Back
Ida1b2c3d4-5678-90ab-cdef-222222222222
RulenameRecorded Future Sandbox - Malicious Email Attachment
DescriptionCreates incidents when Recorded Future Sandbox detects malicious files from Outlook email attachments
SeverityHigh
Required data connectorsRecordedFuture
KindNRT
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxEmailAttachment.yaml
Version2.0.0
Arm templatea1b2c3d4-5678-90ab-cdef-222222222222.json
Deploy To Azure
RecordedFutureSandboxResults_V2_CL
| where TimeGenerated >= now(-1h)
| where Source == "OutlookAttachment"
| where toint(SandboxScore) >= 50
incidentConfiguration:
  groupingConfiguration:
    groupByCustomDetails:
    - EmailFrom
    lookbackDuration: 1h
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
  createIncident: true
name: Recorded Future Sandbox - Malicious Email Attachment
triggerOperator: gt
query: |
  RecordedFutureSandboxResults_V2_CL
  | where TimeGenerated >= now(-1h)
  | where Source == "OutlookAttachment"
  | where toint(SandboxScore) >= 50
queryFrequency: 1h
description: |
  'Creates incidents when Recorded Future Sandbox detects malicious files from Outlook email attachments'
id: a1b2c3d4-5678-90ab-cdef-222222222222
triggerThreshold: 0
version: 2.0.0
queryPeriod: 1h
status: Available
kind: NRT
customDetails:
  SampleId: SampleId
  SandboxVerdict: SandboxVerdict
  EmailTo: EmailTo
  Source: Source
  SandboxScore: SandboxScore
  FileName: FileName
  EmailFrom: EmailFrom
relevantTechniques: []
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: RecordedFuture
  dataTypes:
  - RecordedFutureSandboxResults_V2_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxEmailAttachment.yaml
alertDetailsOverride:
  alertDescriptionFormat: |
    _Recorded Future Sandbox - Malicious Email Attachment Detected_

    **Sandbox Score:** {{SandboxScore}}/100

    **Verdict:** {{SandboxVerdict}}

    **Sample ID:** {{SampleId}}

    A malicious file was detected in an email attachment. Review the full sandbox report and investigate the sender.
  alertDisplayNameFormat: 'Malicious Email Attachment: {{FileName}} from {{EmailFrom}}'
tactics: []
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: FileName
  entityType: File
- fieldMappings:
  - identifier: MailboxPrimaryAddress
    columnName: EmailFrom
  entityType: Mailbox
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/a1b2c3d4-5678-90ab-cdef-222222222222')]",
      "kind": "NRT",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/a1b2c3d4-5678-90ab-cdef-222222222222')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "_Recorded Future Sandbox - Malicious Email Attachment Detected_\n\n**Sandbox Score:** {{SandboxScore}}/100\n\n**Verdict:** {{SandboxVerdict}}\n\n**Sample ID:** {{SampleId}}\n\nA malicious file was detected in an email attachment. Review the full sandbox report and investigate the sender.\n",
          "alertDisplayNameFormat": "Malicious Email Attachment: {{FileName}} from {{EmailFrom}}"
        },
        "alertRuleTemplateName": "a1b2c3d4-5678-90ab-cdef-222222222222",
        "customDetails": {
          "EmailFrom": "EmailFrom",
          "EmailTo": "EmailTo",
          "FileName": "FileName",
          "SampleId": "SampleId",
          "SandboxScore": "SandboxScore",
          "SandboxVerdict": "SandboxVerdict",
          "Source": "Source"
        },
        "description": "'Creates incidents when Recorded Future Sandbox detects malicious files from Outlook email attachments'\n",
        "displayName": "Recorded Future Sandbox - Malicious Email Attachment",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "File",
            "fieldMappings": [
              {
                "columnName": "FileName",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Mailbox",
            "fieldMappings": [
              {
                "columnName": "EmailFrom",
                "identifier": "MailboxPrimaryAddress"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "EmailFrom"
            ],
            "lookbackDuration": "PT1H",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxEmailAttachment.yaml",
        "query": "RecordedFutureSandboxResults_V2_CL\n| where TimeGenerated >= now(-1h)\n| where Source == \"OutlookAttachment\"\n| where toint(SandboxScore) >= 50\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [],
        "techniques": [],
        "templateVersion": "2.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}