Analytic rule catalog
Lookout - Critical Smishing and Phishing Alerts v2
Back
| Id | 7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e |
| Rulename | Lookout - Critical Smishing and Phishing Alerts (v2) |
| Description | Detects critical smishing (SMS phishing) and phishing alerts from Lookout Mobile Risk API v2. This rule identifies sophisticated social engineering attacks including CEO fraud, credential harvesting, and malicious link campaigns targeting mobile devices. Leverages enhanced v2 smishing detection capabilities for comprehensive mobile threat protection. |
| Severity | High |
| Tactics | InitialAccess CredentialAccess Collection Discovery |
| Techniques | T1660 T1417 T1423 |
| Required data connectors | LookoutAPI |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 15m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Lookout/Analytic%20Rules/LookoutSmishingAlertV2.yaml |
| Version | 2.0.3 |
| Arm template | 7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e.json |
LookoutEvents
| where EventType == "SMISHING_ALERT"
| where SmishingAlertSeverity in ("CRITICAL", "HIGH")
| where SmishingAlertType in ("PHISHING_DETECTION", "FRAUD_DETECTION", "CREDENTIAL_HARVESTING")
| extend
AlertRiskScore = case(
SmishingAlertSeverity == "CRITICAL", 10,
SmishingAlertSeverity == "HIGH", 8,
SmishingAlertSeverity == "MEDIUM", 5,
SmishingAlertSeverity == "LOW", 2,
1
),
ThreatCategory = case(
SmishingAlertType == "PHISHING_DETECTION", "Phishing",
SmishingAlertType == "FRAUD_DETECTION", "Fraud",
SmishingAlertType == "CREDENTIAL_HARVESTING", "Credential Theft",
SmishingAlertType == "MALICIOUS_LINK", "Malicious Link",
"Other"
),
ImpersonationRisk = case(
SmishingAlertDescription has "CEO" or SmishingAlertDescription has "executive", "Executive Impersonation",
SmishingAlertDescription has "IT" or SmishingAlertDescription has "support", "IT Support Impersonation",
SmishingAlertDescription has "bank" or SmishingAlertDescription has "financial", "Financial Impersonation",
SmishingAlertDescription has "delivery" or SmishingAlertDescription has "package", "Delivery Impersonation",
"Generic Phishing"
)
| extend DeviceRiskLevel = case(
DeviceSecurityStatus == "THREATS_HIGH", "High",
DeviceSecurityStatus == "THREATS_MEDIUM", "Medium",
DeviceSecurityStatus == "THREATS_LOW", "Low",
"Unknown"
)
| extend CampaignIndicators = case(
AlertRiskScore >= 8 and DeviceRiskLevel == "High", "Targeted Campaign",
AlertRiskScore >= 6 and ImpersonationRisk != "Generic Phishing", "Sophisticated Attack",
AlertRiskScore >= 5, "Coordinated Threat",
"Isolated Incident"
)
| project
TimeGenerated,
EventId,
SmishingAlertId,
SmishingAlertType,
SmishingAlertSeverity,
SmishingAlertDescription,
AlertRiskScore,
ThreatCategory,
ImpersonationRisk,
CampaignIndicators,
DeviceGuid,
DevicePlatform,
DeviceOSVersion,
DeviceManufacturer,
DeviceModel,
DeviceEmailAddress,
DeviceSecurityStatus,
DeviceRiskLevel,
TargetEmailAddress,
TargetPlatform,
ActorType,
ActorGuid,
ChangeType
triggerThreshold: 0
suppressionDuration: PT1H
incidentConfiguration:
createIncident: true
groupingConfiguration:
reopenClosedIncident: false
groupByAlertDetails:
- SmishAlertType
- DeviceGuid
matchingMethod: Selected
groupByEntities:
- Account
- Host
enabled: true
groupByCustomDetails:
- ThreatCategory
- ImpersonationRisk
- CampaignIndicators
lookbackDuration: P1D
kind: Scheduled
description: |
'Detects critical smishing (SMS phishing) and phishing alerts from Lookout Mobile Risk API v2. This rule identifies sophisticated social engineering attacks including CEO fraud, credential harvesting, and malicious link campaigns targeting mobile devices. Leverages enhanced v2 smishing detection capabilities for comprehensive mobile threat protection.'
