Back
Id9392a06f-63a4-4a5d-8ca3-647064b13c28
RulenameDarktrace Model Alert
DescriptionThis query searches for Darktrace model alerts and creates a Microsoft Sentinel alert

from each matching event. Edit this analytic rule if you would like it to create

Microsoft Sentinel incidents.
SeverityHigh
TacticsInitialAccess
Execution
LateralMovement
CommandAndControl
TechniquesT1190
T1059
T1021
T1071
Required data connectorsDarktraceActiveAISecurityPlatform
KindNRT
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml
Version1.1.0
Arm template9392a06f-63a4-4a5d-8ca3-647064b13c28.json
Deploy To Azure
DarktraceModelAlerts_CL
| where TimeGenerated >= ago(5m)
| extend SentinelSeverity = case(
compliance == true, "Informational",
category == "Informational", "Low",
category == "Suspicious", "Medium",
category == "Critical", "High",
"Informational")
| extend ProviderName = "Darktrace"
| mv-apply item = mitreTechniques on (
    extend techniqueId = tostring(item.techniqueId)
    | summarize techniqueIdArray = make_list(techniqueId, 5)
)
relevantTechniques:
- T1190
- T1059
- T1021
- T1071
incidentConfiguration:
  groupingConfiguration:
    reopenClosedIncident: false
    lookbackDuration: PT5H
    matchingMethod: AllEntities
    enabled: false
  createIncident: false
customDetails:
  DeviceCredentials: deviceCredentials
  Compliance: compliance
  CustomLabel: customLabel
  Category: category
  DeviceHostname: deviceHostname
  Score: score
entityMappings:
- entityType: Account
  fieldMappings:
  - columnName: accountName
    identifier: FullName
- entityType: IP
  fieldMappings:
  - columnName: sourceIp
    identifier: Address
- entityType: IP
  fieldMappings:
  - columnName: destIp
    identifier: Address
- entityType: Host
  fieldMappings:
  - columnName: destHost
    identifier: HostName
- entityType: Host
  fieldMappings:
  - columnName: sourceHost
    identifier: HostName
id: 9392a06f-63a4-4a5d-8ca3-647064b13c28
severity: High
description: |
  This query searches for Darktrace model alerts and creates a Microsoft Sentinel alert
  from each matching event. Edit this analytic rule if you would like it to create
  Microsoft Sentinel incidents.
alertDetailsOverride:
  alertSeverityColumnName: SentinelSeverity
  alertDescriptionFormat: '{{message}}'
  alertDynamicProperties:
  - value: alertUrl
    alertProperty: AlertLink
  - value: darktraceProduct
    alertProperty: ProductName
  - value: ProviderName
    alertProperty: ProviderName
  - value: techniqueIdArray
    alertProperty: Techniques
  alertDisplayNameFormat: 'Darktrace Model Alert: {{modelName}}  '
query: |
  DarktraceModelAlerts_CL
  | where TimeGenerated >= ago(5m)
  | extend SentinelSeverity = case(
  compliance == true, "Informational",
  category == "Informational", "Low",
  category == "Suspicious", "Medium",
  category == "Critical", "High",
  "Informational")
  | extend ProviderName = "Darktrace"
  | mv-apply item = mitreTechniques on (
      extend techniqueId = tostring(item.techniqueId)
      | summarize techniqueIdArray = make_list(techniqueId, 5)
  )
requiredDataConnectors:
- connectorId: DarktraceActiveAISecurityPlatform
  dataTypes:
  - DarktraceModelAlerts_CL
version: 1.1.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml
name: Darktrace Model Alert
tactics:
- InitialAccess
- Execution
- LateralMovement
- CommandAndControl
kind: NRT
eventGroupingSettings:
  aggregationKind: AlertPerResult
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/9392a06f-63a4-4a5d-8ca3-647064b13c28')]",
      "kind": "NRT",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/9392a06f-63a4-4a5d-8ca3-647064b13c28')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "{{message}}",
          "alertDisplayNameFormat": "Darktrace Model Alert: {{modelName}}  ",
          "alertDynamicProperties": [
            {
              "alertProperty": "AlertLink",
              "value": "alertUrl"
            },
            {
              "alertProperty": "ProductName",
              "value": "darktraceProduct"
            },
            {
              "alertProperty": "ProviderName",
              "value": "ProviderName"
            },
            {
              "alertProperty": "Techniques",
              "value": "techniqueIdArray"
            }
          ],
          "alertSeverityColumnName": "SentinelSeverity"
        },
        "alertRuleTemplateName": "9392a06f-63a4-4a5d-8ca3-647064b13c28",
        "customDetails": {
          "Category": "category",
          "Compliance": "compliance",
          "CustomLabel": "customLabel",
          "DeviceCredentials": "deviceCredentials",
          "DeviceHostname": "deviceHostname",
          "Score": "score"
        },
        "description": "This query searches for Darktrace model alerts and creates a Microsoft Sentinel alert\nfrom each matching event. Edit this analytic rule if you would like it to create\nMicrosoft Sentinel incidents.\n",
        "displayName": "Darktrace Model Alert",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "accountName",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "sourceIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "destIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "destHost",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "sourceHost",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": false,
          "groupingConfiguration": {
            "enabled": false,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Darktrace/Analytic%20Rules/DarktraceModelAlert.yaml",
        "query": "DarktraceModelAlerts_CL\n| where TimeGenerated >= ago(5m)\n| extend SentinelSeverity = case(\ncompliance == true, \"Informational\",\ncategory == \"Informational\", \"Low\",\ncategory == \"Suspicious\", \"Medium\",\ncategory == \"Critical\", \"High\",\n\"Informational\")\n| extend ProviderName = \"Darktrace\"\n| mv-apply item = mitreTechniques on (\n    extend techniqueId = tostring(item.techniqueId)\n    | summarize techniqueIdArray = make_list(techniqueId, 5)\n)\n",
        "severity": "High",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Execution",
          "InitialAccess",
          "LateralMovement"
        ],
        "techniques": [
          "T1021",
          "T1059",
          "T1071",
          "T1190"
        ],
        "templateVersion": "1.1.0"
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}