Back
Id536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
RulenameGreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
DescriptionThis rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC.

This analytic rule uses ASIM and supports any built-in or custom source that supports the ASIM NetworkSession schema
SeverityMedium
TacticsCommandAndControl
TechniquesT1071
Required data connectorsAIVectraStream
AWSS3
AzureFirewall
AzureMonitor(VMInsights)
AzureNSG
CheckPoint
CiscoASA
CiscoAsaAma
CiscoMeraki
Corelight
Fortinet
GreyNoise2SentinelAPI
MicrosoftDefenderThreatIntelligence
MicrosoftSysmonForLinux
MicrosoftThreatProtection
PaloAltoNetworks
SecurityEvents
WindowsForwardedEvents
WindowsSecurityEvents
Zscaler
KindScheduled
Query frequency1h
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GreyNoiseThreatIntelligence/Analytic%20Rules/GreyNoise_IPEntity_imNetworkSession.yaml
Version1.0.4
Arm template536e8e5c-ce0e-575e-bcc9-aba8e7bf9316.json
Deploy To Azure
let dt_lookBack = 1h;
let ioc_lookBack = 14d;
// Fetch GreyNoise IPv4 indicators from the ThreatIntelIndicators (STIX 2.1) table.
// GreyNoise only publishes ipv4-addr patterns, so a single ObservableKey filter is sufficient.
let IP_TI = materialize (
  ThreatIntelIndicators
  | where TimeGenerated >= ago(ioc_lookBack)
  | where SourceSystem == 'GreyNoise'
  | where ObservableKey == 'ipv4-addr:value'
  // Take the latest row per indicator first, then evaluate its current state, so an
  // indicator that has since been deactivated cannot be resurrected by an older row.
  | summarize arg_max(TimeGenerated, *) by Id
  | where IsActive == true and IsDeleted == false and ValidUntil > now()
  | extend TI_ipEntity = ObservableValue
  | where isnotempty(TI_ipEntity)
  // Explicit projection keeps TimeGenerated and Type off the left side of the join, avoiding column collisions.
  // IsActive is retained because the lookups below use it as the match flag.
  | project IndicatorId = Id, TI_ipEntity, IsActive, ThreatType = tostring(Data.indicator_types[0]), IoCDescription = tostring(Data.description), Tags, Confidence, ValidFrom, ValidUntil
);
IP_TI
  // using innerunique to keep perf fast and result set low, we only need one match to indicate potential malicious activity that needs to be investigated
| join kind=innerunique
(
  _Im_NetworkSession (starttime=ago(dt_lookBack))
  | where isnotempty(SrcIpAddr)
  | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated) by SrcIpAddr, DstIpAddr, Dvc, EventProduct, EventVendor
  | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.SrcIpAddr == $right.TI_ipEntity
  | project-rename SrcMatch = IsActive
  | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.DstIpAddr == $right.TI_ipEntity
  | project-rename DstMatch = IsActive
  | where SrcMatch or DstMatch
  | extend
      IoCIP = iff(SrcMatch, SrcIpAddr, DstIpAddr),
      IoCDirection = iff(SrcMatch, "Source", "Destination")
)on $left.TI_ipEntity == $right.IoCIP
| where imNWS_mintime < ValidUntil
| project imNWS_mintime, imNWS_maxtime, IoCDescription, IndicatorId, ThreatType, ValidFrom, ValidUntil, Confidence, Tags, SrcIpAddr, DstIpAddr, IoCDirection, IoCIP, Dvc, EventVendor, EventProduct
name: GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: |
  'This rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC.
  This analytic rule uses [ASIM](https://aka.ms/AboutASIM) and supports any built-in or custom source that supports the ASIM NetworkSession schema'
id: 536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
triggerThreshold: 0
queryPeriod: 14d
query: |
  let dt_lookBack = 1h;
  let ioc_lookBack = 14d;
  // Fetch GreyNoise IPv4 indicators from the ThreatIntelIndicators (STIX 2.1) table.
  // GreyNoise only publishes ipv4-addr patterns, so a single ObservableKey filter is sufficient.
  let IP_TI = materialize (
    ThreatIntelIndicators
    | where TimeGenerated >= ago(ioc_lookBack)
    | where SourceSystem == 'GreyNoise'
    | where ObservableKey == 'ipv4-addr:value'
    // Take the latest row per indicator first, then evaluate its current state, so an
    // indicator that has since been deactivated cannot be resurrected by an older row.
    | summarize arg_max(TimeGenerated, *) by Id
    | where IsActive == true and IsDeleted == false and ValidUntil > now()
    | extend TI_ipEntity = ObservableValue
    | where isnotempty(TI_ipEntity)
    // Explicit projection keeps TimeGenerated and Type off the left side of the join, avoiding column collisions.
