Back
Id4d284d59-1ce5-4ea7-8e97-52256b95aa10
RulenameGTI - Actively Exploited Vulnerability Detected
DescriptionDetects vulnerabilities ingested from Google Threat Intelligence where the exploitation state is

Confirmed or Wide, indicating the vulnerability is being actively exploited in the wild. Fires when

such a record is ingested via the GTIVulnerabilities parser, prompting analyst triage and remediation.
SeverityHigh
TacticsInitialAccess
Execution
Impact
TechniquesT1190
T1203
T1486
Required data connectorsGTIVulnerabilitiesConnector
KindScheduled
Query frequency10m
Query period10m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/Vulnerabilities/GTI_ActivelyExploitedVulnerability.yaml
Version1.0.0
Arm template4d284d59-1ce5-4ea7-8e97-52256b95aa10.json
Deploy To Azure
GTIVulnerabilities
| where ExploitationState in ("Confirmed", "Wide")
| extend Cvssv3Score = coalesce(Cvssv3xBaseScore, Cvssv3xTranslatedBaseScore)
| extend
    Vendor       = tostring(Cpes[0].start_cpe.vendor),
    Product      = tostring(Cpes[0].start_cpe.product),
    CpeVersion   = tostring(Cpes[0].start_cpe.version),
    VendorFixUrl = coalesce(tostring(VendorFixReferences[0].url), tostring(VendorFixReferences[0]))
| mv-apply _c = Cpes on (
    where isnotnull(_c.start_cpe)
    | summarize AffectedVendors  = make_set(tostring(_c.start_cpe.vendor)),
                AffectedProducts = make_set(tostring(_c.start_cpe.product))
  )
| project
    TimeGenerated,
    CveId,
    VulnName,
    ExploitationState,
    ExploitationConsequence,
    ExploitReleaseDate,
    FirstExploitation,
    Cvssv3Score,
    Cvssv4xScore,
    EpssScore,
    EpssPercentile,
    Cvssv4xThreatExploitMaturity,
    RiskRating,
    Priority,
    RecentActivityRelativeChange,
    Vendor,
    Product,
    CpeVersion,
    AffectedVendors,
    AffectedProducts,
    Description,
    VendorFixUrl,
    VendorFixReferences,
    Tags,
    Type
incidentConfiguration:
  groupingConfiguration:
    groupByCustomDetails:
    - CveId
    lookbackDuration: P1D
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
  createIncident: true
name: GTI - Actively Exploited Vulnerability Detected
triggerOperator: gt
query: |
  GTIVulnerabilities
  | where ExploitationState in ("Confirmed", "Wide")
  | extend Cvssv3Score = coalesce(Cvssv3xBaseScore, Cvssv3xTranslatedBaseScore)
  | extend
      Vendor       = tostring(Cpes[0].start_cpe.vendor),
      Product      = tostring(Cpes[0].start_cpe.product),
      CpeVersion   = tostring(Cpes[0].start_cpe.version),
      VendorFixUrl = coalesce(tostring(VendorFixReferences[0].url), tostring(VendorFixReferences[0]))
  | mv-apply _c = Cpes on (
      where isnotnull(_c.start_cpe)
      | summarize AffectedVendors  = make_set(tostring(_c.start_cpe.vendor)),
                  AffectedProducts = make_set(tostring(_c.start_cpe.product))
    )
  | project
      TimeGenerated,
      CveId,
      VulnName,
      ExploitationState,
      ExploitationConsequence,
      ExploitReleaseDate,
      FirstExploitation,
      Cvssv3Score,
      Cvssv4xScore,
      EpssScore,
      EpssPercentile,
      Cvssv4xThreatExploitMaturity,
      RiskRating,
      Priority,
      RecentActivityRelativeChange,
      Vendor,
      Product,
      CpeVersion,
      AffectedVendors,
      AffectedProducts,
      Description,
      VendorFixUrl,
      VendorFixReferences,
      Tags,
      Type
queryFrequency: 10m
description: |
  Detects vulnerabilities ingested from Google Threat Intelligence where the exploitation state is
  Confirmed or Wide, indicating the vulnerability is being actively exploited in the wild. Fires when
  such a record is ingested via the GTIVulnerabilities parser, prompting analyst triage and remediation.
