Back
Id968b70c1-b468-418a-ac02-1eb74783a52a
RulenameVaikora - Engine offline
DescriptionIdentifies a Vaikora for O365 engine outage by absent quarantine telemetry. Fires when a tenant active in the last 24 hours has sent no rows in the last two hours, indicating the customer VM is unhealthy or the Graph subscription has lapsed.
SeverityMedium
TacticsDefenseEvasion
TechniquesT1562
Required data connectorsVaikoraO365
KindScheduled
Query frequency30m
Query period1d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vaikora-O365/Analytic%20Rules/Vaikora%20-%20Engine%20offline.yaml
Version1.0.0
Arm template968b70c1-b468-418a-ac02-1eb74783a52a.json
Deploy To Azure
let recentTenants = toscalar(
  VaikoraO365_Quarantine_CL
  | where TimeGenerated >= ago(2h)
  | summarize make_set(TenantId_s)
);
VaikoraO365_Quarantine_CL
| where TimeGenerated between (ago(1d) .. ago(2h))
| summarize LastSeen = max(TimeGenerated) by TenantId_s
| where TenantId_s !in (recentTenants)
| project TimeGenerated = now(), TenantId = TenantId_s, LastSeen, HoursOffline = (now() - LastSeen) / 1h
name: Vaikora - Engine offline
triggerOperator: gt
query: |
  let recentTenants = toscalar(
    VaikoraO365_Quarantine_CL
    | where TimeGenerated >= ago(2h)
    | summarize make_set(TenantId_s)
  );
  VaikoraO365_Quarantine_CL
  | where TimeGenerated between (ago(1d) .. ago(2h))
  | summarize LastSeen = max(TimeGenerated) by TenantId_s
  | where TenantId_s !in (recentTenants)
  | project TimeGenerated = now(), TenantId = TenantId_s, LastSeen, HoursOffline = (now() - LastSeen) / 1h
queryFrequency: 30m
description: |
  Identifies a Vaikora for O365 engine outage by absent quarantine telemetry. Fires when a tenant active in the last 24 hours has sent no rows in the last two hours, indicating the customer VM is unhealthy or the Graph subscription has lapsed.
id: 968b70c1-b468-418a-ac02-1eb74783a52a
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.0
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: VaikoraO365
  dataTypes:
  - VaikoraO365_Quarantine_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vaikora-O365/Analytic%20Rules/Vaikora%20-%20Engine%20offline.yaml
alertDetailsOverride:
  alertDescriptionFormat: 'No Vaikora-O365 quarantine telemetry has arrived from this tenant in the last 2 hours. Last seen: {{LastSeen}}.'
  alertDisplayNameFormat: Vaikora-O365 engine offline for tenant {{TenantId}}
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: TenantId
  entityType: CloudApplication
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/968b70c1-b468-418a-ac02-1eb74783a52a')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/968b70c1-b468-418a-ac02-1eb74783a52a')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "No Vaikora-O365 quarantine telemetry has arrived from this tenant in the last 2 hours. Last seen: {{LastSeen}}.",
          "alertDisplayNameFormat": "Vaikora-O365 engine offline for tenant {{TenantId}}"
        },
        "alertRuleTemplateName": "968b70c1-b468-418a-ac02-1eb74783a52a",
        "customDetails": null,
        "description": "Identifies a Vaikora for O365 engine outage by absent quarantine telemetry. Fires when a tenant active in the last 24 hours has sent no rows in the last two hours, indicating the customer VM is unhealthy or the Graph subscription has lapsed.\n",
        "displayName": "Vaikora - Engine offline",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "CloudApplication",
            "fieldMappings": [
              {
                "columnName": "TenantId",
                "identifier": "Name"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vaikora-O365/Analytic%20Rules/Vaikora%20-%20Engine%20offline.yaml",
        "query": "let recentTenants = toscalar(\n  VaikoraO365_Quarantine_CL\n  | where TimeGenerated >= ago(2h)\n  | summarize make_set(TenantId_s)\n);\nVaikoraO365_Quarantine_CL\n| where TimeGenerated between (ago(1d) .. ago(2h))\n| summarize LastSeen = max(TimeGenerated) by TenantId_s\n| where TenantId_s !in (recentTenants)\n| project TimeGenerated = now(), TenantId = TenantId_s, LastSeen, HoursOffline = (now() - LastSeen) / 1h\n",
        "queryFrequency": "PT30M",
        "queryPeriod": "P1D",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}