Theom - Least priv large value shadow DB
| Id | 67b9ff50-5393-49d5-b66f-05b33e2f35d2 |
| Rulename | Theom - Least priv large value shadow DB |
| Description | “Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0032 (Theom has observed shadow (or clone) databases/tables that have a large financial value. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)” |
| Severity | High |
| Tactics | Collection |
| Techniques | T1560 T1530 |
| Required data connectors | Theom |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0033_Least_priv_large_value_shadow_DB.yaml |
| Version | 1.0.2 |
| Arm template | 67b9ff50-5393-49d5-b66f-05b33e2f35d2.json |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
relevantTechniques:
- T1560
- T1530
entityMappings:
- fieldMappings:
- columnName: customProps_AssetName_s
identifier: Name
entityType: CloudApplication
- fieldMappings:
- columnName: deepLink_s
identifier: Url
entityType: URL
version: 1.0.2
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0033_Least_priv_large_value_shadow_DB.yaml
description: |
"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0032 (Theom has observed shadow (or clone) databases/tables that have a large financial value. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)"
requiredDataConnectors:
- connectorId: Theom
dataTypes:
- TheomAlerts_CL
triggerOperator: gt
alertDetailsOverride:
alertDisplayNameFormat: 'Theom Alert ID: {{id_s}} '
alertDescriptionFormat: |2
Summary: {{summary_s}}
Additional info: {{details_s}}
Please investigate further on Theom UI at {{deepLink_s}}
eventGroupingSettings:
aggregationKind: AlertPerResult
id: 67b9ff50-5393-49d5-b66f-05b33e2f35d2
queryFrequency: 5m
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
severity: High
status: Available
queryPeriod: 5m
name: Theom - Least priv large value shadow DB
tactics:
- Collection
kind: Scheduled