AlertEvidence
| where EntityType in ("Device", "User")
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: AccountName
- entityType: IP
fieldMappings:
- identifier: Address
columnName: LocalIP
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: DeviceName
tactics:
- Persistence
suppressionEnabled: false
suppressionDuration: PT5H
requiredDataConnectors:
- dataTypes:
- AlertEvidence
connectorId: MicrosoftThreatProtection
incidentConfiguration:
groupingConfiguration:
enabled: false
lookbackDuration: PT5H
reopenClosedIncident: false
matchingMethod: AllEntities
createIncident: false
id: 8138863e-e55f-4f02-ac94-72796e203d27
severity: High
eventGroupingSettings:
aggregationKind: SingleAlert
status: Available
query: |
AlertEvidence
| where EntityType in ("Device", "User")
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra XDR/Analytic Rules/Defender_Alert_Evidence.yaml
kind: Scheduled
queryPeriod: 60m
name: Defender Alert Evidence
description: This analytic rule is looking for new alert evidence from Microsoft Defender for Endpoint. The intent is to create entries in the SecurityAlert table for every new alert evidence attached to an entity of type Device or User monitored by Defender for Endpoint.
type: Microsoft.OperationalInsights/workspaces/providers/alertRules
relevantTechniques:
- T1546
version: 1.0.0
queryFrequency: 60m
triggerThreshold: 0
triggerOperator: GreaterThan