Back
Id674429c9-a858-436c-95b8-5808024ebd01
RulenamePRODAFT USTA - Non-expired payment card exposed
DescriptionIdentifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a

payment card whose expiration date is still in the future. A non-expired card is

immediately usable for fraudulent transactions and is therefore higher risk than an

already-expired card. The full card number is never stored - only the BIN, last 4 digits,

brand, and length are retained. Prioritize reissue of the affected card with the issuing

bank and monitor for fraudulent activity.
SeverityHigh
TacticsImpact
TechniquesT1657
Required data connectorsPRODAFTUstaPCFICCPDefinition
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/NonExpiredPaymentCardExposed.yaml
Version1.0.0
Arm template674429c9-a858-436c-95b8-5808024ebd01.json
Deploy To Azure
PRODAFTUstaCompromisedCards
| where Created > ago(1h)
| where ExpirationDate > now()
| project
    TimeGenerated,
    Created,
    TicketId,
    CompanyName,
    CardBrand,
    CardBin,
    CardLast4,
    CardMasked,
    CardLength,
    ExpirationDate,
    Status
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 1h
    reopenClosedIncident: false
    matchingMethod: AnyAlert
    enabled: true
  createIncident: true
name: PRODAFT USTA - Non-expired payment card exposed
triggerOperator: gt
query: |
  PRODAFTUstaCompromisedCards
  | where Created > ago(1h)
  | where ExpirationDate > now()
  | project
      TimeGenerated,
      Created,
      TicketId,
      CompanyName,
      CardBrand,
      CardBin,
      CardLast4,
      CardMasked,
      CardLength,
      ExpirationDate,
      Status
queryFrequency: 1h
description: |
  'Identifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a
  payment card whose expiration date is still in the future. A non-expired card is
  immediately usable for fraudulent transactions and is therefore higher risk than an
  already-expired card. The full card number is never stored - only the BIN, last 4 digits,
  brand, and length are retained. Prioritize reissue of the affected card with the issuing
  bank and monitor for fraudulent activity.'
id: 674429c9-a858-436c-95b8-5808024ebd01
triggerThreshold: 0
queryPeriod: 1h
status: Available
kind: Scheduled
customDetails:
  Card: CardMasked
  Company: CompanyName
  Expiration: ExpirationDate
  Brand: CardBrand
  Ticket: TicketId
  Status: Status
relevantTechniques:
- T1657
severity: High
requiredDataConnectors:
- connectorId: PRODAFTUstaPCFICCPDefinition
  dataTypes:
  - PRODAFTUstaCompromisedCards_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/NonExpiredPaymentCardExposed.yaml
tactics:
- Impact
version: 1.0.0
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/674429c9-a858-436c-95b8-5808024ebd01')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/674429c9-a858-436c-95b8-5808024ebd01')]",
      "properties": {
        "alertRuleTemplateName": "674429c9-a858-436c-95b8-5808024ebd01",
        "customDetails": {
          "Brand": "CardBrand",
          "Card": "CardMasked",
          "Company": "CompanyName",
          "Expiration": "ExpirationDate",
          "Status": "Status",
          "Ticket": "TicketId"
        },
        "description": "'Identifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a\npayment card whose expiration date is still in the future. A non-expired card is\nimmediately usable for fraudulent transactions and is therefore higher risk than an\nalready-expired card. The full card number is never stored - only the BIN, last 4 digits,\nbrand, and length are retained. Prioritize reissue of the affected card with the issuing\nbank and monitor for fraudulent activity.'\n",
        "displayName": "PRODAFT USTA - Non-expired payment card exposed",
        "enabled": true,
        "entityMappings": null,
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT1H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/NonExpiredPaymentCardExposed.yaml",
        "query": "PRODAFTUstaCompromisedCards\n| where Created > ago(1h)\n| where ExpirationDate > now()\n| project\n    TimeGenerated,\n    Created,\n    TicketId,\n    CompanyName,\n    CardBrand,\n    CardBin,\n    CardLast4,\n    CardMasked,\n    CardLength,\n    ExpirationDate,\n    Status\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Impact"
        ],
        "techniques": [
          "T1657"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}