Back
Id2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
RulenameCheck Point Exposure Management - Argos alerts to incidents
DescriptionCreates a Microsoft Sentinel incident for each Check Point Exposure Management alert that

reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes

its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate

and InboundStatusSync playbooks can map the incident back to the originating Argos alert.



The CCP data connector polls on update_date, so every change to an Argos alert adds a new row

for the same ref_id. Only the first open or acknowledged row creates an incident; later rows

are status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the

existing incident. An alert counts as already seen when it had an open or acknowledged row

ingested more than 20 minutes earlier.



Only alerts created within the 47-hour lookback are considered, which is the longest lookback

Microsoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an

alert falls inside the same lookback, so the already-seen check is complete and an update can

never open a second incident. An alert created more than 47 hours before it first reaches the

table does not get an incident.



The ingestion_time bound limits each row to the few runs its arrival window covers, because

the DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after

that timestamp. Repeats within that window are folded into one incident by grouping on the

ref_id custom detail.
SeverityMedium
TacticsInitialAccess
DefenseEvasion
TechniquesT1566
T1036
Required data connectorsCheckPointCyberintAlerts
KindScheduled
Query frequency5m
Query period47h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml
Version1.0.0
Arm template2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36.json
Deploy To Azure
let ArrivalWindow = 20m;
let Lookback = 47h;
let SeenBefore = argsentdc_CL
    | where TimeGenerated > ago(Lookback)
    | where ingestion_time() <= ago(ArrivalWindow)
    | where status in ("open", "acknowledged")
    | distinct ref_id = tostring(ref_id);
argsentdc_CL
| where TimeGenerated > ago(Lookback)
| where ingestion_time() > ago(ArrivalWindow)
| summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)
| where status in ("open", "acknowledged")
| where todatetime(created_date) > ago(Lookback)
| join kind=leftanti SeenBefore on ref_id
| extend SentinelSeverity = case(
    severity in ("very_high", "critical"), "High",
    severity == "high", "High",
    severity == "medium", "Medium",
    severity == "low", "Low",
    "Informational")
| project TimeGenerated,
          RefId = ref_id,
          AlertTitle = tostring(event_title),
          AlertDescription = tostring(description),
          OriginalSeverity = tostring(severity),
          SentinelSeverity,
          Confidence = tostring(confidence),
          EventType = tostring(event_type),
          Category = tostring(category),
          Recommendation = tostring(recommendation)
suppressionDuration: 5h
name: Check Point Exposure Management - Argos alerts to incidents
suppressionEnabled: false
triggerOperator: gt
query: |
  let ArrivalWindow = 20m;
  let Lookback = 47h;
  let SeenBefore = argsentdc_CL
      | where TimeGenerated > ago(Lookback)
      | where ingestion_time() <= ago(ArrivalWindow)
      | where status in ("open", "acknowledged")
      | distinct ref_id = tostring(ref_id);
  argsentdc_CL
  | where TimeGenerated > ago(Lookback)
  | where ingestion_time() > ago(ArrivalWindow)
  | summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)
  | where status in ("open", "acknowledged")
  | where todatetime(created_date) > ago(Lookback)
  | join kind=leftanti SeenBefore on ref_id
  | extend SentinelSeverity = case(
      severity in ("very_high", "critical"), "High",
      severity == "high", "High",
      severity == "medium", "Medium",
      severity == "low", "Low",
      "Informational")
  | project TimeGenerated,
            RefId = ref_id,
            AlertTitle = tostring(event_title),
            AlertDescription = tostring(description),
            OriginalSeverity = tostring(severity),
            SentinelSeverity,
            Confidence = tostring(confidence),
            EventType = tostring(event_type),
            Category = tostring(category),
            Recommendation = tostring(recommendation)
queryFrequency: 5m
description: |
  Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that
  reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes
  its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate
  and InboundStatusSync playbooks can map the incident back to the originating Argos alert.

  The CCP data connector polls on update_date, so every change to an Argos alert adds a new row
  for the same ref_id. Only the first open or acknowledged row creates an incident; later rows
  are status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the
  existing incident. An alert counts as already seen when it had an open or acknowledged row
  ingested more than 20 minutes earlier.

  Only alerts created within the 47-hour lookback are considered, which is the longest lookback
  Microsoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an
  alert falls inside the same lookback, so the already-seen check is complete and an update can
  never open a second incident. An alert created more than 47 hours before it first reaches the
  table does not get an incident.

