Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Dragos Notifications

Back
Id9a74fe72-4c21-4ac5-80d9-37434e809721
RulenameDragos Notifications
DescriptionFires Microsoft Sentinel alerts for Dragos Notifcations.
SeverityMedium
Required data connectorsCefAma
DragosSitestoreCCP
KindScheduled
Query frequency10m
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
Version1.0.1
Arm template9a74fe72-4c21-4ac5-80d9-37434e809721.json
Deploy To Azure
DragosNotificationsToSentinel()
description: |
    'Fires Microsoft Sentinel alerts for Dragos Notifcations.'
requiredDataConnectors:
- dataTypes:
  - DragosAlerts_CL
  connectorId: DragosSitestoreCCP
- dataTypes:
  - CommonSecurityLog
  connectorId: CefAma
kind: Scheduled
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
customDetails:
  DragosConnectSrc: DragosConnectorSource
  DragosThreatInfo: threatInfo
  DragosSource: source
  DragosLastSeenAt: lastSeenAt
  DragosSeverity: severity
  DragosFirstSeenAt: firstSeenAt
  DragosCreatedAt: createdAt
  DragosIpAddresses: IpAddresses
  DragosOccurredAt: occurredAt
  DragosState: state
  DragosMacAddresses: MacAddresses
  DragosDetectionQuads: detectionQuads
  DragosIdentifier: id
id: 9a74fe72-4c21-4ac5-80d9-37434e809721
name: Dragos Notifications
relevantTechniques: []
alertDetailsOverride:
  alertDynamicProperties:
  - value: MitreTechniques
    alertProperty: Techniques
  - value: AlertProductName
    alertProperty: ProductName
  alertSeverityColumnName: MSSentinelSeverity
  alertTacticsColumnName: MitreTactics
  alertDescriptionFormat: '{{content}}'
  alertDisplayNameFormat: 'Dragos: {{summary}}'
triggerThreshold: 0
entityMappings:
- fieldMappings:
  - identifier: Entities
    columnName: SentinelEntities
  entityType: SentinelEntities
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    enabled: true
    reopenClosedIncident: false
    lookbackDuration: PT1H
    groupByCustomDetails:
    - DragosIdentifier
    matchingMethod: Selected
version: 1.0.1
triggerOperator: gt
query: |
    DragosNotificationsToSentinel()
status: Available
tactics: []
queryPeriod: 1h
severity: Medium
queryFrequency: 10m
eventGroupingSettings:
  aggregationKind: AlertPerResult