Mimecast Audit - Logon Authentication Failed
| Id | 9c5dcd76-9f6d-42a3-b984-314b52678f20 |
| Rulename | Mimecast Audit - Logon Authentication Failed |
| Description | Detects threat when logon authentication failure found in audit |
| Severity | High |
| Tactics | Discovery InitialAccess CredentialAccess |
| Techniques | T1110 |
| Required data connectors | MimecastAuditAPI |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 15m |
| Trigger threshold | 3 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MimecastAudit/Analytic Rules/MimecastAudit.yaml |
| Version | 1.0.0 |
| Arm template | 9c5dcd76-9f6d-42a3-b984-314b52678f20.json |
MimecastAudit_CL | where src_s !="" and auditType_s == "Logon Authentication Failed"
severity: High
description: Detects threat when logon authentication failure found in audit
triggerThreshold: 3
entityMappings:
- entityType: IP
fieldMappings:
- columnName: src_s
identifier: Address
- entityType: Mailbox
fieldMappings:
- columnName: user_s
identifier: MailboxPrimaryAddress
- entityType: CloudApplication
fieldMappings:
- columnName: app_s
identifier: AppId
displayName: Mimecast Audit - Logon Authentication Failed
incidentConfiguration:
createIncident: true
groupingConfiguration:
lookbackDuration: 1d
reopenClosedIncident: false
enabled: true
matchingMethod: AllEntities
query: MimecastAudit_CL | where src_s !="" and auditType_s == "Logon Authentication Failed"
suppressionDuration: 5h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MimecastAudit/Analytic Rules/MimecastAudit.yaml
customDetails:
alertRuleTemplateName:
id: 9c5dcd76-9f6d-42a3-b984-314b52678f20
apiVersion: 2021-09-01-preview
eventGroupingSettings:
aggregationKind: SingleAlert
version: 1.0.0
requiredDataConnectors:
- connectorId: MimecastAuditAPI
dataTypes:
- MimecastAudit_CL
enabled: true
suppressionEnabled: false
name: Mimecast Audit - Logon Authentication Failed
alertDetailsOverride:
triggerOperator: gt
kind: Scheduled
tactics:
- Discovery
- InitialAccess
- CredentialAccess
queryFrequency: 5m
relevantTechniques:
- T1110
queryPeriod: 15m