Anvilogic_Alerts_CL | where avl_rule_mode!='Warn'
version: 1.0.1
alertDetailsOverride:
alertTacticsColumnName: avl_mitre_tactic
alertDynamicProperties:
- value: avl_mitre_technique
alertProperty: Techniques
alertDisplayNameFormat: '{{avl_rule_id}} - {{avl_use_case_title}} - {{avl_use_case_type}}'
alertDescriptionFormat: |-
avl_rule_id: {{avl_rule_id}}
{{avl_definition}}
customDetails:
techniques: avl_mitre_technique
raw: raw
tactics: avl_mitre_tactic
incidentConfiguration:
groupingConfiguration:
enabled: false
reopenClosedIncident: false
lookbackDuration: PT5M
matchingMethod: AllEntities
createIncident: true
queryPeriod: 5m
severity: Medium
suppressionDuration: 1h
query: |
Anvilogic_Alerts_CL | where avl_rule_mode!='Warn'
tactics: []
id: 6ccc187a-42ee-4635-8bcc-3b299f8570df
eventGroupingSettings:
aggregationKind: AlertPerResult
queryFrequency: 5m
kind: Scheduled
relevantTechniques: []
requiredDataConnectors:
- connectorId: Anvilogic
dataTypes:
- Anvilogic_Alerts_CL
entityMappings:
- entityType: Account
fieldMappings:
- columnName: coi_account
identifier: Name
- columnName: src_nt_domain
identifier: NTDomain
- columnName: ssid
identifier: Sid
- entityType: Host
fieldMappings:
- columnName: coi_host
identifier: HostName
- entityType: IP
fieldMappings:
- columnName: coi_ip
identifier: Address
- entityType: URL
fieldMappings:
- columnName: url
identifier: Url
- entityType: CloudApplication
fieldMappings:
- columnName: coi_app
identifier: Name
- entityType: File
fieldMappings:
- columnName: file_name
identifier: Name
- columnName: file_path
identifier: Directory
- entityType: Process
fieldMappings:
- columnName: process_id
identifier: ProcessId
- columnName: process_exec
identifier: CommandLine
- entityType: RegistryKey
fieldMappings:
- columnName: registry_hive
identifier: Hive
- columnName: registry_key_name
identifier: Key
- entityType: RegistryValue
fieldMappings:
- columnName: registry_value_name
identifier: Name
- columnName: registry_value_data
identifier: Value
- columnName: registry_value_type
identifier: ValueType
suppressionEnabled: false
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Anvilogic/Analytic Rules/Anvilogic_Alerts.yaml
status: Available
triggerThreshold: 0
triggerOperator: gt
description: |
'Alert generated by Anvilogic.'
name: Anvilogic Alert