Back
Id48ef0be4-8240-4a03-bbb9-320b562d6ce4
RulenameD3 Smart SOAR - High or critical severity incident detected
DescriptionIdentifies when a D3 Smart SOAR incident with High or Critical severity is ingested. This helps security teams prioritize response to the most impactful incidents reported by D3 Smart SOAR.
SeverityHigh
TacticsImpact
TechniquesT1499
Required data connectorsD3SOARConnectorDefinition
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/D3SmartSOAR/Analytic%20Rules/D3SmartSOAR-HighOrCriticalSeverityIncident.yaml
Version1.0.0
Arm template48ef0be4-8240-4a03-bbb9-320b562d6ce4.json
Deploy To Azure
D3SOARIncidents_CL
| where TimeGenerated > ago(1h)
| where IncidentSeverity in ("High", "Critical")
| project
    TimeGenerated,
    IncidentNumber,
    IncidentTitle,
    IncidentSeverity,
    IncidentStatus,
    IncidentType,
    IncidentPriority,
    IncidentOwner,
    IncidentCreator,
    IncidentDescription,
    IncidentStage
name: D3 Smart SOAR - High or critical severity incident detected
triggerOperator: gt
query: |
  D3SOARIncidents_CL
  | where TimeGenerated > ago(1h)
  | where IncidentSeverity in ("High", "Critical")
  | project
      TimeGenerated,
      IncidentNumber,
      IncidentTitle,
      IncidentSeverity,
      IncidentStatus,
      IncidentType,
      IncidentPriority,
      IncidentOwner,
      IncidentCreator,
      IncidentDescription,
      IncidentStage
queryFrequency: 1h
description: |
  Identifies when a D3 Smart SOAR incident with High or Critical severity is ingested. This helps security teams prioritize response to the most impactful incidents reported by D3 Smart SOAR.
id: 48ef0be4-8240-4a03-bbb9-320b562d6ce4
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: D3SOARConnectorDefinition
  dataTypes:
  - D3SOARIncidents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/D3SmartSOAR/Analytic%20Rules/D3SmartSOAR-HighOrCriticalSeverityIncident.yaml
relevantTechniques:
- T1499
tactics:
- Impact
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: IncidentOwner
  entityType: Account
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/48ef0be4-8240-4a03-bbb9-320b562d6ce4')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/48ef0be4-8240-4a03-bbb9-320b562d6ce4')]",
      "properties": {
        "alertRuleTemplateName": "48ef0be4-8240-4a03-bbb9-320b562d6ce4",
        "customDetails": null,
        "description": "Identifies when a D3 Smart SOAR incident with High or Critical severity is ingested. This helps security teams prioritize response to the most impactful incidents reported by D3 Smart SOAR.\n",
        "displayName": "D3 Smart SOAR - High or critical severity incident detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "IncidentOwner",
                "identifier": "Name"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/D3SmartSOAR/Analytic%20Rules/D3SmartSOAR-HighOrCriticalSeverityIncident.yaml",
        "query": "D3SOARIncidents_CL\n| where TimeGenerated > ago(1h)\n| where IncidentSeverity in (\"High\", \"Critical\")\n| project\n    TimeGenerated,\n    IncidentNumber,\n    IncidentTitle,\n    IncidentSeverity,\n    IncidentStatus,\n    IncidentType,\n    IncidentPriority,\n    IncidentOwner,\n    IncidentCreator,\n    IncidentDescription,\n    IncidentStage\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Impact"
        ],
        "techniques": [
          "T1499"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}