    // IsActive is retained because the lookups below use it as the match flag.
    | project IndicatorId = Id, TI_ipEntity, IsActive, ThreatType = tostring(Data.indicator_types[0]), IoCDescription = tostring(Data.description), Tags, Confidence, ValidFrom, ValidUntil
  );
  IP_TI
    // using innerunique to keep perf fast and result set low, we only need one match to indicate potential malicious activity that needs to be investigated
  | join kind=innerunique
  (
    _Im_NetworkSession (starttime=ago(dt_lookBack))
    | where isnotempty(SrcIpAddr)
    | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated) by SrcIpAddr, DstIpAddr, Dvc, EventProduct, EventVendor
    | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.SrcIpAddr == $right.TI_ipEntity
    | project-rename SrcMatch = IsActive
    | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.DstIpAddr == $right.TI_ipEntity
    | project-rename DstMatch = IsActive
    | where SrcMatch or DstMatch
    | extend
        IoCIP = iff(SrcMatch, SrcIpAddr, DstIpAddr),
        IoCDirection = iff(SrcMatch, "Source", "Destination")
  )on $left.TI_ipEntity == $right.IoCIP
  | where imNWS_mintime < ValidUntil
  | project imNWS_mintime, imNWS_maxtime, IoCDescription, IndicatorId, ThreatType, ValidFrom, ValidUntil, Confidence, Tags, SrcIpAddr, DstIpAddr, IoCDirection, IoCIP, Dvc, EventVendor, EventProduct
version: 1.0.4
customDetails:
  IoCExpirationTime: ValidUntil
  IndicatorId: IndicatorId
  EventEndTime: imNWS_maxtime
  IoCIPDirection: IoCDirection
  IoCDescription: IoCDescription
  EventStartTime: imNWS_mintime
  IoCTags: Tags
  IoCConfidenceScore: Confidence
  ThreatType: ThreatType
status: Available
tags:
- SchemaVersion: 0.2.4
  Schema: ASIMNetworkSession
severity: Medium
requiredDataConnectors:
- connectorId: AWSS3
  dataTypes:
  - AWSVPCFlow
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceNetworkEvents
- connectorId: SecurityEvents
  dataTypes:
  - SecurityEvent
- connectorId: WindowsSecurityEvents
  dataTypes:
  - SecurityEvent
- connectorId: WindowsForwardedEvents
  dataTypes:
  - WindowsEvent
- connectorId: Zscaler
  dataTypes:
  - CommonSecurityLog
- connectorId: MicrosoftSysmonForLinux
  dataTypes:
  - Syslog
- connectorId: PaloAltoNetworks
  dataTypes:
  - CommonSecurityLog
- connectorId: AzureMonitor(VMInsights)
  dataTypes:
  - VMConnection
- connectorId: AzureFirewall
  dataTypes:
  - AzureDiagnostics
- connectorId: AzureNSG
  dataTypes:
  - AzureDiagnostics
- connectorId: CiscoASA
  dataTypes:
  - CommonSecurityLog
- connectorId: CiscoAsaAma
  dataTypes:
  - CommonSecurityLog
- connectorId: Corelight
  dataTypes:
  - Corelight_CL
- connectorId: AIVectraStream
  dataTypes:
  - VectraStream
- connectorId: CheckPoint
  dataTypes:
  - CommonSecurityLog
- connectorId: Fortinet
  dataTypes:
  - CommonSecurityLog
- connectorId: MicrosoftDefenderThreatIntelligence
  dataTypes:
  - ThreatIntelIndicators
- connectorId: CiscoMeraki
  dataTypes:
  - Syslog
  - CiscoMerakiNativePoller
- connectorId: GreyNoise2SentinelAPI
  dataTypes:
  - ThreatIntelIndicators
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GreyNoiseThreatIntelligence/Analytic%20Rules/GreyNoise_IPEntity_imNetworkSession.yaml
alertDetailsOverride:
  alertDescriptionFormat: The {{IoCDirection}} address {{IoCIP}} of a network session  matched a known indicator of compromise of {{ThreatType}}. Consult the threat intelligence blade for more information on the indicator.
  alertDisplayNameFormat: A network session {{IoCDirection}} address {{IoCIP}} matched an IoC.
relevantTechniques:
- T1071
tactics:
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: IoCIP
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/536e8e5c-ce0e-575e-bcc9-aba8e7bf9316')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/536e8e5c-ce0e-575e-bcc9-aba8e7bf9316')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "The {{IoCDirection}} address {{IoCIP}} of a network session  matched a known indicator of compromise of {{ThreatType}}. Consult the threat intelligence blade for more information on the indicator.",
          "alertDisplayNameFormat": "A network session {{IoCDirection}} address {{IoCIP}} matched an IoC."
