{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2d7b90c5-41ae-4f83-a6d2-9b1c5e3407fa')]",
      "kind": "Hunting",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2d7b90c5-41ae-4f83-a6d2-9b1c5e3407fa')]",
      "properties": {
        "alertRuleTemplateName": "2d7b90c5-41ae-4f83-a6d2-9b1c5e3407fa",
        "customDetails": null,
        "description": "Matches Datazag impersonation indicators against historical ASIM-normalized DNS to surface domains resolved inside the estate before the feed was connected. Adjust dns_lookback to your DNS retention. Requires ASIM DNS parsers.\n",
        "displayName": "Datazag - retro-hunt historical DNS against impersonation indicators",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "DNS",
            "fieldMappings": [
              {
                "columnName": "IndicatorDomain",
                "identifier": "DomainName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SourceIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "SourceHost",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "AccountUpn",
                "identifier": "FullName"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Datazag/Hunting%20Queries/DatazagRetroHunt_DNS.yaml",
        "query": "let datazag_identity = \"identity--55a5a448-c6f1-5128-bc71-4d85b719131e\";\nlet dns_lookback = 90d;\nlet confidence_floor = 85;\nlet DatazagDomains =\n    ThreatIntelIndicators\n    | where tostring(Data.created_by_ref) == datazag_identity\n    | where ObservableKey == \"domain-name:value\"\n    | where isnotempty(ObservableValue)\n    | summarize arg_max(TimeGenerated, *) by Id\n    | where IsDeleted == false\n    | where tostring(Data.revoked) != \"true\"\n    | where Confidence >= confidence_floor\n    | extend IndicatorDomain = tolower(trim_end(@\"\\.\", ObservableValue))\n    | project\n        IndicatorDomain,\n        DatazagAlertRef = tostring(Data.external_references[0].external_id),\n        Confidence,\n        IndicatorEvidence = tostring(Data.labels),\n        IndicatorFirstPublished = todatetime(Data.created);\nlet DnsActivity =\n    _Im_Dns\n    | where TimeGenerated >= ago(dns_lookback)\n    | where isnotempty(DnsQuery)\n    | extend IndicatorDomain = tolower(trim_end(@\"\\.\", DnsQuery))\n    | project\n        DnsTime         = TimeGenerated,\n        IndicatorDomain,\n        SrcIpAddr       = column_ifexists(\"SrcIpAddr\", \"\"),\n        SrcHostname     = column_ifexists(\"SrcHostname\", \"\"),\n        SrcUsername     = column_ifexists(\"SrcUsername\", \"\"),\n        SrcUsernameType = column_ifexists(\"SrcUsernameType\", \"\");\nDatazagDomains\n| join kind=innerunique DnsActivity on IndicatorDomain\n| summarize\n    FirstResolved = min(DnsTime),\n    LastResolved  = max(DnsTime),\n    QueryCount    = count(),\n    SourceIps     = make_set(SrcIpAddr, 100),\n    SourceHosts   = make_set(SrcHostname, 100),\n    Upns          = make_set_if(SrcUsername, SrcUsernameType == \"UPN\", 100)\n    by IndicatorDomain, DatazagAlertRef, Confidence, IndicatorEvidence, IndicatorFirstPublished\n| extend\n    SourceIp      = tostring(SourceIps[0]),\n    SourceHost    = tostring(SourceHosts[0]),\n    AccountUpn    = tostring(Upns[0]),\n    HostsAffected = array_length(SourceHosts),\n    DaysBeforeIndicator = datetime_diff('day', IndicatorFirstPublished, FirstResolved)\n| order by FirstResolved asc\n",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "InitialAccess"
        ],
        "techniques": [
          "T1071",
          "T1566"
        ],
        "templateVersion": "1.0.0"
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}