  The ingestion_time bound limits each row to the few runs its arrival window covers, because
  the DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after
  that timestamp. Repeats within that window are folded into one incident by grouping on the
  ref_id custom detail.
id: 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
triggerThreshold: 0
queryPeriod: 47h
version: 1.0.0
kind: Scheduled
customDetails:
  category: Category
  recommendation: Recommendation
  event_type: EventType
  ref_id: RefId
  confidence: Confidence
  argos_severity: OriginalSeverity
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Medium
requiredDataConnectors:
- connectorId: CheckPointCyberintAlerts
  dataTypes:
  - argsentdc_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml
incidentConfiguration:
  groupingConfiguration:
    groupByCustomDetails:
    - ref_id
    lookbackDuration: 1d
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
  createIncident: true
alertDetailsOverride:
  alertDescriptionFormat: '{{AlertDescription}}'
  alertDisplayNameFormat: '{{AlertTitle}}'
  alertSeverityColumnName: SentinelSeverity
relevantTechniques:
- T1566
- T1036
tactics:
- InitialAccess
- DefenseEvasion
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "{{AlertDescription}}",
          "alertDisplayNameFormat": "{{AlertTitle}}",
          "alertSeverityColumnName": "SentinelSeverity"
        },
        "alertRuleTemplateName": "2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36",
        "customDetails": {
          "argos_severity": "OriginalSeverity",
          "category": "Category",
          "confidence": "Confidence",
          "event_type": "EventType",
          "recommendation": "Recommendation",
          "ref_id": "RefId"
        },
        "description": "Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that\nreaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes\nits own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate\nand InboundStatusSync playbooks can map the incident back to the originating Argos alert.\n\nThe CCP data connector polls on update_date, so every change to an Argos alert adds a new row\nfor the same ref_id. Only the first open or acknowledged row creates an incident; later rows\nare status updates, which the Check_Point_EM_InboundStatusSync playbook applies to the\nexisting incident. An alert counts as already seen when it had an open or acknowledged row\ningested more than 20 minutes earlier.\n\nOnly alerts created within the 47-hour lookback are considered, which is the longest lookback\nMicrosoft Sentinel allows for a rule that runs every 5 minutes. Every earlier row of such an\nalert falls inside the same lookback, so the already-seen check is complete and an update can\nnever open a second incident. An alert created more than 47 hours before it first reaches the\ntable does not get an incident.\n\nThe ingestion_time bound limits each row to the few runs its arrival window covers, because\nthe DCR maps update_date into TimeGenerated and a row becomes queryable several minutes after\nthat timestamp. Repeats within that window are folded into one incident by grouping on the\nref_id custom detail.\n",
        "displayName": "Check Point Exposure Management - Argos alerts to incidents",
        "enabled": true,
        "entityMappings": null,
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "ref_id"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Check%20Point%20Cyberint%20Alerts/Analytic%20Rules/CPEMArgosAlertsToIncidents.yaml",
        "query": "let ArrivalWindow = 20m;\nlet Lookback = 47h;\nlet SeenBefore = argsentdc_CL\n    | where TimeGenerated > ago(Lookback)\n    | where ingestion_time() <= ago(ArrivalWindow)\n    | where status in (\"open\", \"acknowledged\")\n    | distinct ref_id = tostring(ref_id);\nargsentdc_CL\n| where TimeGenerated > ago(Lookback)\n| where ingestion_time() > ago(ArrivalWindow)\n| summarize arg_max(TimeGenerated, *) by ref_id = tostring(ref_id)\n| where status in (\"open\", \"acknowledged\")\n| where todatetime(created_date) > ago(Lookback)\n| join kind=leftanti SeenBefore on ref_id\n| extend SentinelSeverity = case(\n    severity in (\"very_high\", \"critical\"), \"High\",\n    severity == \"high\", \"High\",\n    severity == \"medium\", \"Medium\",\n    severity == \"low\", \"Low\",\n    \"Informational\")\n| project TimeGenerated,\n          RefId = ref_id,\n          AlertTitle = tostring(event_title),\n          AlertDescription = tostring(description),\n          OriginalSeverity = tostring(severity),\n          SentinelSeverity,\n          Confidence = tostring(confidence),\n          EventType = tostring(event_type),\n          Category = tostring(category),\n          Recommendation = tostring(recommendation)\n",
        "queryFrequency": "PT5M",
        "queryPeriod": "PT47H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion",
          "InitialAccess"
        ],
        "techniques": [
          "T1036",
          "T1566"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}