secRMM_CL | where Event_s == "ONLINE" |
extend AccountCustomEntity = User_s |
extend HostCustomEntity = Computer
suppressionDuration: PT5H
createIncident: true
subTechniques: []
incidentConfiguration:
eventGroupingSettings:
alertRuleTemplateName:
query: |
secRMM_CL | where Event_s == "ONLINE" |
extend AccountCustomEntity = User_s |
extend HostCustomEntity = Computer
displayName: Removable Storage ONLINE
enabled: true
relevantTechniques:
- T1025
tactics:
- Collection
alertDetailsOverride:
groupingConfiguration:
reopenClosedIncident: false
groupByCustomDetails: []
enabled: false
groupByAlertDetails: []
matchingMethod: AllEntities
lookbackDuration: PT5H
groupByEntities: []
entityMappings:
- entityType: Account
fieldMappings:
- identifier: AadUserId
columnName: User_s
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Computer
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Squadra Technologies SecRmm/Analytic Rules/Removable_Storage_ONLINE.yaml
kind: NRT
apiVersion: 2025-09-01
aggregationKind: AlertPerResult
customDetails:
description: Detect when a removable storage device is plugged in by the end-user.
severity: High
name: Removable storage ONLINE event from secRMM
id: A22B2ECF-1478-4400-877E-07A32E53A897
suppressionEnabled: false