Contrast ADR - Security Incident Alert
| Id | 7ce5956f-48f2-42f5-8e2e-c254e7643c11 |
| Rulename | Contrast ADR - Security Incident Alert |
| Description | Monitors Contrast ADR security incidents across all applications and environments. This rule creates alerts for all security incidents detected by Contrast Security ADR, providing comprehensive visibility into application security events requiring investigation. |
| Severity | Medium |
| Tactics | InitialAccess DefenseEvasion Discovery CommandAndControl |
| Techniques | T1190 T1055 T1018 T1008 |
| Required data connectors | ContrastADRCCF |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic Rules/Contrast_Security_ADR_incident.yaml |
| Version | 1.0.1 |
| Arm template | 7ce5956f-48f2-42f5-8e2e-c254e7643c11.json |
ContrastADRIncidents_CL
entityMappings:
- entityType: SecurityGroup
fieldMappings:
- identifier: ObjectGuid
columnName: incidentId
tactics:
- InitialAccess
- DefenseEvasion
- Discovery
- CommandAndControl
requiredDataConnectors:
- dataTypes:
- ContrastADRIncidents_CL
connectorId: ContrastADRCCF
alertDetailsOverride:
alertDisplayNameFormat: '{{incidentName}}'
alertDescriptionFormat: '{{summary}}'
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
lookbackDuration: PT1H
groupByEntities:
- SecurityGroup
enabled: true
matchingMethod: Selected
createIncident: true
id: 7ce5956f-48f2-42f5-8e2e-c254e7643c11
severity: Medium
eventGroupingSettings:
aggregationKind: AlertPerResult
status: Available
query: |
ContrastADRIncidents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic Rules/Contrast_Security_ADR_incident.yaml
kind: Scheduled
queryPeriod: 5m
version: 1.0.1
name: Contrast ADR - Security Incident Alert
queryFrequency: 5m
triggerThreshold: 0
relevantTechniques:
- T1190
- T1055
- T1018
- T1008
description: |
'Monitors Contrast ADR security incidents across all applications and environments. This rule creates alerts for all security incidents detected by Contrast Security ADR, providing comprehensive visibility into application security events requiring investigation.'
triggerOperator: gt