queryFrequency: 5m
triggerOperator: gt
relevantTechniques:
- T1660
- T1417
- T1423
entityMappings:
- fieldMappings:
- identifier: FullName
columnName: DeviceEmailAddress
- identifier: Name
columnName: TargetEmailAddress
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: DeviceGuid
- identifier: OSFamily
columnName: DevicePlatform
- identifier: OSVersion
columnName: DeviceOSVersion
entityType: Host
- fieldMappings:
- identifier: Url
columnName: SmishingAlertDescription
entityType: URL
id: 7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e
version: 2.0.3
query: |
LookoutEvents
| where EventType == "SMISHING_ALERT"
| where SmishingAlertSeverity in ("CRITICAL", "HIGH")
| where SmishingAlertType in ("PHISHING_DETECTION", "FRAUD_DETECTION", "CREDENTIAL_HARVESTING")
| extend
AlertRiskScore = case(
SmishingAlertSeverity == "CRITICAL", 10,
SmishingAlertSeverity == "HIGH", 8,
SmishingAlertSeverity == "MEDIUM", 5,
SmishingAlertSeverity == "LOW", 2,
1
),
ThreatCategory = case(
SmishingAlertType == "PHISHING_DETECTION", "Phishing",
SmishingAlertType == "FRAUD_DETECTION", "Fraud",
SmishingAlertType == "CREDENTIAL_HARVESTING", "Credential Theft",
SmishingAlertType == "MALICIOUS_LINK", "Malicious Link",
"Other"
),
ImpersonationRisk = case(
SmishingAlertDescription has "CEO" or SmishingAlertDescription has "executive", "Executive Impersonation",
SmishingAlertDescription has "IT" or SmishingAlertDescription has "support", "IT Support Impersonation",
SmishingAlertDescription has "bank" or SmishingAlertDescription has "financial", "Financial Impersonation",
SmishingAlertDescription has "delivery" or SmishingAlertDescription has "package", "Delivery Impersonation",
"Generic Phishing"
)
| extend DeviceRiskLevel = case(
DeviceSecurityStatus == "THREATS_HIGH", "High",
DeviceSecurityStatus == "THREATS_MEDIUM", "Medium",
DeviceSecurityStatus == "THREATS_LOW", "Low",
"Unknown"
)
| extend CampaignIndicators = case(
AlertRiskScore >= 8 and DeviceRiskLevel == "High", "Targeted Campaign",
AlertRiskScore >= 6 and ImpersonationRisk != "Generic Phishing", "Sophisticated Attack",
AlertRiskScore >= 5, "Coordinated Threat",
"Isolated Incident"
)
| project
TimeGenerated,
EventId,
SmishingAlertId,
SmishingAlertType,
SmishingAlertSeverity,
SmishingAlertDescription,
AlertRiskScore,
ThreatCategory,
ImpersonationRisk,
CampaignIndicators,
DeviceGuid,
DevicePlatform,
DeviceOSVersion,
DeviceManufacturer,
DeviceModel,
DeviceEmailAddress,
DeviceSecurityStatus,
DeviceRiskLevel,
TargetEmailAddress,
TargetPlatform,
ActorType,
ActorGuid,
ChangeType
eventGroupingSettings:
aggregationKind: AlertPerResult
alertDetailsOverride:
alertDisplayNameFormat: 'Critical Smishing Alert: {{ThreatCategory}} targeting {{DevicePlatform}} Device'
alertDescriptionFormat: '{{SmishingAlertSeverity}} {{ThreatCategory}} attack on {{DevicePlatform}}'
alertSeverityColumnName: SmishingAlertSeverity
alertTacticsColumnName: ThreatCategory
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Lookout/Analytic%20Rules/LookoutSmishingAlertV2.yaml
suppressionEnabled: false
requiredDataConnectors:
- dataTypes:
- LookoutEvents
connectorId: LookoutAPI
customDetails:
AlertRiskScore: AlertRiskScore
ImpersonationRisk: ImpersonationRisk
SmishAlertType: SmishingAlertType
SmishSeverity: SmishingAlertSeverity
ThreatCategory: ThreatCategory
CampaignIndicators: CampaignIndicators
DevicePlatform: DevicePlatform
DeviceRiskLevel: DeviceRiskLevel
DeviceSecStatus: DeviceSecurityStatus
tactics:
- InitialAccess
- CredentialAccess
- Collection
- Discovery
queryPeriod: 15m
severity: High
status: Available
name: Lookout - Critical Smishing and Phishing Alerts (v2)
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "{{SmishingAlertSeverity}} {{ThreatCategory}} attack on {{DevicePlatform}}",
"alertDisplayNameFormat": "Critical Smishing Alert: {{ThreatCategory}} targeting {{DevicePlatform}} Device",
"alertSeverityColumnName": "SmishingAlertSeverity",
"alertTacticsColumnName": "ThreatCategory"
},
"alertRuleTemplateName": "7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e",
"customDetails": {
