Back
Id6909c70c-fb52-47a3-9eb9-3b8109b0b32a
RulenameUniqkey - Sign-in from unfamiliar IP address
DescriptionIdentifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.
SeverityLow
TacticsInitialAccess
TechniquesT1078
Required data connectorsUniqkeyEventsConnector
KindScheduled
Query frequency1h
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml
Version1.0.0
Arm template6909c70c-fb52-47a3-9eb9-3b8109b0b32a.json
Deploy To Azure
let lookback = 14d;
let frequency = 1h;
let knownPairs =
    UniqkeyEvents_CL
    | where TimeGenerated between (ago(lookback) .. ago(frequency))
    | where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
    | summarize by ActorEmail, SrcIpAddr;
UniqkeyEvents_CL
| where TimeGenerated > ago(frequency)
| where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr
| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr
| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 1h
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: Uniqkey - Sign-in from unfamiliar IP address
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.
id: 6909c70c-fb52-47a3-9eb9-3b8109b0b32a
triggerThreshold: 0
queryPeriod: 14d
query: |-
  let lookback = 14d;
  let frequency = 1h;
  let knownPairs =
      UniqkeyEvents_CL
      | where TimeGenerated between (ago(lookback) .. ago(frequency))
      | where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
      | summarize by ActorEmail, SrcIpAddr;
  UniqkeyEvents_CL
  | where TimeGenerated > ago(frequency)
  | where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
  | join kind=leftanti knownPairs on ActorEmail, SrcIpAddr
  | summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr
  | project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr
version: 1.0.0
requiredDataConnectors:
- connectorId: UniqkeyEventsConnector
  dataTypes:
  - UniqkeyEvents_CL
eventGroupingSettings:
  aggregationKind: SingleAlert
severity: Low
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml
relevantTechniques:
- T1078
tactics:
- InitialAccess
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: ActorEmail
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: SrcIpAddr
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
      "properties": {
        "alertRuleTemplateName": "6909c70c-fb52-47a3-9eb9-3b8109b0b32a",
        "customDetails": null,
        "description": "Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.",
        "displayName": "Uniqkey - Sign-in from unfamiliar IP address",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "ActorEmail",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIpAddr",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT1H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml",
        "query": "let lookback = 14d;\nlet frequency = 1h;\nlet knownPairs =\n    UniqkeyEvents_CL\n    | where TimeGenerated between (ago(lookback) .. ago(frequency))\n    | where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n    | summarize by ActorEmail, SrcIpAddr;\nUniqkeyEvents_CL\n| where TimeGenerated > ago(frequency)\n| where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr\n| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr\n| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "Low",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "InitialAccess"
        ],
        "techniques": [
          "T1078"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}