Analytic rule catalog
Uniqkey - Sign-in from unfamiliar IP address
Back
| Id | 6909c70c-fb52-47a3-9eb9-3b8109b0b32a |
| Rulename | Uniqkey - Sign-in from unfamiliar IP address |
| Description | Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required. |
| Severity | Low |
| Tactics | InitialAccess |
| Techniques | T1078 |
| Required data connectors | UniqkeyEventsConnector |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 14d |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml |
| Version | 1.0.0 |
| Arm template | 6909c70c-fb52-47a3-9eb9-3b8109b0b32a.json |
let lookback = 14d;
let frequency = 1h;
let knownPairs =
UniqkeyEvents_CL
| where TimeGenerated between (ago(lookback) .. ago(frequency))
| where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
| summarize by ActorEmail, SrcIpAddr;
UniqkeyEvents_CL
| where TimeGenerated > ago(frequency)
| where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr
| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr
| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr
incidentConfiguration:
groupingConfiguration:
lookbackDuration: 1h
reopenClosedIncident: false
matchingMethod: AllEntities
enabled: true
createIncident: true
name: Uniqkey - Sign-in from unfamiliar IP address
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.
id: 6909c70c-fb52-47a3-9eb9-3b8109b0b32a
triggerThreshold: 0
queryPeriod: 14d
query: |-
let lookback = 14d;
let frequency = 1h;
let knownPairs =
UniqkeyEvents_CL
| where TimeGenerated between (ago(lookback) .. ago(frequency))
| where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
| summarize by ActorEmail, SrcIpAddr;
UniqkeyEvents_CL
| where TimeGenerated > ago(frequency)
| where Category == "authentication" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)
| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr
| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr
| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr
version: 1.0.0
requiredDataConnectors:
- connectorId: UniqkeyEventsConnector
dataTypes:
- UniqkeyEvents_CL
eventGroupingSettings:
aggregationKind: SingleAlert
severity: Low
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml
relevantTechniques:
- T1078
tactics:
- InitialAccess
entityMappings:
- fieldMappings:
- identifier: FullName
columnName: ActorEmail
entityType: Account
- fieldMappings:
- identifier: Address
columnName: SrcIpAddr
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/6909c70c-fb52-47a3-9eb9-3b8109b0b32a')]",
"properties": {
"alertRuleTemplateName": "6909c70c-fb52-47a3-9eb9-3b8109b0b32a",
"customDetails": null,
"description": "Identifies successful Uniqkey sign-ins (browser extension, mobile, web or desktop) originating from an IP address that has not been observed for that user during the trailing 14 days. A new source address can indicate session hijacking or use of stolen master credentials, particularly when combined with an unusual client system. Uniqkey audits successful authentications only, so pair this rule with identity-provider telemetry if failed sign-in coverage is required.",
"displayName": "Uniqkey - Sign-in from unfamiliar IP address",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "ActorEmail",
"identifier": "FullName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIpAddr",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"lookbackDuration": "PT1H",
"matchingMethod": "AllEntities",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Sign-in%20from%20unfamiliar%20IP%20address.yaml",
"query": "let lookback = 14d;\nlet frequency = 1h;\nlet knownPairs =\n UniqkeyEvents_CL\n | where TimeGenerated between (ago(lookback) .. ago(frequency))\n | where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n | summarize by ActorEmail, SrcIpAddr;\nUniqkeyEvents_CL\n| where TimeGenerated > ago(frequency)\n| where Category == \"authentication\" and isnotempty(SrcIpAddr) and isnotempty(ActorEmail)\n| join kind=leftanti knownPairs on ActorEmail, SrcIpAddr\n| summarize arg_max(TimeGenerated, Action, ActionId, ActorType, ClientSystem) by ActorEmail, SrcIpAddr\n| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, ClientSystem, SrcIpAddr",
"queryFrequency": "PT1H",
"queryPeriod": "P14D",
"severity": "Low",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"InitialAccess"
],
"techniques": [
"T1078"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}