Back
Id6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7
RulenameCyren High-Risk URL Indicators
DescriptionDetects high-risk URL indicators (risk score >= 80) from Cyren malware URL threat intelligence feeds in the last 24 hours.

These URLs are associated with malware distribution, phishing campaigns, or other malicious content hosting.
SeverityHigh
TacticsInitialAccess
Execution
TechniquesT1566
T1189
Required data connectorsCyrenThreatIntel
KindScheduled
Query frequency1h
Query period1d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyrenThreatIntelligence/Analytic%20Rules/Cyren%20-%20High%20Risk%20URL%20Indicators.yaml
Version1.0.0
Arm template6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7.json
Deploy To Azure
Cyren_Indicators_CL
| where TimeGenerated > ago(1d)
| where isnotempty(url_s)
| extend Risk = toint(risk_d)
| where Risk >= 80
| summarize 
    DetectionCount = count(), 
    MaxRisk = max(Risk), 
    Categories = make_set(category_s) 
  by URL = url_s, Domain = domain_s, Source = source_s
| where DetectionCount >= 1
| extend 
    MaliciousURL = URL,
    ThreatCategories = strcat_array(Categories, ", ")
suppressionDuration: 1h
name: Cyren High-Risk URL Indicators
suppressionEnabled: false
triggerOperator: gt
query: |
  Cyren_Indicators_CL
  | where TimeGenerated > ago(1d)
  | where isnotempty(url_s)
  | extend Risk = toint(risk_d)
  | where Risk >= 80
  | summarize 
      DetectionCount = count(), 
      MaxRisk = max(Risk), 
      Categories = make_set(category_s) 
    by URL = url_s, Domain = domain_s, Source = source_s
  | where DetectionCount >= 1
  | extend 
      MaliciousURL = URL,
      ThreatCategories = strcat_array(Categories, ", ")
queryFrequency: 1h
description: |
  'Detects high-risk URL indicators (risk score >= 80) from Cyren malware URL threat intelligence feeds in the last 24 hours.
  These URLs are associated with malware distribution, phishing campaigns, or other malicious content hosting.'
id: 6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.0
kind: Scheduled
customDetails:
  Domain: Domain
  RiskScore: MaxRisk
  Categories: ThreatCategories
  Source: Source
  DetectionCount: DetectionCount
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: CyrenThreatIntel
  dataTypes:
  - Cyren_Indicators_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyrenThreatIntelligence/Analytic%20Rules/Cyren%20-%20High%20Risk%20URL%20Indicators.yaml
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 1d
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
    groupByEntities:
    - URL
  createIncident: true
relevantTechniques:
- T1566
- T1189
tactics:
- InitialAccess
- Execution
entityMappings:
- fieldMappings:
  - identifier: Url
    columnName: MaliciousURL
  entityType: URL
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7')]",
      "properties": {
        "alertRuleTemplateName": "6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7",
        "customDetails": {
          "Categories": "ThreatCategories",
          "DetectionCount": "DetectionCount",
          "Domain": "Domain",
          "RiskScore": "MaxRisk",
          "Source": "Source"
        },
        "description": "'Detects high-risk URL indicators (risk score >= 80) from Cyren malware URL threat intelligence feeds in the last 24 hours.\nThese URLs are associated with malware distribution, phishing campaigns, or other malicious content hosting.'\n",
        "displayName": "Cyren High-Risk URL Indicators",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "MaliciousURL",
                "identifier": "Url"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByEntities": [
              "URL"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyrenThreatIntelligence/Analytic%20Rules/Cyren%20-%20High%20Risk%20URL%20Indicators.yaml",
        "query": "Cyren_Indicators_CL\n| where TimeGenerated > ago(1d)\n| where isnotempty(url_s)\n| extend Risk = toint(risk_d)\n| where Risk >= 80\n| summarize \n    DetectionCount = count(), \n    MaxRisk = max(Risk), \n    Categories = make_set(category_s) \n  by URL = url_s, Domain = domain_s, Source = source_s\n| where DetectionCount >= 1\n| extend \n    MaliciousURL = URL,\n    ThreatCategories = strcat_array(Categories, \", \")\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P1D",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Execution",
          "InitialAccess"
        ],
        "techniques": [
          "T1189",
          "T1566"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}