Analytic rule catalog
Netskope Client - Internet Security disabled by user
Back
| Id | 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8 |
| Rulename | Netskope Client - Internet Security disabled by user |
| Description | Detects Netskope Client devices where the user disabled the Netskope Internet Security (secure web gateway / CASB steering) service. All matching client-status events in the 6-hour window are collected into a single alert, grouped per device, so repeated disable events on the same device are reported once. A user disabling Internet Security bypasses web, threat and data protection policies for that device. |
| Severity | Medium |
| Tactics | DefenseEvasion |
| Techniques | T1562 |
| Required data connectors | NetskopeClientStatus |
| Kind | Scheduled |
| Query frequency | 6h |
| Query period | 6h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml |
| Version | 1.0.0 |
| Arm template | 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8.json |
NetskopeClientStatus_CL
| where TimeGenerated > ago(6h)
| where last_seen_device_event_actor_name =~ "USER"
and last_seen_device_event_service_name =~ "Internet Security"
and last_seen_device_event_status_name =~ "DISABLED"
| extend DeviceKey = case(
isnotempty(device_hash), device_hash,
isnotempty(guid), guid,
isnotempty(device_id), device_id,
host_info_hostname)
| summarize
EventCount = count(),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated),
ClientEvents = make_set(last_seen_device_event_event_name, 10),
arg_max(TimeGenerated,
host_info_hostname,
user_info_username,
last_connected_from_public_ip,
last_connected_from_private_ip,
host_info_os_name,
client_version,
last_seen_device_event_actor_name,
last_seen_device_event_service_name,
last_seen_device_event_status_name,
last_seen_device_event_status_v2_name,
last_seen_device_event_npa_status_name,
last_seen_device_event_event_name,
last_seen_device_event_event_details)
by DeviceKey
| project
LastSeen,
FirstSeen,
EventCount,
DeviceKey,
HostName = host_info_hostname,
UserName = user_info_username,
PublicIp = last_connected_from_public_ip,
PrivateIp = last_connected_from_private_ip,
OperatingSystem = host_info_os_name,
ClientVersion = client_version,
Actor = last_seen_device_event_actor_name,
ServiceName = last_seen_device_event_service_name,
ClientStatus = last_seen_device_event_status_name,
ClientStatusV2 = last_seen_device_event_status_v2_name,
NpaStatus = last_seen_device_event_npa_status_name,
LatestClientEvent = last_seen_device_event_event_name,
EventDetails = last_seen_device_event_event_details,
ClientEvents
| order by LastSeen desc
name: Netskope Client - Internet Security disabled by user
triggerOperator: gt
query: |
NetskopeClientStatus_CL
| where TimeGenerated > ago(6h)
| where last_seen_device_event_actor_name =~ "USER"
and last_seen_device_event_service_name =~ "Internet Security"
and last_seen_device_event_status_name =~ "DISABLED"
| extend DeviceKey = case(
isnotempty(device_hash), device_hash,
isnotempty(guid), guid,
isnotempty(device_id), device_id,
host_info_hostname)
| summarize
EventCount = count(),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated),
ClientEvents = make_set(last_seen_device_event_event_name, 10),
arg_max(TimeGenerated,
host_info_hostname,
user_info_username,
last_connected_from_public_ip,
last_connected_from_private_ip,
host_info_os_name,
client_version,
last_seen_device_event_actor_name,
last_seen_device_event_service_name,
last_seen_device_event_status_name,
last_seen_device_event_status_v2_name,
last_seen_device_event_npa_status_name,
last_seen_device_event_event_name,
last_seen_device_event_event_details)
by DeviceKey
| project
LastSeen,
FirstSeen,
EventCount,
DeviceKey,
HostName = host_info_hostname,
UserName = user_info_username,
PublicIp = last_connected_from_public_ip,
PrivateIp = last_connected_from_private_ip,
OperatingSystem = host_info_os_name,
ClientVersion = client_version,
Actor = last_seen_device_event_actor_name,
ServiceName = last_seen_device_event_service_name,
ClientStatus = last_seen_device_event_status_name,
ClientStatusV2 = last_seen_device_event_status_v2_name,
NpaStatus = last_seen_device_event_npa_status_name,
LatestClientEvent = last_seen_device_event_event_name,
EventDetails = last_seen_device_event_event_details,
ClientEvents
| order by LastSeen desc
queryFrequency: 6h
description: |
Detects Netskope Client devices where the user disabled the Netskope Internet Security
(secure web gateway / CASB steering) service. All matching client-status events in the
6-hour window are collected into a single alert, grouped per device, so repeated disable
events on the same device are reported once. A user disabling Internet Security bypasses
web, threat and data protection policies for that device.
