Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

CyberArkEPM - Attack attempt not blocked

Back
Id8e8978a2-9188-4187-8909-5ea00507bf16
RulenameCyberArkEPM - Attack attempt not blocked
DescriptionThis rule triggers on attack attempt which was not blocked by CyberArkEPM.
SeverityHigh
TacticsExecution
TechniquesT1204
Required data connectorsCyberArkEPM
KindScheduled
Query frequency10m
Query period10m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyberArkEPM/Analytic Rules/CyberArkEPMAttackAttemptNotBlocked.yaml
Version1.0.0
Arm template8e8978a2-9188-4187-8909-5ea00507bf16.json
Deploy To Azure
CyberArkEPM
| where EventSubType =~ 'AttackAttempt'
| where ThreatProtectionAction =~ 'Detect'
| project EventEndTime, EventMessage, ActorUsername, ActingProcessFileInternalName, Evidences
| extend AccountCustomEntity = ActorUsername
triggerOperator: gt
triggerThreshold: 0
name: CyberArkEPM - Attack attempt not blocked
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyberArkEPM/Analytic Rules/CyberArkEPMAttackAttemptNotBlocked.yaml
queryPeriod: 10m
severity: High
kind: Scheduled
entityMappings:
- entityType: Account
  fieldMappings:
  - columnName: AccountCustomEntity
    identifier: Name
queryFrequency: 10m
relevantTechniques:
- T1204
requiredDataConnectors:
- dataTypes:
  - CyberArkEPM
  connectorId: CyberArkEPM
description: |
    'This rule triggers on attack attempt which was not blocked by CyberArkEPM.'
tactics:
- Execution
query: |
  CyberArkEPM
  | where EventSubType =~ 'AttackAttempt'
  | where ThreatProtectionAction =~ 'Detect'
  | project EventEndTime, EventMessage, ActorUsername, ActingProcessFileInternalName, Evidences
  | extend AccountCustomEntity = ActorUsername  
id: 8e8978a2-9188-4187-8909-5ea00507bf16
version: 1.0.0
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/8e8978a2-9188-4187-8909-5ea00507bf16')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/8e8978a2-9188-4187-8909-5ea00507bf16')]",
      "properties": {
        "alertRuleTemplateName": "8e8978a2-9188-4187-8909-5ea00507bf16",
        "customDetails": null,
        "description": "'This rule triggers on attack attempt which was not blocked by CyberArkEPM.'\n",
        "displayName": "CyberArkEPM - Attack attempt not blocked",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "AccountCustomEntity",
                "identifier": "Name"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CyberArkEPM/Analytic Rules/CyberArkEPMAttackAttemptNotBlocked.yaml",
        "query": "CyberArkEPM\n| where EventSubType =~ 'AttackAttempt'\n| where ThreatProtectionAction =~ 'Detect'\n| project EventEndTime, EventMessage, ActorUsername, ActingProcessFileInternalName, Evidences\n| extend AccountCustomEntity = ActorUsername\n",
        "queryFrequency": "PT10M",
        "queryPeriod": "PT10M",
        "severity": "High",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Execution"
        ],
        "techniques": [
          "T1204"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}