Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Radiflow - Exploit Detected

Back
Id6c028ebd-03ca-41cb-bce7-5727ddb43731
RulenameRadiflow - Exploit Detected
DescriptionGenerates an incident when the use of an exploit is detected by Radiflow’s iSID.
SeverityHigh
TacticsInitialAccess
PrivilegeEscalation
LateralMovement
TechniquesT0819
T0866
T0890
Required data connectorsRadiflowIsid
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Radiflow/Analytic Rules/RadiflowExploitDetected.yaml
Version1.0.0
Arm template6c028ebd-03ca-41cb-bce7-5727ddb43731.json
Deploy To Azure
RadiflowEvent
| where DeviceProduct =~ 'iSID'
| where
    (
        EventClassID in (34, 53, 67, 68, 69, 70, 71, 179)
        or EventMessage has 'Exploit'
    )
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Radiflow/Analytic Rules/RadiflowExploitDetected.yaml
query: |
  RadiflowEvent
  | where DeviceProduct =~ 'iSID'
  | where
      (
          EventClassID in (34, 53, 67, 68, 69, 70, 71, 179)
          or EventMessage has 'Exploit'
      )  
suppressionDuration: 5h
suppressionEnabled: false
kind: Scheduled
entityMappings:
- entityType: Host
  fieldMappings:
  - identifier: HostName
    columnName: SourceHostName
  - identifier: NetBiosName
    columnName: SourceHostName
- entityType: Host
  fieldMappings:
  - identifier: HostName
    columnName: DestinationHostName
  - identifier: NetBiosName
    columnName: DestinationHostName
- entityType: IP
  fieldMappings:
  - identifier: Address
    columnName: SourceIP
- entityType: IP
  fieldMappings:
  - identifier: Address
    columnName: DestinationIP
triggerOperator: gt
requiredDataConnectors:
- dataTypes:
  - RadiflowEvent
  connectorId: RadiflowIsid
tactics:
- InitialAccess
- PrivilegeEscalation
- LateralMovement
triggerThreshold: 0
description: |
    'Generates an incident when the use of an exploit is detected by Radiflow's iSID.'
queryPeriod: 1h
version: 1.0.0
queryFrequency: 1h
severity: High
alertDetailsOverride:
  alertDisplayNameFormat: 'Exploit Detected: {{EventMessage}}'
  alertSeverityColumnName: EventSeverity
  alertDynamicProperties: []
  alertDescriptionFormat: "A possible exploit attempt has been detected. Check the details of this incident for further information.\n\nMessage: {{EventMessage}}\nSource device: {{SourceIP}} \nDestination device (if any): {{DestinationIP}} "
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    groupByEntities: []
    reopenClosedIncident: false
    groupByAlertDetails: []
    matchingMethod: AllEntities
    lookbackDuration: 1h
    groupByCustomDetails: []
    enabled: true
customDetails:
  Protocol: Protocol
  DestinationIP: DestinationIP
  DestinationType: DestinationType
  DestinationHostName: DestinationHostName
  SourceVLAN: SourceVLAN
  SourceVendor: SourceVendor
  SourceMAC: SourceMACAddress
  SourceHostName: SourceHostName
  SourceType: SourceType
  SourceIP: SourceIP
  DestinationVendor: DestinationVendor
  DestinationMAC: DestinationMACAddress
  Port: Port
name: Radiflow - Exploit Detected
id: 6c028ebd-03ca-41cb-bce7-5727ddb43731
eventGroupingSettings:
  aggregationKind: AlertPerResult
status: Available
relevantTechniques:
- T0819
- T0866
- T0890