id: 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
triggerThreshold: 0
queryPeriod: 6h
version: 1.0.0
kind: Scheduled
customDetails:
DeviceKey: DeviceKey
EventCount: EventCount
Actor: Actor
LatestClientEvent: LatestClientEvent
ServiceName: ServiceName
ClientVersion: ClientVersion
OperatingSystem: OperatingSystem
ClientStatus: ClientStatus
NpaStatus: NpaStatus
status: Available
eventGroupingSettings:
aggregationKind: SingleAlert
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeClientStatus
dataTypes:
- NetskopeClientStatus_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
- identifier: Name
columnName: UserName
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: HostName
entityType: Host
- fieldMappings:
- identifier: Address
columnName: PublicIp
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8')]",
"properties": {
"alertRuleTemplateName": "3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8",
"customDetails": {
"Actor": "Actor",
"ClientStatus": "ClientStatus",
"ClientVersion": "ClientVersion",
"DeviceKey": "DeviceKey",
"EventCount": "EventCount",
"LatestClientEvent": "LatestClientEvent",
"NpaStatus": "NpaStatus",
"OperatingSystem": "OperatingSystem",
"ServiceName": "ServiceName"
},
"description": "Detects Netskope Client devices where the user disabled the Netskope Internet Security\n(secure web gateway / CASB steering) service. All matching client-status events in the\n6-hour window are collected into a single alert, grouped per device, so repeated disable\nevents on the same device are reported once. A user disabling Internet Security bypasses\nweb, threat and data protection policies for that device.\n",
"displayName": "Netskope Client - Internet Security disabled by user",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "UserName",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "HostName",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "PublicIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml",
"query": "NetskopeClientStatus_CL\n| where TimeGenerated > ago(6h)\n| where last_seen_device_event_actor_name =~ \"USER\"\n and last_seen_device_event_service_name =~ \"Internet Security\"\n and last_seen_device_event_status_name =~ \"DISABLED\"\n| extend DeviceKey = case(\n isnotempty(device_hash), device_hash,\n isnotempty(guid), guid,\n isnotempty(device_id), device_id,\n host_info_hostname)\n| summarize\n EventCount = count(),\n FirstSeen = min(TimeGenerated),\n LastSeen = max(TimeGenerated),\n ClientEvents = make_set(last_seen_device_event_event_name, 10),\n arg_max(TimeGenerated,\n host_info_hostname,\n user_info_username,\n last_connected_from_public_ip,\n last_connected_from_private_ip,\n host_info_os_name,\n client_version,\n last_seen_device_event_actor_name,\n last_seen_device_event_service_name,\n last_seen_device_event_status_name,\n last_seen_device_event_status_v2_name,\n last_seen_device_event_npa_status_name,\n last_seen_device_event_event_name,\n last_seen_device_event_event_details)\n by DeviceKey\n| project\n LastSeen,\n FirstSeen,\n EventCount,\n DeviceKey,\n HostName = host_info_hostname,\n UserName = user_info_username,\n PublicIp = last_connected_from_public_ip,\n PrivateIp = last_connected_from_private_ip,\n OperatingSystem = host_info_os_name,\n ClientVersion = client_version,\n Actor = last_seen_device_event_actor_name,\n ServiceName = last_seen_device_event_service_name,\n ClientStatus = last_seen_device_event_status_name,\n ClientStatusV2 = last_seen_device_event_status_v2_name,\n NpaStatus = last_seen_device_event_npa_status_name,\n LatestClientEvent = last_seen_device_event_event_name,\n EventDetails = last_seen_device_event_event_details,\n ClientEvents\n| order by LastSeen desc\n",
"queryFrequency": "PT6H",
"queryPeriod": "PT6H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion"
],
"techniques": [
"T1562"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}