        },
        "alertRuleTemplateName": "536e8e5c-ce0e-575e-bcc9-aba8e7bf9316",
        "customDetails": {
          "EventEndTime": "imNWS_maxtime",
          "EventStartTime": "imNWS_mintime",
          "IndicatorId": "IndicatorId",
          "IoCConfidenceScore": "Confidence",
          "IoCDescription": "IoCDescription",
          "IoCExpirationTime": "ValidUntil",
          "IoCIPDirection": "IoCDirection",
          "IoCTags": "Tags",
          "ThreatType": "ThreatType"
        },
        "description": "'This rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC.\nThis analytic rule uses [ASIM](https://aka.ms/AboutASIM) and supports any built-in or custom source that supports the ASIM NetworkSession schema'\n",
        "displayName": "GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "IoCIP",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GreyNoiseThreatIntelligence/Analytic%20Rules/GreyNoise_IPEntity_imNetworkSession.yaml",
        "query": "let dt_lookBack = 1h;\nlet ioc_lookBack = 14d;\n// Fetch GreyNoise IPv4 indicators from the ThreatIntelIndicators (STIX 2.1) table.\n// GreyNoise only publishes ipv4-addr patterns, so a single ObservableKey filter is sufficient.\nlet IP_TI = materialize (\n  ThreatIntelIndicators\n  | where TimeGenerated >= ago(ioc_lookBack)\n  | where SourceSystem == 'GreyNoise'\n  | where ObservableKey == 'ipv4-addr:value'\n  // Take the latest row per indicator first, then evaluate its current state, so an\n  // indicator that has since been deactivated cannot be resurrected by an older row.\n  | summarize arg_max(TimeGenerated, *) by Id\n  | where IsActive == true and IsDeleted == false and ValidUntil > now()\n  | extend TI_ipEntity = ObservableValue\n  | where isnotempty(TI_ipEntity)\n  // Explicit projection keeps TimeGenerated and Type off the left side of the join, avoiding column collisions.\n  // IsActive is retained because the lookups below use it as the match flag.\n  | project IndicatorId = Id, TI_ipEntity, IsActive, ThreatType = tostring(Data.indicator_types[0]), IoCDescription = tostring(Data.description), Tags, Confidence, ValidFrom, ValidUntil\n);\nIP_TI\n  // using innerunique to keep perf fast and result set low, we only need one match to indicate potential malicious activity that needs to be investigated\n| join kind=innerunique\n(\n  _Im_NetworkSession (starttime=ago(dt_lookBack))\n  | where isnotempty(SrcIpAddr)\n  | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated) by SrcIpAddr, DstIpAddr, Dvc, EventProduct, EventVendor\n  | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.SrcIpAddr == $right.TI_ipEntity\n  | project-rename SrcMatch = IsActive\n  | lookup (IP_TI | project TI_ipEntity, IsActive) on $left.DstIpAddr == $right.TI_ipEntity\n  | project-rename DstMatch = IsActive\n  | where SrcMatch or DstMatch\n  | extend\n      IoCIP = iff(SrcMatch, SrcIpAddr, DstIpAddr),\n      IoCDirection = iff(SrcMatch, \"Source\", \"Destination\")\n)on $left.TI_ipEntity == $right.IoCIP\n| where imNWS_mintime < ValidUntil\n| project imNWS_mintime, imNWS_maxtime, IoCDescription, IndicatorId, ThreatType, ValidFrom, ValidUntil, Confidence, Tags, SrcIpAddr, DstIpAddr, IoCDirection, IoCIP, Dvc, EventVendor, EventProduct\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl"
        ],
        "tags": [
          {
            "Schema": "ASIMNetworkSession",
            "SchemaVersion": "0.2.4"
          }
        ],
        "techniques": [
          "T1071"
        ],
        "templateVersion": "1.0.4",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}