SailPointIdentityNowUserWithFailedEvent
| Id | 2a215222-bfc5-4858-a530-6d4088ebfa15 |
| Rulename | SailPointIdentityNowUserWithFailedEvent |
| Description | Detects any failed event for a particular user. |
| Severity | High |
| Tactics | InitialAccess |
| Techniques | T1133 |
| Required data connectors | SailPointIdentityNow SailPointIdentityNowConnector |
| Kind | Scheduled |
| Query frequency | 1d |
| Query period | 14d |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SailPointIdentityNow/Analytic Rules/SailPointIdentityNowUserWithFailedEvents.yaml |
| Version | 1.1.0 |
| Arm template | 2a215222-bfc5-4858-a530-6d4088ebfa15.json |
declare query_parameters(lbperiod:timespan = 14d, type:string = "ACCESS_ITEM", actorName:string = "test.tester", targetName:string = "test.tester");
SailPointIDN_Events
| where TimeGenerated > ago(lbperiod)
| where EventType == type
| where Status == "FAILED"
| where ActorName == actorName
| where TargetName == targetName
| sort by Created
relevantTechniques:
- T1133
entityMappings:
- entityType: Account
fieldMappings:
- columnName: TechnicalName
identifier: Name
version: 1.1.0
id: 2a215222-bfc5-4858-a530-6d4088ebfa15
severity: High
kind: Scheduled
queryFrequency: 1d
description: |
'Detects any failed event for a particular user.'
requiredDataConnectors:
- connectorId: SailPointIdentityNow
dataTypes:
- SailPointIDN_Events
- connectorId: SailPointIdentityNowConnector
dataTypes:
- SailPointIDN_Events
triggerOperator: gt
name: SailPointIdentityNowUserWithFailedEvent
tactics:
- InitialAccess
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SailPointIdentityNow/Analytic Rules/SailPointIdentityNowUserWithFailedEvents.yaml
triggerThreshold: 0
queryPeriod: 14d
query: |
declare query_parameters(lbperiod:timespan = 14d, type:string = "ACCESS_ITEM", actorName:string = "test.tester", targetName:string = "test.tester");
SailPointIDN_Events
| where TimeGenerated > ago(lbperiod)
| where EventType == type
| where Status == "FAILED"
| where ActorName == actorName
| where TargetName == targetName
| sort by Created
status: Available