Back
Id8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41
RulenameNetskope Client - Private Access disabled by user
DescriptionDetects Netskope Client devices where the user disabled the Netskope Private Access (NPA)

service. All matching client-status events in the 6-hour window are collected into a single

alert, grouped per device, so repeated disable events on the same device are reported once.

A user disabling Private Access removes zero-trust access controls from the device.
SeverityMedium
TacticsDefenseEvasion
TechniquesT1562
Required data connectorsNetskopeClientStatus
KindScheduled
Query frequency6h
Query period6h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_PrivateAccessDisabledByUser.yaml
Version1.0.0
Arm template8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41.json
Deploy To Azure
NetskopeClientStatus_CL
| where TimeGenerated > ago(6h)
| where last_seen_device_event_actor_name =~ "USER"
    and last_seen_device_event_service_name =~ "Private Access"
    and last_seen_device_event_status_name =~ "DISABLED"
| extend DeviceKey = case(
    isnotempty(device_hash), device_hash,
    isnotempty(guid), guid,
    isnotempty(device_id), device_id,
    host_info_hostname)
| summarize
    EventCount = count(),
    FirstSeen = min(TimeGenerated),
    LastSeen = max(TimeGenerated),
    ClientEvents = make_set(last_seen_device_event_event_name, 10),
    arg_max(TimeGenerated,
        host_info_hostname,
        user_info_username,
        last_connected_from_public_ip,
        last_connected_from_private_ip,
        host_info_os_name,
        client_version,
        last_seen_device_event_actor_name,
        last_seen_device_event_service_name,
        last_seen_device_event_status_name,
        last_seen_device_event_status_v2_name,
        last_seen_device_event_npa_status_name,
        last_seen_device_event_event_name,
        last_seen_device_event_event_details)
    by DeviceKey
| project
    LastSeen,
    FirstSeen,
    EventCount,
    DeviceKey,
    HostName = host_info_hostname,
    UserName = user_info_username,
    PublicIp = last_connected_from_public_ip,
    PrivateIp = last_connected_from_private_ip,
    OperatingSystem = host_info_os_name,
    ClientVersion = client_version,
    Actor = last_seen_device_event_actor_name,
    ServiceName = last_seen_device_event_service_name,
    ClientStatus = last_seen_device_event_status_name,
    ClientStatusV2 = last_seen_device_event_status_v2_name,
    NpaStatus = last_seen_device_event_npa_status_name,
    LatestClientEvent = last_seen_device_event_event_name,
    EventDetails = last_seen_device_event_event_details,
    ClientEvents
| order by LastSeen desc
name: Netskope Client - Private Access disabled by user
triggerOperator: gt
query: |
  NetskopeClientStatus_CL
  | where TimeGenerated > ago(6h)
  | where last_seen_device_event_actor_name =~ "USER"
      and last_seen_device_event_service_name =~ "Private Access"
      and last_seen_device_event_status_name =~ "DISABLED"
  | extend DeviceKey = case(
      isnotempty(device_hash), device_hash,
      isnotempty(guid), guid,
      isnotempty(device_id), device_id,
      host_info_hostname)
  | summarize
      EventCount = count(),
      FirstSeen = min(TimeGenerated),
      LastSeen = max(TimeGenerated),
      ClientEvents = make_set(last_seen_device_event_event_name, 10),
      arg_max(TimeGenerated,
          host_info_hostname,
          user_info_username,
          last_connected_from_public_ip,
          last_connected_from_private_ip,
          host_info_os_name,
          client_version,
          last_seen_device_event_actor_name,
          last_seen_device_event_service_name,
          last_seen_device_event_status_name,
          last_seen_device_event_status_v2_name,
          last_seen_device_event_npa_status_name,
          last_seen_device_event_event_name,
          last_seen_device_event_event_details)
      by DeviceKey
  | project
      LastSeen,
      FirstSeen,
      EventCount,
      DeviceKey,
      HostName = host_info_hostname,
      UserName = user_info_username,
      PublicIp = last_connected_from_public_ip,
      PrivateIp = last_connected_from_private_ip,
      OperatingSystem = host_info_os_name,
      ClientVersion = client_version,
      Actor = last_seen_device_event_actor_name,
      ServiceName = last_seen_device_event_service_name,
      ClientStatus = last_seen_device_event_status_name,
      ClientStatusV2 = last_seen_device_event_status_v2_name,
      NpaStatus = last_seen_device_event_npa_status_name,
      LatestClientEvent = last_seen_device_event_event_name,
