Back
Id3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
RulenameNetskope Client - Internet Security disabled by user
DescriptionDetects Netskope Client devices where the user disabled the Netskope Internet Security

(secure web gateway / CASB steering) service. All matching client-status events in the

6-hour window are collected into a single alert, grouped per device, so repeated disable

events on the same device are reported once. A user disabling Internet Security bypasses

web, threat and data protection policies for that device.
SeverityMedium
TacticsDefenseEvasion
TechniquesT1562
Required data connectorsNetskopeClientStatus
KindScheduled
Query frequency6h
Query period6h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml
Version1.0.0
Arm template3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8.json
Deploy To Azure
NetskopeClientStatus_CL
| where TimeGenerated > ago(6h)
| where last_seen_device_event_actor_name =~ "USER"
    and last_seen_device_event_service_name =~ "Internet Security"
    and last_seen_device_event_status_name =~ "DISABLED"
| extend DeviceKey = case(
    isnotempty(device_hash), device_hash,
    isnotempty(guid), guid,
    isnotempty(device_id), device_id,
    host_info_hostname)
| summarize
    EventCount = count(),
    FirstSeen = min(TimeGenerated),
    LastSeen = max(TimeGenerated),
    ClientEvents = make_set(last_seen_device_event_event_name, 10),
    arg_max(TimeGenerated,
        host_info_hostname,
        user_info_username,
        last_connected_from_public_ip,
        last_connected_from_private_ip,
        host_info_os_name,
        client_version,
        last_seen_device_event_actor_name,
        last_seen_device_event_service_name,
        last_seen_device_event_status_name,
        last_seen_device_event_status_v2_name,
        last_seen_device_event_npa_status_name,
        last_seen_device_event_event_name,
        last_seen_device_event_event_details)
    by DeviceKey
| project
    LastSeen,
    FirstSeen,
    EventCount,
    DeviceKey,
    HostName = host_info_hostname,
    UserName = user_info_username,
    PublicIp = last_connected_from_public_ip,
    PrivateIp = last_connected_from_private_ip,
    OperatingSystem = host_info_os_name,
    ClientVersion = client_version,
    Actor = last_seen_device_event_actor_name,
    ServiceName = last_seen_device_event_service_name,
    ClientStatus = last_seen_device_event_status_name,
    ClientStatusV2 = last_seen_device_event_status_v2_name,
    NpaStatus = last_seen_device_event_npa_status_name,
    LatestClientEvent = last_seen_device_event_event_name,
    EventDetails = last_seen_device_event_event_details,
    ClientEvents
| order by LastSeen desc
name: Netskope Client - Internet Security disabled by user
triggerOperator: gt
query: |
  NetskopeClientStatus_CL
  | where TimeGenerated > ago(6h)
  | where last_seen_device_event_actor_name =~ "USER"
      and last_seen_device_event_service_name =~ "Internet Security"
      and last_seen_device_event_status_name =~ "DISABLED"
  | extend DeviceKey = case(
      isnotempty(device_hash), device_hash,
      isnotempty(guid), guid,
      isnotempty(device_id), device_id,
      host_info_hostname)
  | summarize
      EventCount = count(),
      FirstSeen = min(TimeGenerated),
      LastSeen = max(TimeGenerated),
      ClientEvents = make_set(last_seen_device_event_event_name, 10),
      arg_max(TimeGenerated,
          host_info_hostname,
          user_info_username,
          last_connected_from_public_ip,
          last_connected_from_private_ip,
          host_info_os_name,
          client_version,
          last_seen_device_event_actor_name,
          last_seen_device_event_service_name,
          last_seen_device_event_status_name,
          last_seen_device_event_status_v2_name,
          last_seen_device_event_npa_status_name,
          last_seen_device_event_event_name,
          last_seen_device_event_event_details)
      by DeviceKey
  | project
      LastSeen,
      FirstSeen,
      EventCount,
      DeviceKey,
      HostName = host_info_hostname,
      UserName = user_info_username,
      PublicIp = last_connected_from_public_ip,
      PrivateIp = last_connected_from_private_ip,
      OperatingSystem = host_info_os_name,
      ClientVersion = client_version,
      Actor = last_seen_device_event_actor_name,
      ServiceName = last_seen_device_event_service_name,
      ClientStatus = last_seen_device_event_status_name,
      ClientStatusV2 = last_seen_device_event_status_v2_name,
      NpaStatus = last_seen_device_event_npa_status_name,
      LatestClientEvent = last_seen_device_event_event_name,
