CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
| Id | 359e2afb-b6d4-45db-90aa-c89ce7234d72 |
| Rulename | CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule |
| Description | “This analytics rule identifies network-based indicators such as URLs, IP addresses, and domains related to phishing campaigns, as reported by CYFIRMA threat intelligence. These indicators are flagged with a recommended action to block and are categorized under the ‘Phishing’ role. Such infrastructure is often used to deliver phishing emails, host fake login portals, or redirect victims to credential-harvesting pages. monitoring these indicators proactively helps prevent user compromise and data theft.” |
| Severity | High |
| Tactics | InitialAccess Execution CredentialAccess Exfiltration |
| Techniques | T1566 T1204 T1556 T1110 T1041 T1566.001 T1566.002 T1204.001 T1556.002 T1110.003 |
| Required data connectors | CyfirmaCyberIntelligenceDC |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | GreaterThan |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyfirma Cyber Intelligence/Analytic Rules/PhishingNetworkIndicatorsMonitorHighSeverityRule.yaml |
| Version | 1.0.1 |
| Arm template | 359e2afb-b6d4-45db-90aa-c89ce7234d72.json |
//Phishing Network Indicators - Monitor Recommended
let timeFrame= 5m;
CyfirmaIndicators_CL
| where ConfidenceScore >= 80
and TimeGenerated between (ago(timeFrame) .. now())
and pattern !contains 'file:hashes' and RecommendedActions has 'Monitor' and Roles has 'Phishing'
| extend IPv4 = extract(@"ipv4-addr:value\s*=\s*'([^']+)'", 1, pattern)
| extend IPv6 = extract(@"ipv6-addr:value\s*=\s*'([^']+)'", 1, pattern)
| extend URL = extract(@"url:value\s*=\s*'([^']+)'", 1, pattern)
| extend Domain = extract(@"domain-name:value\s*=\s*'([^']+)'", 1, pattern)
| extend parsed = parse_json(extensions)
| extend extensionKeys = bag_keys(parsed)
| mv-expand extensionKeys
| extend extensionKeyStr = tostring(extensionKeys)
| extend ext = parsed[extensionKeyStr]
| extend props = ext.properties
| extend
extension_id = extensionKeyStr,
ASN_Owner = props.asn_owner,
ASN = props.asn,
ProviderName = 'CYFIRMA',
ProductName = 'DeCYFIR/DeTCT'
| project
IPv4,
IPv6,
URL,
Domain,
ThreatActors,
RecommendedActions,
Sources,
Roles,
Country,
IPAbuse,
name,
Description,
ConfidenceScore,
IndicatorID,
created,
modified,
valid_from,
Tags,
ThreatType,
TimeGenerated,
SecurityVendors,
ProductName,
ProviderName
alertDetailsOverride:
alertDynamicProperties:
- value: ProductName
alertProperty: ProductName
- value: ProviderName
alertProperty: ProviderName
alertDescriptionFormat: '{{Description}} - {{name}} '
alertDisplayNameFormat: 'High-Confidence Malicious Phishing Network Indicators - Monitor Recommended - {{name}} '
kind: Scheduled
severity: High
eventGroupingSettings:
aggregationKind: AlertPerResult
tactics:
- InitialAccess
- Execution
- CredentialAccess
- Exfiltration
suppressionDuration: 5m
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
enabled: false
matchingMethod: AllEntities
lookbackDuration: PT5H
createIncident: true
version: 1.0.1
triggerThreshold: 0
queryPeriod: 5m
entityMappings:
- fieldMappings:
- columnName: IPv4
identifier: Address
entityType: IP
- fieldMappings:
- columnName: IPv6
identifier: Address
entityType: IP
- fieldMappings:
- columnName: Domain
identifier: DomainName
entityType: DNS
- fieldMappings:
- columnName: URL
identifier: Url
entityType: URL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyfirma Cyber Intelligence/Analytic Rules/PhishingNetworkIndicatorsMonitorHighSeverityRule.yaml
enabled: false
triggerOperator: GreaterThan
id: 359e2afb-b6d4-45db-90aa-c89ce7234d72
requiredDataConnectors:
- dataTypes:
- CyfirmaIndicators_CL
connectorId: CyfirmaCyberIntelligenceDC
relevantTechniques:
- T1566
- T1204
- T1556
- T1110
- T1041
- T1566.001
- T1566.002
- T1204.001
- T1556.002
- T1110.003
name: CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
queryFrequency: 5m
suppressionEnabled: true
query: |
//Phishing Network Indicators - Monitor Recommended
let timeFrame= 5m;
CyfirmaIndicators_CL
| where ConfidenceScore >= 80
and TimeGenerated between (ago(timeFrame) .. now())
and pattern !contains 'file:hashes' and RecommendedActions has 'Monitor' and Roles has 'Phishing'
| extend IPv4 = extract(@"ipv4-addr:value\s*=\s*'([^']+)'", 1, pattern)
| extend IPv6 = extract(@"ipv6-addr:value\s*=\s*'([^']+)'", 1, pattern)
| extend URL = extract(@"url:value\s*=\s*'([^']+)'", 1, pattern)
| extend Domain = extract(@"domain-name:value\s*=\s*'([^']+)'", 1, pattern)
| extend parsed = parse_json(extensions)
| extend extensionKeys = bag_keys(parsed)
| mv-expand extensionKeys
| extend extensionKeyStr = tostring(extensionKeys)
| extend ext = parsed[extensionKeyStr]
| extend props = ext.properties
| extend
extension_id = extensionKeyStr,
ASN_Owner = props.asn_owner,
ASN = props.asn,
ProviderName = 'CYFIRMA',
ProductName = 'DeCYFIR/DeTCT'
| project
IPv4,
IPv6,
URL,
Domain,
ThreatActors,
RecommendedActions,
Sources,
Roles,
Country,
IPAbuse,
name,
Description,
ConfidenceScore,
IndicatorID,
created,
modified,
valid_from,
Tags,
ThreatType,
TimeGenerated,
SecurityVendors,
ProductName,
ProviderName
description: |
"This analytics rule identifies network-based indicators such as URLs, IP addresses, and domains related to phishing campaigns, as reported by CYFIRMA threat intelligence.
These indicators are flagged with a recommended action to block and are categorized under the 'Phishing' role.
Such infrastructure is often used to deliver phishing emails, host fake login portals, or redirect victims to credential-harvesting pages.
monitoring these indicators proactively helps prevent user compromise and data theft."
customDetails:
Created: created
Description: Description
SecurityVendors: SecurityVendors
RecommendedActions: RecommendedActions
ThreatActors: ThreatActors
ConfidenceScore: ConfidenceScore
Tags: Tags
ValidFrom: valid_from
Sources: Sources
Roles: Roles
IndicatorID: IndicatorID
ThreatType: ThreatType
Modified: modified
TimeGenerated: TimeGenerated
Country: Country
IPAbuse: IPAbuse