PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
query: |
PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
version: 1.0.1
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Purview/Analytic Rules/MicrosoftPurviewSensitiveDataDiscoveredCustom.yaml
triggerThreshold: 0
tactics:
- Discovery
customDetails:
SourceRegion: SourceRegion
AssetName: AssetName
PurviewAccount: PurviewAccountName
LastScanTime: AssetLastScanTime
AssetPath: AssetPath
Classification: Classification
entityMappings:
- entityType: AzureResource
fieldMappings:
- columnName: SourcePath
identifier: ResourceId
- entityType: File
fieldMappings:
- columnName: AssetName
identifier: Name
- entityType: Account
fieldMappings:
- columnName: PurviewAccountName
identifier: Name
kind: Scheduled
queryFrequency: 1d
name: Sensitive Data Discovered in the Last 24 Hours - Customized
description: |
'Customized query used to identify specific classifications and parameters that have been discovered on assets in the last 24 hours by Microsoft Purview. By default, the query identifies Social Security Numbers detected, but the specific classification monitored along with other data fields can be adjusted. A list of supported Microsoft Purview classifications can be found here: https://docs.microsoft.com/azure/purview/supported-classifications'
alertDetailsOverride:
alertDescriptionFormat: Within the last 24 hours, Microsoft Purview scanned assets that contained classifications. The classifications discovered include {{Classification}}.
alertDisplayNameFormat: Sensitive Data Discovered in the Last 24 Hours by Microsoft Purview
queryPeriod: 1d
triggerOperator: gt
id: 79f296d9-e6e4-45dc-9ca7-1770955435fa
relevantTechniques:
- T1087
severity: Informational
requiredDataConnectors:
- dataTypes:
- PurviewDataSensitivityLogs
connectorId: MicrosoftAzurePurview