Analytic rule catalog
Check Point Exposure Management - Argos alerts to incidents
Back
| Id | 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36 |
| Rulename | Check Point Exposure Management - Argos alerts to incidents |
| Description | Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate and InboundStatusSync playbooks can map the incident back to the originating Argos alert. The CCP data connector polls on update_date, so every change to an Argos alert adds a new row for the same ref_id. Only the first open or acknowledged row creates an incident; later rows are status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the existing incident. An alert counts as already seen when it had an open or acknowledged row ingested more than 20 minutes earlier. Only alerts created within the 47-hour lookback are considered, which is the longest lookback Microsoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an alert falls inside the same lookback, so the already-seen check is complete and an update can never open a second incident. An alert created more than 47 hours before it first reaches the table does not get an incident. The ingestion_time bound limits each row to the few runs its arrival window covers, because the DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after that timestamp. Repeats within that window are folded into one incident by grouping on the ref_id custom detail. |
| Severity | Medium |
| Tactics | InitialAccess DefenseEvasion |
| Techniques | T1566 T1036 |
| Required data connectors | CheckPointCyberintAlerts |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 47h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml |
| Version | 1.0.0 |
| Arm template | 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36.json |
let ArrivalWindow = 20m;
let Lookback = 47h;
let SeenBefore = argsentdc_CL
| where TimeGenerated > ago(Lookback)
| where ingestion_time() <= ago(ArrivalWindow)
| where status in ("open", "acknowledged")
| distinct ref_id = tostring(ref_id);
argsentdc_CL
| where TimeGenerated > ago(Lookback)
| where ingestion_time() > ago(ArrivalWindow)
| summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)
| where status in ("open", "acknowledged")
| where todatetime(created_date) > ago(Lookback)
| join kind=leftanti SeenBefore on ref_id
| extend SentinelSeverity = case(
severity in ("very_high", "critical"), "High",
severity == "high", "High",
severity == "medium", "Medium",
severity == "low", "Low",
"Informational")
| project TimeGenerated,
RefId = ref_id,
AlertTitle = tostring(event_title),
AlertDescription = tostring(description),
OriginalSeverity = tostring(severity),
SentinelSeverity,
Confidence = tostring(confidence),
EventType = tostring(event_type),
Category = tostring(category),
Recommendation = tostring(recommendation)
suppressionDuration: 5h
name: Check Point Exposure Management - Argos alerts to incidents
suppressionEnabled: false
triggerOperator: gt
query: |
let ArrivalWindow = 20m;
let Lookback = 47h;
let SeenBefore = argsentdc_CL
| where TimeGenerated > ago(Lookback)
| where ingestion_time() <= ago(ArrivalWindow)
| where status in ("open", "acknowledged")
| distinct ref_id = tostring(ref_id);
argsentdc_CL
| where TimeGenerated > ago(Lookback)
| where ingestion_time() > ago(ArrivalWindow)
| summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)
| where status in ("open", "acknowledged")
| where todatetime(created_date) > ago(Lookback)
| join kind=leftanti SeenBefore on ref_id
| extend SentinelSeverity = case(
severity in ("very_high", "critical"), "High",
severity == "high", "High",
severity == "medium", "Medium",
severity == "low", "Low",
"Informational")
| project TimeGenerated,
RefId = ref_id,
AlertTitle = tostring(event_title),
AlertDescription = tostring(description),
OriginalSeverity = tostring(severity),
SentinelSeverity,
Confidence = tostring(confidence),
EventType = tostring(event_type),
Category = tostring(category),
Recommendation = tostring(recommendation)
queryFrequency: 5m
description: |
Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that
reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes
its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate
and InboundStatusSync playbooks can map the incident back to the originating Argos alert.
The CCP data connector polls on update_date, so every change to an Argos alert adds a new row
for the same ref_id. Only the first open or acknowledged row creates an incident; later rows
are status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the
existing incident. An alert counts as already seen when it had an open or acknowledged row
ingested more than 20 minutes earlier.
Only alerts created within the 47-hour lookback are considered, which is the longest lookback
Microsoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an
alert falls inside the same lookback, so the already-seen check is complete and an update can
never open a second incident. An alert created more than 47 hours before it first reaches the
table does not get an incident.