      EventDetails = last_seen_device_event_event_details,
      ClientEvents
  | order by LastSeen desc
queryFrequency: 6h
description: |
  Detects Netskope Client devices where the user disabled the Netskope Internet Security
  (secure web gateway / CASB steering) service. All matching client-status events in the
  6-hour window are collected into a single alert, grouped per device, so repeated disable
  events on the same device are reported once. A user disabling Internet Security bypasses
  web, threat and data protection policies for that device.
id: 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
triggerThreshold: 0
queryPeriod: 6h
version: 1.0.0
kind: Scheduled
customDetails:
  DeviceKey: DeviceKey
  EventCount: EventCount
  Actor: Actor
  LatestClientEvent: LatestClientEvent
  ServiceName: ServiceName
  ClientVersion: ClientVersion
  OperatingSystem: OperatingSystem
  ClientStatus: ClientStatus
  NpaStatus: NpaStatus
status: Available
eventGroupingSettings:
  aggregationKind: SingleAlert
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeClientStatus
  dataTypes:
  - NetskopeClientStatus_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: UserName
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: HostName
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: PublicIp
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8')]",
      "properties": {
        "alertRuleTemplateName": "3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8",
        "customDetails": {
          "Actor": "Actor",
          "ClientStatus": "ClientStatus",
          "ClientVersion": "ClientVersion",
          "DeviceKey": "DeviceKey",
          "EventCount": "EventCount",
          "LatestClientEvent": "LatestClientEvent",
          "NpaStatus": "NpaStatus",
          "OperatingSystem": "OperatingSystem",
          "ServiceName": "ServiceName"
        },
        "description": "Detects Netskope Client devices where the user disabled the Netskope Internet Security\n(secure web gateway / CASB steering) service. All matching client-status events in the\n6-hour window are collected into a single alert, grouped per device, so repeated disable\nevents on the same device are reported once. A user disabling Internet Security bypasses\nweb, threat and data protection policies for that device.\n",
        "displayName": "Netskope Client - Internet Security disabled by user",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "UserName",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "PublicIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_InternetSecurityDisabledByUser.yaml",
        "query": "NetskopeClientStatus_CL\n| where TimeGenerated > ago(6h)\n| where last_seen_device_event_actor_name =~ \"USER\"\n    and last_seen_device_event_service_name =~ \"Internet Security\"\n    and last_seen_device_event_status_name =~ \"DISABLED\"\n| extend DeviceKey = case(\n    isnotempty(device_hash), device_hash,\n    isnotempty(guid), guid,\n    isnotempty(device_id), device_id,\n    host_info_hostname)\n| summarize\n    EventCount = count(),\n    FirstSeen = min(TimeGenerated),\n    LastSeen = max(TimeGenerated),\n    ClientEvents = make_set(last_seen_device_event_event_name, 10),\n    arg_max(TimeGenerated,\n        host_info_hostname,\n        user_info_username,\n        last_connected_from_public_ip,\n        last_connected_from_private_ip,\n        host_info_os_name,\n        client_version,\n        last_seen_device_event_actor_name,\n        last_seen_device_event_service_name,\n        last_seen_device_event_status_name,\n        last_seen_device_event_status_v2_name,\n        last_seen_device_event_npa_status_name,\n        last_seen_device_event_event_name,\n        last_seen_device_event_event_details)\n    by DeviceKey\n| project\n    LastSeen,\n    FirstSeen,\n    EventCount,\n    DeviceKey,\n    HostName = host_info_hostname,\n    UserName = user_info_username,\n    PublicIp = last_connected_from_public_ip,\n    PrivateIp = last_connected_from_private_ip,\n    OperatingSystem = host_info_os_name,\n    ClientVersion = client_version,\n    Actor = last_seen_device_event_actor_name,\n    ServiceName = last_seen_device_event_service_name,\n    ClientStatus = last_seen_device_event_status_name,\n    ClientStatusV2 = last_seen_device_event_status_v2_name,\n    NpaStatus = last_seen_device_event_npa_status_name,\n    LatestClientEvent = last_seen_device_event_event_name,\n    EventDetails = last_seen_device_event_event_details,\n    ClientEvents\n| order by LastSeen desc\n",
        "queryFrequency": "PT6H",
        "queryPeriod": "PT6H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}