      EventDetails = last_seen_device_event_event_details,
      ClientEvents
  | order by LastSeen desc
queryFrequency: 6h
description: |
  Detects Netskope Client devices where the user disabled the Netskope Private Access (NPA)
  service. All matching client-status events in the 6-hour window are collected into a single
  alert, grouped per device, so repeated disable events on the same device are reported once.
  A user disabling Private Access removes zero-trust access controls from the device.
id: 8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41
triggerThreshold: 0
queryPeriod: 6h
version: 1.0.0
kind: Scheduled
customDetails:
  DeviceKey: DeviceKey
  EventCount: EventCount
  Actor: Actor
  LatestClientEvent: LatestClientEvent
  ServiceName: ServiceName
  ClientVersion: ClientVersion
  OperatingSystem: OperatingSystem
  ClientStatus: ClientStatus
  NpaStatus: NpaStatus
status: Available
eventGroupingSettings:
  aggregationKind: SingleAlert
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeClientStatus
  dataTypes:
  - NetskopeClientStatus_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_PrivateAccessDisabledByUser.yaml
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: UserName
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: HostName
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: PublicIp
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41')]",
      "properties": {
        "alertRuleTemplateName": "8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41",
        "customDetails": {
          "Actor": "Actor",
          "ClientStatus": "ClientStatus",
          "ClientVersion": "ClientVersion",
          "DeviceKey": "DeviceKey",
          "EventCount": "EventCount",
          "LatestClientEvent": "LatestClientEvent",
          "NpaStatus": "NpaStatus",
          "OperatingSystem": "OperatingSystem",
          "ServiceName": "ServiceName"
        },
        "description": "Detects Netskope Client devices where the user disabled the Netskope Private Access (NPA)\nservice. All matching client-status events in the 6-hour window are collected into a single\nalert, grouped per device, so repeated disable events on the same device are reported once.\nA user disabling Private Access removes zero-trust access controls from the device.\n",
        "displayName": "Netskope Client - Private Access disabled by user",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "UserName",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "PublicIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeClientStatus_PrivateAccessDisabledByUser.yaml",
        "query": "NetskopeClientStatus_CL\n| where TimeGenerated > ago(6h)\n| where last_seen_device_event_actor_name =~ \"USER\"\n    and last_seen_device_event_service_name =~ \"Private Access\"\n    and last_seen_device_event_status_name =~ \"DISABLED\"\n| extend DeviceKey = case(\n    isnotempty(device_hash), device_hash,\n    isnotempty(guid), guid,\n    isnotempty(device_id), device_id,\n    host_info_hostname)\n| summarize\n    EventCount = count(),\n    FirstSeen = min(TimeGenerated),\n    LastSeen = max(TimeGenerated),\n    ClientEvents = make_set(last_seen_device_event_event_name, 10),\n    arg_max(TimeGenerated,\n        host_info_hostname,\n        user_info_username,\n        last_connected_from_public_ip,\n        last_connected_from_private_ip,\n        host_info_os_name,\n        client_version,\n        last_seen_device_event_actor_name,\n        last_seen_device_event_service_name,\n        last_seen_device_event_status_name,\n        last_seen_device_event_status_v2_name,\n        last_seen_device_event_npa_status_name,\n        last_seen_device_event_event_name,\n        last_seen_device_event_event_details)\n    by DeviceKey\n| project\n    LastSeen,\n    FirstSeen,\n    EventCount,\n    DeviceKey,\n    HostName = host_info_hostname,\n    UserName = user_info_username,\n    PublicIp = last_connected_from_public_ip,\n    PrivateIp = last_connected_from_private_ip,\n    OperatingSystem = host_info_os_name,\n    ClientVersion = client_version,\n    Actor = last_seen_device_event_actor_name,\n    ServiceName = last_seen_device_event_service_name,\n    ClientStatus = last_seen_device_event_status_name,\n    ClientStatusV2 = last_seen_device_event_status_v2_name,\n    NpaStatus = last_seen_device_event_npa_status_name,\n    LatestClientEvent = last_seen_device_event_event_name,\n    EventDetails = last_seen_device_event_event_details,\n    ClientEvents\n| order by LastSeen desc\n",
        "queryFrequency": "PT6H",
        "queryPeriod": "PT6H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}