"AlertRiskScore": "AlertRiskScore",
"CampaignIndicators": "CampaignIndicators",
"DevicePlatform": "DevicePlatform",
"DeviceRiskLevel": "DeviceRiskLevel",
"DeviceSecStatus": "DeviceSecurityStatus",
"ImpersonationRisk": "ImpersonationRisk",
"SmishAlertType": "SmishingAlertType",
"SmishSeverity": "SmishingAlertSeverity",
"ThreatCategory": "ThreatCategory"
},
"description": "'Detects critical smishing (SMS phishing) and phishing alerts from Lookout Mobile Risk API v2. This rule identifies sophisticated social engineering attacks including CEO fraud, credential harvesting, and malicious link campaigns targeting mobile devices. Leverages enhanced v2 smishing detection capabilities for comprehensive mobile threat protection.'\n",
"displayName": "Lookout - Critical Smishing and Phishing Alerts (v2)",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "DeviceEmailAddress",
"identifier": "FullName"
},
{
"columnName": "TargetEmailAddress",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "DeviceGuid",
"identifier": "HostName"
},
{
"columnName": "DevicePlatform",
"identifier": "OSFamily"
},
{
"columnName": "DeviceOSVersion",
"identifier": "OSVersion"
}
]
},
{
"entityType": "URL",
"fieldMappings": [
{
"columnName": "SmishingAlertDescription",
"identifier": "Url"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [
"SmishAlertType",
"DeviceGuid"
],
"groupByCustomDetails": [
"ThreatCategory",
"ImpersonationRisk",
"CampaignIndicators"
],
"groupByEntities": [
"Account",
"Host"
],
"lookbackDuration": "P1D",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Lookout/Analytic%20Rules/LookoutSmishingAlertV2.yaml",
"query": "LookoutEvents\n| where EventType == \"SMISHING_ALERT\"\n| where SmishingAlertSeverity in (\"CRITICAL\", \"HIGH\")\n| where SmishingAlertType in (\"PHISHING_DETECTION\", \"FRAUD_DETECTION\", \"CREDENTIAL_HARVESTING\")\n| extend \n AlertRiskScore = case(\n SmishingAlertSeverity == \"CRITICAL\", 10,\n SmishingAlertSeverity == \"HIGH\", 8,\n SmishingAlertSeverity == \"MEDIUM\", 5,\n SmishingAlertSeverity == \"LOW\", 2,\n 1\n ),\n ThreatCategory = case(\n SmishingAlertType == \"PHISHING_DETECTION\", \"Phishing\",\n SmishingAlertType == \"FRAUD_DETECTION\", \"Fraud\",\n SmishingAlertType == \"CREDENTIAL_HARVESTING\", \"Credential Theft\",\n SmishingAlertType == \"MALICIOUS_LINK\", \"Malicious Link\",\n \"Other\"\n ),\n ImpersonationRisk = case(\n SmishingAlertDescription has \"CEO\" or SmishingAlertDescription has \"executive\", \"Executive Impersonation\",\n SmishingAlertDescription has \"IT\" or SmishingAlertDescription has \"support\", \"IT Support Impersonation\", \n SmishingAlertDescription has \"bank\" or SmishingAlertDescription has \"financial\", \"Financial Impersonation\",\n SmishingAlertDescription has \"delivery\" or SmishingAlertDescription has \"package\", \"Delivery Impersonation\",\n \"Generic Phishing\"\n )\n| extend DeviceRiskLevel = case(\n DeviceSecurityStatus == \"THREATS_HIGH\", \"High\",\n DeviceSecurityStatus == \"THREATS_MEDIUM\", \"Medium\", \n DeviceSecurityStatus == \"THREATS_LOW\", \"Low\",\n \"Unknown\"\n)\n| extend CampaignIndicators = case(\n AlertRiskScore >= 8 and DeviceRiskLevel == \"High\", \"Targeted Campaign\",\n AlertRiskScore >= 6 and ImpersonationRisk != \"Generic Phishing\", \"Sophisticated Attack\",\n AlertRiskScore >= 5, \"Coordinated Threat\",\n \"Isolated Incident\"\n)\n| project\n TimeGenerated,\n EventId,\n SmishingAlertId,\n SmishingAlertType,\n SmishingAlertSeverity,\n SmishingAlertDescription,\n AlertRiskScore,\n ThreatCategory,\n ImpersonationRisk,\n CampaignIndicators,\n DeviceGuid,\n DevicePlatform,\n DeviceOSVersion,\n DeviceManufacturer,\n DeviceModel,\n DeviceEmailAddress,\n DeviceSecurityStatus,\n DeviceRiskLevel,\n TargetEmailAddress,\n TargetPlatform,\n ActorType,\n ActorGuid,\n ChangeType\n",
"queryFrequency": "PT5M",
"queryPeriod": "PT15M",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Collection",
"CredentialAccess",
"Discovery",
"InitialAccess"
],
"techniques": null,
"templateVersion": "2.0.3",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}