PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
severity: Informational
triggerOperator: gt
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Purview/Analytic Rules/MicrosoftPurviewSensitiveDataDiscoveredCustom.yaml
id: 79f296d9-e6e4-45dc-9ca7-1770955435fa
customDetails:
PurviewAccount: PurviewAccountName
AssetPath: AssetPath
LastScanTime: AssetLastScanTime
Classification: Classification
SourceRegion: SourceRegion
AssetName: AssetName
entityMappings:
- fieldMappings:
- identifier: ResourceId
columnName: SourcePath
entityType: AzureResource
- fieldMappings:
- identifier: Name
columnName: AssetName
entityType: File
- fieldMappings:
- identifier: Name
columnName: PurviewAccountName
entityType: Account
kind: Scheduled
tactics:
- Discovery
queryFrequency: 1d
requiredDataConnectors:
- connectorId: MicrosoftAzurePurview
dataTypes:
- PurviewDataSensitivityLogs
relevantTechniques:
- T1087
version: 1.0.1
description: |
'Customized query used to identify specific classifications and parameters that have been discovered on assets in the last 24 hours by Microsoft Purview. By default, the query identifies Social Security Numbers detected, but the specific classification monitored along with other data fields can be adjusted. A list of supported Microsoft Purview classifications can be found here: https://docs.microsoft.com/azure/purview/supported-classifications'
alertDetailsOverride:
alertDisplayNameFormat: Sensitive Data Discovered in the Last 24 Hours by Microsoft Purview
alertDescriptionFormat: Within the last 24 hours, Microsoft Purview scanned assets that contained classifications. The classifications discovered include {{Classification}}.
triggerThreshold: 0
query: |
PurviewDataSensitivityLogs
| where Classification contains "Social Security Number"
//| where SourceRegion == "westeurope"
//| where SourceType contains "Amazon"
| where TimeGenerated > ago(24h)
queryPeriod: 1d
name: Sensitive Data Discovered in the Last 24 Hours - Customized