Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Dragos Notifications

Back
Id9a74fe72-4c21-4ac5-80d9-37434e809721
RulenameDragos Notifications
DescriptionFires Microsoft Sentinel alerts for Dragos Notifcations.
SeverityMedium
Required data connectorsCefAma
DragosSitestoreCCP
KindScheduled
Query frequency10m
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
Version1.0.1
Arm template9a74fe72-4c21-4ac5-80d9-37434e809721.json
Deploy To Azure
DragosNotificationsToSentinel()
queryPeriod: 1h
query: |
    DragosNotificationsToSentinel()
name: Dragos Notifications
entityMappings:
- fieldMappings:
  - columnName: SentinelEntities
    identifier: Entities
  entityType: SentinelEntities
eventGroupingSettings:
  aggregationKind: AlertPerResult
queryFrequency: 10m
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
alertDetailsOverride:
  alertDynamicProperties:
  - value: MitreTechniques
    alertProperty: Techniques
  - value: AlertProductName
    alertProperty: ProductName
  alertSeverityColumnName: MSSentinelSeverity
  alertDescriptionFormat: '{{content}}'
  alertDisplayNameFormat: 'Dragos: {{summary}}'
  alertTacticsColumnName: MitreTactics
requiredDataConnectors:
- connectorId: DragosSitestoreCCP
  dataTypes:
  - DragosAlerts_CL
- connectorId: CefAma
  dataTypes:
  - CommonSecurityLog
description: |
    'Fires Microsoft Sentinel alerts for Dragos Notifcations.'
kind: Scheduled
incidentConfiguration:
  groupingConfiguration:
    matchingMethod: Selected
    reopenClosedIncident: false
    lookbackDuration: PT1H
    groupByCustomDetails:
    - DragosIdentifier
    enabled: true
  createIncident: true
version: 1.0.1
status: Available
severity: Medium
relevantTechniques: []
triggerOperator: gt
triggerThreshold: 0
customDetails:
  DragosThreatInfo: threatInfo
  DragosIdentifier: id
  DragosOccurredAt: occurredAt
  DragosCreatedAt: createdAt
  DragosSeverity: severity
  DragosDetectionQuads: detectionQuads
  DragosMacAddresses: MacAddresses
  DragosFirstSeenAt: firstSeenAt
  DragosIpAddresses: IpAddresses
  DragosState: state
  DragosConnectSrc: DragosConnectorSource
  DragosSource: source
  DragosLastSeenAt: lastSeenAt
tactics: []
id: 9a74fe72-4c21-4ac5-80d9-37434e809721