Entities_Data_CL
| where entity_type == "account"
| extend Tags = todynamic(tags)
| where set_has_element(Tags, "MDR - Customer Escalation")
| summarize arg_max(['last_modified_timestamp'], *) by ['name']
suppressionEnabled: false
description: Create an incident when the account entity presents a specific tag. If the tag is present, an incident should be created and marked with highest priority.
kind: Scheduled
tactics:
- Persistence
requiredDataConnectors:
- connectorId: VectraXDR
dataTypes:
- Entities_Data_CL
incidentConfiguration:
groupingConfiguration:
enabled: true
groupByEntities:
- Account
reopenClosedIncident: false
lookbackDuration: P7D
matchingMethod: AllEntities
groupByAlertDetails:
- DisplayName
createIncident: true
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra XDR/Analytic Rules/Create_Incident_Based_On_Tag_For_Account_Entity.yaml
severity: High
name: Vectra Create Incident Based on Tag for Accounts
suppressionDuration: PT1H
customDetails:
entity_id: id
attack_profile: attack_profile
entity_type: entity_type
ip_address: ip
tags: tags
eventGroupingSettings:
aggregationKind: AlertPerResult
triggerThreshold: 0
queryPeriod: 10m
query: |
Entities_Data_CL
| where entity_type == "account"
| extend Tags = todynamic(tags)
| where set_has_element(Tags, "MDR - Customer Escalation")
| summarize arg_max(['last_modified_timestamp'], *) by ['name']
relevantTechniques:
- T1546
alertDetailsOverride:
alertDescriptionFormat: An incident has been escalated for Vectra AI entity {{name}} that is presenting an urgency score of {{urgency_score}}
alertDisplayNameFormat: Vectra AI Incident- {{name}}
id: 87325835-dd8c-41e7-b686-fd5adbbd0aee
queryFrequency: 10m
status: Available
triggerOperator: GreaterThan
version: 1.1.0
entityMappings:
- entityType: Account
fieldMappings:
- columnName: name
identifier: Name