmrc', '.muttrc', '.gitconfig', '.netrc', 'package.json', 'Gemfile', 'bower.json', 'config.gypi', 'travis.yml', 'config.json')
  | where isempty(AllowedFiles) or EntityFileName !in~ (AllowedFiles)
  | where isempty(AllowedUsers) or UserLower !in~ (AllowedUsers)
  | extend AccountCustomEntity = SrcUserName
  | extend IPCustomEntity = SrcIpAddr
queryFrequency: 1h
description: |
  'Detects public links created for files that may contain sensitive data such as passwords, authentication tokens,
  secret keys, or private configuration files. Tune exclusions using the SlackAuditSensitiveFile_Allowlist_File and SlackAuditSensitiveFile_Allowlist_Account
  watchlists when known benign files or accounts generate expected public-link activity.'
id: 279316e8-8965-47d2-9788-b94dc352c853
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.1
kind: Scheduled
customDetails:
  SourceUser: SrcUserName
  FileName: EntityFileName
  SourceIP: SrcIpAddr
  IpEntity: IPCustomEntity
  ActorEntity: AccountCustomEntity
  Action: Action
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: SlackAuditAPI
  dataTypes:
  - SlackAudit_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SlackAudit/Analytic%20Rules/SlackAuditSensitiveFile.yaml
alertDetailsOverride:
  alertDescriptionFormat: Public link created for {{EntityFileName}} by {{SrcUserName}} from {{SrcIpAddr}}
  alertDisplayNameFormat: Slack public link created for sensitive file {{EntityFileName}} by {{SrcUserName}}
relevantTechniques:
- T1048
- T1567.002
tactics:
- Exfiltration
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: AccountCustomEntity
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: IPCustomEntity
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/279316e8-8965-47d2-9788-b94dc352c853')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/279316e8-8965-47d2-9788-b94dc352c853')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Public link created for {{EntityFileName}} by {{SrcUserName}} from {{SrcIpAddr}}",
          "alertDisplayNameFormat": "Slack public link created for sensitive file {{EntityFileName}} by {{SrcUserName}}"
        },
        "alertRuleTemplateName": "279316e8-8965-47d2-9788-b94dc352c853",
        "customDetails": {
          "Action": "Action",
          "ActorEntity": "AccountCustomEntity",
          "FileName": "EntityFileName",
          "IpEntity": "IPCustomEntity",
          "SourceIP": "SrcIpAddr",
          "SourceUser": "SrcUserName"
        },
        "description": "'Detects public links created for files that may contain sensitive data such as passwords, authentication tokens,\nsecret keys, or private configuration files. Tune exclusions using the SlackAuditSensitiveFile_Allowlist_File and SlackAuditSensitiveFile_Allowlist_Account\nwatchlists when known benign files or accounts generate expected public-link activity.'\n",
        "displayName": "SlackAudit - Public link created for file which can contain sensitive information.",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "AccountCustomEntity",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "IPCustomEntity",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SlackAudit/Analytic%20Rules/SlackAuditSensitiveFile.yaml",
        "query": "let AllowedFiles = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_File') | summarize make_set(tostring(SearchKey)));\nlet AllowedUsers = toscalar(_GetWatchlist('SlackAuditSensitiveFile_Allowlist_Account') | summarize make_set(tostring(SearchKey)));\nSlackAudit\n| where Action =~ 'file_public_link_created'\n| extend FileNameLower = tolower(EntityFileName), UserLower = tolower(SrcUserName)\n| where EntityFileName in~ ('id_rsa')\n    or FileNameLower has_any ('password', 'secret', 'token', 'credential', 'private key', 'api key')\n    or FileNameLower has_any ('.ssh', '.npmrc', '.muttrc', '.gitconfig', '.netrc', 'package.json', 'Gemfile', 'bower.json', 'config.gypi', 'travis.yml', 'config.json')\n| where isempty(AllowedFiles) or EntityFileName !in~ (AllowedFiles)\n| where isempty(AllowedUsers) or UserLower !in~ (AllowedUsers)\n| extend AccountCustomEntity = SrcUserName\n| extend IPCustomEntity = SrcIpAddr\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [
          "T1567.002"
        ],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Exfiltration"
        ],
        "techniques": [
          "T1048",
          "T1567"
        ],
        "templateVersion": "1.0.1",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}