Analytic rule catalog
Sensitive Data Discovered in the Last 24 Hours - Customized
Back
| Id | 79f296d9-e6e4-45dc-9ca7-1770955435fa |
| Rulename | Sensitive Data Discovered in the Last 24 Hours - Customized |
| Description | Customized query used to identify specific classifications and parameters that have been discovered on assets in the last 24 hours by Microsoft Purview. By default, the query identifies Social Security Numbers detected, but the specific classification monitored along with other data fields can be adjusted. A list of supported Microsoft Purview classifications can be found here: https://docs.microsoft.com/azure/purview/supported-classifications |
| Severity | Informational |
| Tactics | Discovery |
| Techniques | T1087 |
| Required data connectors | MicrosoftAzurePurview |
| Kind | Scheduled |
| Query frequency | 1d |
| Query period | 1d |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Purview/Analytic%20Rules/MicrosoftPurviewSensitiveDataDiscoveredCustom.yaml |
| Version | 1.0.1 |
| Arm template | 79f296d9-e6e4-45dc-9ca7-1770955435fa.json |
PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
name: Sensitive Data Discovered in the Last 24 Hours - Customized
triggerOperator: gt
query: |
PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
queryFrequency: 1d
description: |
'Customized query used to identify specific classifications and parameters that have been discovered on assets in the last 24 hours by Microsoft Purview. By default, the query identifies Social Security Numbers detected, but the specific classification monitored along with other data fields can be adjusted. A list of supported Microsoft Purview classifications can be found here: https://docs.microsoft.com/azure/purview/supported-classifications'
id: 79f296d9-e6e4-45dc-9ca7-1770955435fa
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.1
kind: Scheduled
customDetails:
AssetPath: AssetPath
PurviewAccount: PurviewAccountName
AssetName: AssetName
Classification: Classification
SourceRegion: SourceRegion
LastScanTime: AssetLastScanTime
relevantTechniques:
- T1087
severity: Informational
requiredDataConnectors:
- connectorId: MicrosoftAzurePurview
dataTypes:
- PurviewDataSensitivityLogs
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Purview/Analytic%20Rules/MicrosoftPurviewSensitiveDataDiscoveredCustom.yaml
alertDetailsOverride:
alertDescriptionFormat: Within the last 24 hours, Microsoft Purview scanned assets that contained classifications. The classifications discovered include {{Classification}}.
alertDisplayNameFormat: Sensitive Data Discovered in the Last 24 Hours by Microsoft Purview
tactics:
- Discovery
entityMappings:
- fieldMappings:
- identifier: ResourceId
columnName: SourcePath
entityType: AzureResource
- fieldMappings:
- identifier: Name
columnName: AssetName
entityType: File
- fieldMappings:
- identifier: Name
columnName: PurviewAccountName
entityType: Account
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/79f296d9-e6e4-45dc-9ca7-1770955435fa')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/79f296d9-e6e4-45dc-9ca7-1770955435fa')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "Within the last 24 hours, Microsoft Purview scanned assets that contained classifications. The classifications discovered include {{Classification}}.",
"alertDisplayNameFormat": "Sensitive Data Discovered in the Last 24 Hours by Microsoft Purview"
},
"alertRuleTemplateName": "79f296d9-e6e4-45dc-9ca7-1770955435fa",
"customDetails": {
"AssetName": "AssetName",
"AssetPath": "AssetPath",
"Classification": "Classification",
"LastScanTime": "AssetLastScanTime",
"PurviewAccount": "PurviewAccountName",
"SourceRegion": "SourceRegion"
},
"description": "'Customized query used to identify specific classifications and parameters that have been discovered on assets in the last 24 hours by Microsoft Purview. By default, the query identifies Social Security Numbers detected, but the specific classification monitored along with other data fields can be adjusted. A list of supported Microsoft Purview classifications can be found here: https://docs.microsoft.com/azure/purview/supported-classifications'\n",
"displayName": "Sensitive Data Discovered in the Last 24 Hours - Customized",
"enabled": true,
"entityMappings": [
{
"entityType": "AzureResource",
"fieldMappings": [
{
"columnName": "SourcePath",
"identifier": "ResourceId"
}
]
},
{
"entityType": "File",
"fieldMappings": [
{
"columnName": "AssetName",
"identifier": "Name"
}
]
},
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "PurviewAccountName",
"identifier": "Name"
}
]
}
],
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Purview/Analytic%20Rules/MicrosoftPurviewSensitiveDataDiscoveredCustom.yaml",
"query": "PurviewDataSensitivityLogs\n| where Classification contains \"Social Security Number\"\n//| where SourceRegion == \"westeurope\"\n//| where SourceType contains \"Amazon\"\n| where TimeGenerated > ago(24h)\n",
"queryFrequency": "P1D",
"queryPeriod": "P1D",
"severity": "Informational",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Discovery"
],
"techniques": [
"T1087"
],
"templateVersion": "1.0.1",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}