The ingestion_time bound limits each row to the few runs its arrival window covers, because
the DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after
that timestamp. Repeats within that window are folded into one incident by grouping on the
ref_id custom detail.
id: 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
triggerThreshold: 0
queryPeriod: 47h
version: 1.0.0
kind: Scheduled
customDetails:
category: Category
recommendation: Recommendation
event_type: EventType
ref_id: RefId
confidence: Confidence
argos_severity: OriginalSeverity
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
severity: Medium
requiredDataConnectors:
- connectorId: CheckPointCyberintAlerts
dataTypes:
- argsentdc_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml
incidentConfiguration:
groupingConfiguration:
groupByCustomDetails:
- ref_id
lookbackDuration: 1d
enabled: true
reopenClosedIncident: false
matchingMethod: Selected
createIncident: true
alertDetailsOverride:
alertDescriptionFormat: '{{AlertDescription}}'
alertDisplayNameFormat: '{{AlertTitle}}'
alertSeverityColumnName: SentinelSeverity
relevantTechniques:
- T1566
- T1036
tactics:
- InitialAccess
- DefenseEvasion
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "{{AlertDescription}}",
"alertDisplayNameFormat": "{{AlertTitle}}",
"alertSeverityColumnName": "SentinelSeverity"
},
"alertRuleTemplateName": "2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36",
"customDetails": {
"argos_severity": "OriginalSeverity",
"category": "Category",
"confidence": "Confidence",
"event_type": "EventType",
"recommendation": "Recommendation",
"ref_id": "RefId"
},
"description": "Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that\nreaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes\nits own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate\nand InboundStatusSync playbooks can map the incident back to the originating Argos alert.\n\nThe CCP data connector polls on update_date, so every change to an Argos alert adds a new row\nfor the same ref_id. Only the first open or acknowledged row creates an incident; later rows\nare status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the\nexisting incident. An alert counts as already seen when it had an open or acknowledged row\ningested more than 20 minutes earlier.\n\nOnly alerts created within the 47-hour lookback are considered, which is the longest lookback\nMicrosoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an\nalert falls inside the same lookback, so the already-seen check is complete and an update can\nnever open a second incident. An alert created more than 47 hours before it first reaches the\ntable does not get an incident.\n\nThe ingestion_time bound limits each row to the few runs its arrival window covers, because\nthe DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after\nthat timestamp. Repeats within that window are folded into one incident by grouping on the\nref_id custom detail.\n",
"displayName": "Check Point Exposure Management - Argos alerts to incidents",
"enabled": true,
"entityMappings": null,
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByCustomDetails": [
"ref_id"
],
"lookbackDuration": "P1D",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml",
"query": "let ArrivalWindow = 20m;\nlet Lookback = 47h;\nlet SeenBefore = argsentdc_CL\n | where TimeGenerated > ago(Lookback)\n | where ingestion_time() <= ago(ArrivalWindow)\n | where status in (\"open\", \"acknowledged\")\n | distinct ref_id = tostring(ref_id);\nargsentdc_CL\n| where TimeGenerated > ago(Lookback)\n| where ingestion_time() > ago(ArrivalWindow)\n| summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)\n| where status in (\"open\", \"acknowledged\")\n| where todatetime(created_date) > ago(Lookback)\n| join kind=leftanti SeenBefore on ref_id\n| extend SentinelSeverity = case(\n severity in (\"very_high\", \"critical\"), \"High\",\n severity == \"high\", \"High\",\n severity == \"medium\", \"Medium\",\n severity == \"low\", \"Low\",\n \"Informational\")\n| project TimeGenerated,\n RefId = ref_id,\n AlertTitle = tostring(event_title),\n AlertDescription = tostring(description),\n OriginalSeverity = tostring(severity),\n SentinelSeverity,\n Confidence = tostring(confidence),\n EventType = tostring(event_type),\n Category = tostring(category),\n Recommendation = tostring(recommendation)\n",
"queryFrequency": "PT5M",
"queryPeriod": "PT47H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion",
"InitialAccess"
],
"techniques": [
"T1036",
"T1566"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}