Back
Id9392a06f-63a4-4a5d-8ca3-647064b13c28
RulenameDarktrace Model Alert
DescriptionThis query searches for Darktrace model alerts and creates a Microsoft Sentinel alert

from each matching event. Edit this analytic rule if you would like it to create

Microsoft Sentinel incidents.
SeverityHigh
TacticsInitialAccess
Execution
LateralMovement
CommandAndControl
TechniquesT1190
T1059
T1021
T1071
Required data connectorsDarktraceActiveAISecurityPlatform
KindNRT
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml
Version1.1.0
Arm template9392a06f-63a4-4a5d-8ca3-647064b13c28.json
Deploy To Azure
DarktraceModelAlerts_CL
| where TimeGenerated >= ago(5m)
| extend SentinelSeverity = case(
compliance == true, "Informational",
category == "Informational", "Low",
category == "Suspicious", "Medium",
category == "Critical", "High",
"Informational")
| extend ProviderName = "Darktrace"
| mv-apply item = mitreTechniques on (
    extend techniqueId = tostring(item.techniqueId)
    | summarize techniqueIdArray = make_list(techniqueId, 5)
)
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: false
  createIncident: false
name: Darktrace Model Alert
query: |
  DarktraceModelAlerts_CL
  | where TimeGenerated >= ago(5m)
  | extend SentinelSeverity = case(
  compliance == true, "Informational",
  category == "Informational", "Low",
  category == "Suspicious", "Medium",
  category == "Critical", "High",
  "Informational")
  | extend ProviderName = "Darktrace"
  | mv-apply item = mitreTechniques on (
      extend techniqueId = tostring(item.techniqueId)
      | summarize techniqueIdArray = make_list(techniqueId, 5)
  )
description: |
  This query searches for Darktrace model alerts and creates a Microsoft Sentinel alert
  from each matching event. Edit this analytic rule if you would like it to create
  Microsoft Sentinel incidents.
id: 9392a06f-63a4-4a5d-8ca3-647064b13c28
kind: NRT
version: 1.1.0
customDetails:
  DeviceHostname: deviceHostname
  Score: score
  Category: category
  CustomLabel: customLabel
  DeviceCredentials: deviceCredentials
  Compliance: compliance
relevantTechniques:
- T1190
- T1059
- T1021
- T1071
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: DarktraceActiveAISecurityPlatform
  dataTypes:
  - DarktraceModelAlerts_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml
alertDetailsOverride:
  alertDescriptionFormat: '{{message}}'
  alertDisplayNameFormat: 'Darktrace Model Alert: {{modelName}}  '
  alertSeverityColumnName: SentinelSeverity
  alertDynamicProperties:
  - value: alertUrl
    alertProperty: AlertLink
  - value: darktraceProduct
    alertProperty: ProductName
  - value: ProviderName
    alertProperty: ProviderName
  - value: techniqueIdArray
    alertProperty: Techniques
tactics:
- InitialAccess
- Execution
- LateralMovement
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: accountName
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: sourceIp
  entityType: IP
- fieldMappings:
  - identifier: Address
    columnName: destIp
  entityType: IP
- fieldMappings:
  - identifier: HostName
    columnName: destHost
  entityType: Host
- fieldMappings:
  - identifier: HostName
    columnName: sourceHost
  entityType: Host
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/9392a06f-63a4-4a5d-8ca3-647064b13c28')]",
      "kind": "NRT",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/9392a06f-63a4-4a5d-8ca3-647064b13c28')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "{{message}}",
          "alertDisplayNameFormat": "Darktrace Model Alert: {{modelName}}  ",
          "alertDynamicProperties": [
            {
              "alertProperty": "AlertLink",
              "value": "alertUrl"
            },
            {
              "alertProperty": "ProductName",
              "value": "darktraceProduct"
            },
            {
              "alertProperty": "ProviderName",
              "value": "ProviderName"
            },
            {
              "alertProperty": "Techniques",
              "value": "techniqueIdArray"
            }
          ],
          "alertSeverityColumnName": "SentinelSeverity"
        },
        "alertRuleTemplateName": "9392a06f-63a4-4a5d-8ca3-647064b13c28",
        "customDetails": {
          "Category": "category",
          "Compliance": "compliance",
          "CustomLabel": "customLabel",
          "DeviceCredentials": "deviceCredentials",
          "DeviceHostname": "deviceHostname",
          "Score": "score"
        },
        "description": "This query searches for Darktrace model alerts and creates a Microsoft Sentinel alert\nfrom each matching event. Edit this analytic rule if you would like it to create\nMicrosoft Sentinel incidents.\n",
        "displayName": "Darktrace Model Alert",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "accountName",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "sourceIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "destIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "destHost",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "sourceHost",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": false,
          "groupingConfiguration": {
            "enabled": false,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml",
        "query": "DarktraceModelAlerts_CL\n| where TimeGenerated >= ago(5m)\n| extend SentinelSeverity = case(\ncompliance == true, \"Informational\",\ncategory == \"Informational\", \"Low\",\ncategory == \"Suspicious\", \"Medium\",\ncategory == \"Critical\", \"High\",\n\"Informational\")\n| extend ProviderName = \"Darktrace\"\n| mv-apply item = mitreTechniques on (\n    extend techniqueId = tostring(item.techniqueId)\n    | summarize techniqueIdArray = make_list(techniqueId, 5)\n)\n",
        "severity": "High",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Execution",
          "InitialAccess",
          "LateralMovement"
        ],
        "techniques": [
          "T1021",
          "T1059",
          "T1071",
          "T1190"
        ],
        "templateVersion": "1.1.0"
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}