id: 4d284d59-1ce5-4ea7-8e97-52256b95aa10
triggerThreshold: 0
queryPeriod: 10m
version: 1.0.0
kind: Scheduled
customDetails:
  ExploitState: ExploitationState
  AffectedProduct: Product
  ExploitConsequence: ExploitationConsequence
  ExploitMaturity: Cvssv4xThreatExploitMaturity
  EpssScore: EpssScore
  CveId: CveId
  Cvssv4Score: Cvssv4xScore
  AffectedVendor: Vendor
  EpssPercentile: EpssPercentile
  Cvssv3Score: Cvssv3Score
  RiskRating: RiskRating
  Priority: Priority
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: GTIVulnerabilitiesConnector
  dataTypes:
  - GTI_Vulnerabilities_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/Vulnerabilities/GTI_ActivelyExploitedVulnerability.yaml
alertDetailsOverride:
  alertDescriptionFormat: 'CVE: {{CveId}} | State: {{ExploitationState}} | Risk: {{RiskRating}}'
  alertDisplayNameFormat: 'GTI Actively Exploited: {{CveId}} ({{ExploitationState}})'
relevantTechniques:
- T1190
- T1203
- T1486
tactics:
- InitialAccess
- Execution
- Impact
entityMappings:
- fieldMappings:
  - identifier: Url
    columnName: VendorFixUrl
  entityType: URL
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/4d284d59-1ce5-4ea7-8e97-52256b95aa10')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/4d284d59-1ce5-4ea7-8e97-52256b95aa10')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "CVE: {{CveId}} | State: {{ExploitationState}} | Risk: {{RiskRating}}",
          "alertDisplayNameFormat": "GTI Actively Exploited: {{CveId}} ({{ExploitationState}})"
        },
        "alertRuleTemplateName": "4d284d59-1ce5-4ea7-8e97-52256b95aa10",
        "customDetails": {
          "AffectedProduct": "Product",
          "AffectedVendor": "Vendor",
          "CveId": "CveId",
          "Cvssv3Score": "Cvssv3Score",
          "Cvssv4Score": "Cvssv4xScore",
          "EpssPercentile": "EpssPercentile",
          "EpssScore": "EpssScore",
          "ExploitConsequence": "ExploitationConsequence",
          "ExploitMaturity": "Cvssv4xThreatExploitMaturity",
          "ExploitState": "ExploitationState",
          "Priority": "Priority",
          "RiskRating": "RiskRating"
        },
        "description": "Detects vulnerabilities ingested from Google Threat Intelligence where the exploitation state is\nConfirmed or Wide, indicating the vulnerability is being actively exploited in the wild. Fires when\nsuch a record is ingested via the GTIVulnerabilities parser, prompting analyst triage and remediation.\n",
        "displayName": "GTI - Actively Exploited Vulnerability Detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "VendorFixUrl",
                "identifier": "Url"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "CveId"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/Vulnerabilities/GTI_ActivelyExploitedVulnerability.yaml",
        "query": "GTIVulnerabilities\n| where ExploitationState in (\"Confirmed\", \"Wide\")\n| extend Cvssv3Score = coalesce(Cvssv3xBaseScore, Cvssv3xTranslatedBaseScore)\n| extend\n    Vendor       = tostring(Cpes[0].start_cpe.vendor),\n    Product      = tostring(Cpes[0].start_cpe.product),\n    CpeVersion   = tostring(Cpes[0].start_cpe.version),\n    VendorFixUrl = coalesce(tostring(VendorFixReferences[0].url), tostring(VendorFixReferences[0]))\n| mv-apply _c = Cpes on (\n    where isnotnull(_c.start_cpe)\n    | summarize AffectedVendors  = make_set(tostring(_c.start_cpe.vendor)),\n                AffectedProducts = make_set(tostring(_c.start_cpe.product))\n  )\n| project\n    TimeGenerated,\n    CveId,\n    VulnName,\n    ExploitationState,\n    ExploitationConsequence,\n    ExploitReleaseDate,\n    FirstExploitation,\n    Cvssv3Score,\n    Cvssv4xScore,\n    EpssScore,\n    EpssPercentile,\n    Cvssv4xThreatExploitMaturity,\n    RiskRating,\n    Priority,\n    RecentActivityRelativeChange,\n    Vendor,\n    Product,\n    CpeVersion,\n    AffectedVendors,\n    AffectedProducts,\n    Description,\n    VendorFixUrl,\n    VendorFixReferences,\n    Tags,\n    Type\n",
        "queryFrequency": "PT10M",
        "queryPeriod": "PT10M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Execution",
          "Impact",
          "InitialAccess"
        ],
        "techniques": [
          "T1190",
          "T1203",
          "T1486"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}