{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
      "properties": {
        "alertRuleTemplateName": "6909c70c-fb52-47a3-9eb9-3b8109b0b32a",
        "customDetails": null,
        "description": "Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.",
        "displayName": "Uniqkey - Sign-in from unfamiliar IP address",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "ActorEmail",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIpAddr",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT1H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml",
        "query": "let lookback = 14d;\nlet frequency = 1h;\nlet knownPairs =\n    UniqkeyEvents_CL\n    | where TimeGenerated between (ago(lookback) .. ago(frequency))\n    | where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n    | summarize by ActorEmail, SrcIpAddr;\nUniqkeyEvents_CL\n| where TimeGenerated > ago(frequency)\n| where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr\n| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr\n| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "Low",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "InitialAccess"
        ],
        "techniques": [
          "T1078"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}
