Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Lookout - New Threat events found

Back
Id7593cc60-e294-402d-9202-279fb3c7d55f
RulenameLookout - New Threat events found.
DescriptionCreated to detect new Threat events from the data which is recently synced by Lookout Solution.
SeverityHigh
TacticsDiscovery
TechniquesT1057
Required data connectorsLookoutAPI
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Lookout/Analytic Rules/LookoutThreatEvent.yaml
Version1.0.1
Arm template7593cc60-e294-402d-9202-279fb3c7d55f.json
Deploy To Azure
Lookout_CL
| where details_action_s == 'DETECTED' and type_s == 'THREAT'
| extend DetailsPackageName = details_packageName_s
| extend TargetPlatform = target_platform_s
| extend TargetOsVersion = target_osVersion_s
| extend Type = type_s
| extend Severity = details_severity_s
| extend Classifications = details_classifications_s
| extend Platform = target_platform_s
customDetails:
  Platform: Platform
  Type: Type
  Classification: Classifications
  Severity: Severity
status: Available
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Lookout/Analytic Rules/LookoutThreatEvent.yaml
query: |
  Lookout_CL
  | where details_action_s == 'DETECTED' and type_s == 'THREAT'
  | extend DetailsPackageName = details_packageName_s
  | extend TargetPlatform = target_platform_s
  | extend TargetOsVersion = target_osVersion_s
  | extend Type = type_s
  | extend Severity = details_severity_s
  | extend Classifications = details_classifications_s
  | extend Platform = target_platform_s  
requiredDataConnectors:
- dataTypes:
  - Lookout_CL
  connectorId: LookoutAPI
tactics:
- Discovery
name: Lookout - New Threat events found.
relevantTechniques:
- T1057
severity: High
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: DetailsPackageName
  - identifier: OSFamily
    columnName: TargetPlatform
  - identifier: OSVersion
    columnName: TargetOsVersion
  entityType: Host
kind: Scheduled
queryFrequency: 1h
description: |
    'Created to detect new Threat events from the data which is recently synced by Lookout Solution.'
triggerThreshold: 0
triggerOperator: gt
version: 1.0.1
queryPeriod: 1h
id: 7593cc60-e294-402d-9202-279fb3c7d55f