Mimecast Audit - Logon Authentication Failed
| Id | 9c5dcd76-9f6d-42a3-b984-314b52678f20 |
| Rulename | Mimecast Audit - Logon Authentication Failed |
| Description | Detects threat when logon authentication failure found in audit |
| Severity | High |
| Tactics | Discovery InitialAccess CredentialAccess |
| Techniques | T1110 |
| Required data connectors | MimecastAuditAPI |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 15m |
| Trigger threshold | 3 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MimecastAudit/Analytic Rules/MimecastAudit.yaml |
| Version | 1.0.0 |
| Arm template | 9c5dcd76-9f6d-42a3-b984-314b52678f20.json |
MimecastAudit_CL | where src_s !="" and auditType_s == "Logon Authentication Failed"
apiVersion: 2021-09-01-preview
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MimecastAudit/Analytic Rules/MimecastAudit.yaml
suppressionEnabled: false
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: src_s
- entityType: Mailbox
fieldMappings:
- identifier: MailboxPrimaryAddress
columnName: user_s
- entityType: CloudApplication
fieldMappings:
- identifier: AppId
columnName: app_s
description: Detects threat when logon authentication failure found in audit
enabled: true
queryFrequency: 5m
triggerThreshold: 3
relevantTechniques:
- T1110
tactics:
- Discovery
- InitialAccess
- CredentialAccess
queryPeriod: 15m
id: 9c5dcd76-9f6d-42a3-b984-314b52678f20
requiredDataConnectors:
- dataTypes:
- MimecastAudit_CL
connectorId: MimecastAuditAPI
customDetails:
kind: Scheduled
suppressionDuration: 5h
severity: High
triggerOperator: gt
query: MimecastAudit_CL | where src_s !="" and auditType_s == "Logon Authentication Failed"
alertDetailsOverride:
alertRuleTemplateName:
eventGroupingSettings:
aggregationKind: SingleAlert
displayName: Mimecast Audit - Logon Authentication Failed
incidentConfiguration:
groupingConfiguration:
enabled: true
matchingMethod: AllEntities
lookbackDuration: 1d
reopenClosedIncident: false
createIncident: true
version: 1.0.0
name: Mimecast Audit - Logon Authentication Failed