Back
Ida1b2c3d4-5678-90ab-cdef-333333333333
RulenameRecorded Future Sandbox - Malicious File in Storage Account
DescriptionCreates incidents when Recorded Future Sandbox detects malicious files from Azure Storage Account
SeverityMedium
Required data connectorsRecordedFuture
KindNRT
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxStorageAccount.yaml
Version2.0.0
Arm templatea1b2c3d4-5678-90ab-cdef-333333333333.json
Deploy To Azure
RecordedFutureSandboxResults_V2_CL
| where TimeGenerated >= now(-1h)
| where Source == "StorageAccount"
| where toint(SandboxScore) >= 50
incidentConfiguration:
  groupingConfiguration:
    groupByCustomDetails:
    - SandboxVerdict
    lookbackDuration: 1h
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
  createIncident: true
name: Recorded Future Sandbox - Malicious File in Storage Account
triggerOperator: gt
query: |
  RecordedFutureSandboxResults_V2_CL
  | where TimeGenerated >= now(-1h)
  | where Source == "StorageAccount"
  | where toint(SandboxScore) >= 50
queryFrequency: 1h
description: |
  'Creates incidents when Recorded Future Sandbox detects malicious files from Azure Storage Account'
id: a1b2c3d4-5678-90ab-cdef-333333333333
triggerThreshold: 0
version: 2.0.0
queryPeriod: 1h
status: Available
kind: NRT
customDetails:
  SampleId: SampleId
  SandboxVerdict: SandboxVerdict
  Source: Source
  SandboxScore: SandboxScore
  FileName: FileName
relevantTechniques: []
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Medium
requiredDataConnectors:
- connectorId: RecordedFuture
  dataTypes:
  - RecordedFutureSandboxResults_V2_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxStorageAccount.yaml
alertDetailsOverride:
  alertDescriptionFormat: |
    _Recorded Future Sandbox - Malicious File in Storage Account_

    **Sandbox Score:** {{SandboxScore}}/100

    **Verdict:** {{SandboxVerdict}}

    **Sample ID:** {{SampleId}}

    A malicious file was detected in an Azure Storage Account. Investigate the source of this file and review the full sandbox report.
  alertDisplayNameFormat: 'Malicious File in Storage: {{FileName}}'
tactics: []
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: FileName
  entityType: File
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/a1b2c3d4-5678-90ab-cdef-333333333333')]",
      "kind": "NRT",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/a1b2c3d4-5678-90ab-cdef-333333333333')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "_Recorded Future Sandbox - Malicious File in Storage Account_\n\n**Sandbox Score:** {{SandboxScore}}/100\n\n**Verdict:** {{SandboxVerdict}}\n\n**Sample ID:** {{SampleId}}\n\nA malicious file was detected in an Azure Storage Account. Investigate the source of this file and review the full sandbox report.\n",
          "alertDisplayNameFormat": "Malicious File in Storage: {{FileName}}"
        },
        "alertRuleTemplateName": "a1b2c3d4-5678-90ab-cdef-333333333333",
        "customDetails": {
          "FileName": "FileName",
          "SampleId": "SampleId",
          "SandboxScore": "SandboxScore",
          "SandboxVerdict": "SandboxVerdict",
          "Source": "Source"
        },
        "description": "'Creates incidents when Recorded Future Sandbox detects malicious files from Azure Storage Account'\n",
        "displayName": "Recorded Future Sandbox - Malicious File in Storage Account",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "File",
            "fieldMappings": [
              {
                "columnName": "FileName",
                "identifier": "Name"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "SandboxVerdict"
            ],
            "lookbackDuration": "PT1H",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Analytic%20Rules/IncidentCreation/RecordedFutureSandboxStorageAccount.yaml",
        "query": "RecordedFutureSandboxResults_V2_CL\n| where TimeGenerated >= now(-1h)\n| where Source == \"StorageAccount\"\n| where toint(SandboxScore) >= 50\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [],
        "techniques": [],
        "templateVersion": "2.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}