{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/650429cd-afc6-41a5-90e7-6e4a85b2335d')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/650429cd-afc6-41a5-90e7-6e4a85b2335d')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "CVE: {{CveId}} | Risk: {{RiskRating}} | State: {{ExploitationState}}",
          "alertDisplayNameFormat": "GTI CISA KEV: {{CveId}}"
        },
        "alertRuleTemplateName": "650429cd-afc6-41a5-90e7-6e4a85b2335d",
        "customDetails": {
          "AffectedProduct": "Product",
          "AffectedVendor": "Vendor",
          "CisaAddedDate": "CisaKnownExploitedAddedDate",
          "CisaDueDate": "CisaKnownExploitedDueDate",
          "CveId": "CveId",
          "Cvssv3Score": "Cvssv3Score",
          "EpssPercentile": "EpssPercentile",
          "EpssScore": "EpssScore",
          "ExploitState": "ExploitationState",
          "Priority": "Priority",
          "RansomwareUse": "CisaKnownExploitedRansomwareUse",
          "RiskRating": "RiskRating"
        },
        "description": "Detects vulnerabilities ingested from Google Threat Intelligence that are in the CISA Known\nExploited Vulnerabilities (KEV) catalog, meaning CISA has confirmed active exploitation and\nmandated remediation for federal agencies. Uses the explicit CisaKnownExploited field from the\nGTIVulnerabilities parser, with Tags-based fallback for coverage.\n",
        "displayName": "GTI - CISA Known Exploited Vulnerability Detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "VendorFixUrl",
                "identifier": "Url"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "CveId"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/Vulnerabilities/GTI_CISAKnownExploitedVulnerability.yaml",
        "query": "GTIVulnerabilities\n| where isnotempty(CisaKnownExploited)\n    or isnotempty(CisaKnownExploitedDueDate)\n    or isnotempty(CisaKnownExploitedAddedDate)\n    or isnotempty(CisaKnownExploitedRansomwareUse)\n    or (isnotempty(Tags) and tolower(tostring(Tags)) has_any (\"cisa-kev\", \"cisa exploited\", \"cisa_exploited\"))\n| extend Cvssv3Score = coalesce(Cvssv3xBaseScore, Cvssv3xTranslatedBaseScore)\n| extend\n    CisaKnownExploitedAddedDate = iif(isnotempty(CisaKnownExploitedAddedDate), datetime_add('second', toint(todouble(CisaKnownExploitedAddedDate)), datetime(1970-01-01)), datetime(null)),\n    CisaKnownExploitedDueDate   = iif(isnotempty(CisaKnownExploitedDueDate),   datetime_add('second', toint(todouble(CisaKnownExploitedDueDate)),   datetime(1970-01-01)), datetime(null))\n| extend\n    Vendor       = tostring(Cpes[0].start_cpe.vendor),\n    Product      = tostring(Cpes[0].start_cpe.product),\n    CpeVersion   = tostring(Cpes[0].start_cpe.version),\n    VendorFixUrl = coalesce(tostring(VendorFixReferences[0].url), tostring(VendorFixReferences[0]))\n| mv-apply _c = Cpes on (\n    where isnotnull(_c.start_cpe)\n    | summarize AffectedVendors  = make_set(tostring(_c.start_cpe.vendor)),\n                AffectedProducts = make_set(tostring(_c.start_cpe.product))\n  )\n| project\n    TimeGenerated,\n    CveId,\n    VulnName,\n    RiskRating,\n    Priority,\n    ExploitationState,\n    ExploitationConsequence,\n    Cvssv3Score,\n    Cvssv4xScore,\n    EpssScore,\n    EpssPercentile,\n    CisaKnownExploitedAddedDate,\n    CisaKnownExploitedDueDate,\n    CisaKnownExploitedRansomwareUse,\n    Vendor,\n    Product,\n    CpeVersion,\n    AffectedVendors,\n    AffectedProducts,\n    Description,\n    VendorFixUrl,\n    VendorFixReferences,\n    Tags,\n    Type\n",
        "queryFrequency": "PT10M",
        "queryPeriod": "PT10M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Execution",
          "Impact",
          "InitialAccess"
        ],
        "techniques": [
          "T1190",
          "T1203"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}
