Contrast ADR - Security Incident Alert
| Id | 7ce5956f-48f2-42f5-8e2e-c254e7643c11 |
| Rulename | Contrast ADR - Security Incident Alert |
| Description | Monitors Contrast ADR security incidents across all applications and environments. This rule creates alerts for all security incidents detected by Contrast Security ADR, providing comprehensive visibility into application security events requiring investigation. |
| Severity | Medium |
| Tactics | InitialAccess DefenseEvasion Discovery CommandAndControl |
| Techniques | T1190 T1055 T1018 T1008 |
| Required data connectors | ContrastADRCCF |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic Rules/Contrast_Security_ADR_incident.yaml |
| Version | 1.0.1 |
| Arm template | 7ce5956f-48f2-42f5-8e2e-c254e7643c11.json |
ContrastADRIncidents_CL
relevantTechniques:
- T1190
- T1055
- T1018
- T1008
name: Contrast ADR - Security Incident Alert
version: 1.0.1
entityMappings:
- fieldMappings:
- columnName: incidentId
identifier: ObjectGuid
entityType: SecurityGroup
triggerThreshold: 0
alertDetailsOverride:
alertDisplayNameFormat: '{{incidentName}}'
alertDescriptionFormat: '{{summary}}'
kind: Scheduled
queryFrequency: 5m
description: |
'Monitors Contrast ADR security incidents across all applications and environments. This rule creates alerts for all security incidents detected by Contrast Security ADR, providing comprehensive visibility into application security events requiring investigation.'
queryPeriod: 5m
id: 7ce5956f-48f2-42f5-8e2e-c254e7643c11
requiredDataConnectors:
- connectorId: ContrastADRCCF
dataTypes:
- ContrastADRIncidents_CL
tactics:
- InitialAccess
- DefenseEvasion
- Discovery
- CommandAndControl
severity: Medium
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic Rules/Contrast_Security_ADR_incident.yaml
query: |
ContrastADRIncidents_CL
triggerOperator: gt
incidentConfiguration:
createIncident: true
groupingConfiguration:
groupByEntities:
- SecurityGroup
reopenClosedIncident: false
enabled: true
matchingMethod: Selected
lookbackDuration: PT1H