Analytic rule catalog
Pathlock TDnR - RiskTrack Audit Results
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52 |
| Rulename | Pathlock TDnR - RiskTrack Audit Results |
| Description | Detects Pathlock RiskTrack audit results forwarded to Microsoft Sentinel. RiskTrack findings represent completed risk assessments identifying segregation of duties conflicts, critical access violations, and compliance gaps that require remediation or SOC awareness. |
| Severity | High |
| Tactics | Discovery |
| Techniques | T1082 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAST_RT.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52.json |
Pathlock_TDnR_CL
| where DataSource == "SAST_RT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
triggerThreshold: 0
suppressionDuration: 5h
incidentConfiguration:
createIncident: true
groupingConfiguration:
reopenClosedIncident: false
groupByAlertDetails: []
matchingMethod: AnyAlert
groupByEntities: []
enabled: true
groupByCustomDetails: []
lookbackDuration: 5h
kind: Scheduled
description: Detects Pathlock RiskTrack audit results forwarded to Microsoft Sentinel. RiskTrack findings represent completed risk assessments identifying segregation of duties conflicts, critical access violations, and compliance gaps that require remediation or SOC awareness.
queryFrequency: 1h
triggerOperator: gt
relevantTechniques:
- T1082
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52
query: |
Pathlock_TDnR_CL
| where DataSource == "SAST_RT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
eventGroupingSettings:
aggregationKind: SingleAlert
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAST_RT.yaml
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
suppressionEnabled: false
tactics:
- Discovery
queryPeriod: 1h
severity: High
status: Available
name: Pathlock TDnR - RiskTrack Audit Results
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52",
"customDetails": null,
"description": "Detects Pathlock RiskTrack audit results forwarded to Microsoft Sentinel. RiskTrack findings represent completed risk assessments identifying segregation of duties conflicts, critical access violations, and compliance gaps that require remediation or SOC awareness.",
"displayName": "Pathlock TDnR - RiskTrack Audit Results",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAST_RT.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"SAST_RT\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"Discovery"
],
"techniques": [
"T1082"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}