Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Flare paste results

Back
Id9cb7c337-f177-4af6-b0e8-b6b7552d762d
RulenameFlare paste results
DescriptionThis query searches for events found on code Snippet (paste) sharing platform.
SeverityMedium
TacticsReconnaissance
TechniquesT1593
Required data connectorsFlare
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Flare/Analytic Rules/FlarePaste.yaml
Version3.0.0
Arm template9cb7c337-f177-4af6-b0e8-b6b7552d762d.json
Deploy To Azure
FireworkV2_CL
| where notempty(uid) and RiskScore >= 3
| extend index_name = split(uid, "/")[0]
| where index_name == "paste"
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Flare/Analytic Rules/FlarePaste.yaml
relevantTechniques:
- T1593
triggerThreshold: 0
tactics:
- Reconnaissance
query: |
  FireworkV2_CL
  | where notempty(uid) and RiskScore >= 3
  | extend index_name = split(uid, "/")[0]
  | where index_name == "paste"  
triggerOperator: gt
id: 9cb7c337-f177-4af6-b0e8-b6b7552d762d
kind: Scheduled
queryFrequency: 1h
version: 3.0.0
requiredDataConnectors:
- connectorId: Flare
  dataTypes:
  - FireworkV2_CL
description: |
    'This query searches for events found on code Snippet (paste) sharing platform.'
status: Available
name: Flare paste results
severity: Medium
queryPeriod: 1h