Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Dragos Notifications

Back
Id9a74fe72-4c21-4ac5-80d9-37434e809721
RulenameDragos Notifications
DescriptionFires Microsoft Sentinel alerts for Dragos Notifcations.
SeverityMedium
Required data connectorsCefAma
DragosSitestoreCCP
KindScheduled
Query frequency10m
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
Version1.0.1
Arm template9a74fe72-4c21-4ac5-80d9-37434e809721.json
Deploy To Azure
DragosNotificationsToSentinel()
triggerOperator: gt
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT1H
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
    groupByCustomDetails:
    - DragosIdentifier
  createIncident: true
queryFrequency: 10m
requiredDataConnectors:
- connectorId: DragosSitestoreCCP
  dataTypes:
  - DragosAlerts_CL
- connectorId: CefAma
  dataTypes:
  - CommonSecurityLog
relevantTechniques: []
entityMappings:
- entityType: SentinelEntities
  fieldMappings:
  - identifier: Entities
    columnName: SentinelEntities
query: |
    DragosNotificationsToSentinel()
triggerThreshold: 0
customDetails:
  DragosState: state
  DragosMacAddresses: MacAddresses
  DragosFirstSeenAt: firstSeenAt
  DragosConnectSrc: DragosConnectorSource
  DragosIdentifier: id
  DragosIpAddresses: IpAddresses
  DragosCreatedAt: createdAt
  DragosDetectionQuads: detectionQuads
  DragosOccurredAt: occurredAt
  DragosLastSeenAt: lastSeenAt
  DragosThreatInfo: threatInfo
  DragosSeverity: severity
  DragosSource: source
alertDetailsOverride:
  alertDisplayNameFormat: 'Dragos: {{summary}}'
  alertTacticsColumnName: MitreTactics
  alertDescriptionFormat: '{{content}}'
  alertDynamicProperties:
  - alertProperty: Techniques
    value: MitreTechniques
  - alertProperty: ProductName
    value: AlertProductName
  alertSeverityColumnName: MSSentinelSeverity
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Dragos/Analytic Rules/DragosNotifiction.yaml
queryPeriod: 1h
name: Dragos Notifications
status: Available
kind: Scheduled
description: |
    'Fires Microsoft Sentinel alerts for Dragos Notifcations.'
id: 9a74fe72-4c21-4ac5-80d9-37434e809721
version: 1.0.1
eventGroupingSettings:
  aggregationKind: AlertPerResult
tactics: []
severity: Medium