Theom - Unencrypted public data stores
| Id | 6b93d8b1-40cf-4973-adaa-6f240df21ff1 |
| Rulename | Theom - Unencrypted public data stores |
| Description | “Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0005 (Theom has observed data stores that are both unencrypted and publicly accessible. Review if the data store and the data within should be publicly accessible. Additionally, encrypt the data at rest to comply with these CIS requirements)” |
| Severity | High |
| Tactics | Collection |
| Techniques | T1213 T1530 |
| Required data connectors | Theom |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0005_Unencrypted_public_data_stores.yaml |
| Version | 1.0.2 |
| Arm template | 6b93d8b1-40cf-4973-adaa-6f240df21ff1.json |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0005" and (priority_s == "P1" or priority_s == "P2")
name: Theom - Unencrypted public data stores
severity: High
description: |
"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0005 (Theom has observed data stores that are both unencrypted and publicly accessible. Review if the data store and the data within should be publicly accessible. Additionally, encrypt the data at rest to comply with these CIS requirements)"
version: 1.0.2
requiredDataConnectors:
- dataTypes:
- TheomAlerts_CL
connectorId: Theom
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
entityMappings:
- entityType: CloudApplication
fieldMappings:
- identifier: Name
columnName: customProps_AssetName_s
- entityType: URL
fieldMappings:
- identifier: Url
columnName: deepLink_s
kind: Scheduled
triggerThreshold: 0
status: Available
queryPeriod: 5m
alertDetailsOverride:
alertDescriptionFormat: |2
Summary: {{summary_s}}
Additional info: {{details_s}}
Please investigate further on Theom UI at {{deepLink_s}}
alertDisplayNameFormat: 'Theom Alert ID: {{id_s}} '
triggerOperator: gt
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0005" and (priority_s == "P1" or priority_s == "P2")
eventGroupingSettings:
aggregationKind: AlertPerResult
queryFrequency: 5m
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0005_Unencrypted_public_data_stores.yaml
id: 6b93d8b1-40cf-4973-adaa-6f240df21ff1