Back
Idac008972-e70f-4040-96ad-bdce1c642839
RulenameUniqkey - Security policy change
DescriptionDetects modifications to Uniqkey organization security policies, such as authentication, password or sharing policy settings. Weakening a policy is a common preparatory step before credential abuse, and even legitimate changes deserve a review trail, so each policy change is raised as an alert with the acting administrator attached.
SeverityMedium
TacticsDefenseEvasion
Persistence
TechniquesT1562
Required data connectorsUniqkeyEventsConnector
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Security%20policy%20change.yaml
Version1.0.0
Arm templateac008972-e70f-4040-96ad-bdce1c642839.json
Deploy To Azure
UniqkeyEvents_CL
| where Category == "policy_management"
| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, TargetType, TargetName, ClientSystem, SrcIpAddr
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 5h
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: Uniqkey - Security policy change
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Detects modifications to Uniqkey organization security policies, such as authentication, password or sharing policy settings. Weakening a policy is a common preparatory step before credential abuse, and even legitimate changes deserve a review trail, so each policy change is raised as an alert with the acting administrator attached.
id: ac008972-e70f-4040-96ad-bdce1c642839
triggerThreshold: 0
queryPeriod: 1h
query: |-
  UniqkeyEvents_CL
  | where Category == "policy_management"
  | project TimeGenerated, ActorEmail, ActorType, Action, ActionId, TargetType, TargetName, ClientSystem, SrcIpAddr
version: 1.0.0
requiredDataConnectors:
- connectorId: UniqkeyEventsConnector
  dataTypes:
  - UniqkeyEvents_CL
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Medium
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Security%20policy%20change.yaml
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
- Persistence
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: ActorEmail
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: SrcIpAddr
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/ac008972-e70f-4040-96ad-bdce1c642839')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/ac008972-e70f-4040-96ad-bdce1c642839')]",
      "properties": {
        "alertRuleTemplateName": "ac008972-e70f-4040-96ad-bdce1c642839",
        "customDetails": null,
        "description": "Detects modifications to Uniqkey organization security policies, such as authentication, password or sharing policy settings. Weakening a policy is a common preparatory step before credential abuse, and even legitimate changes deserve a review trail, so each policy change is raised as an alert with the acting administrator attached.",
        "displayName": "Uniqkey - Security policy change",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "ActorEmail",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIpAddr",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Security%20policy%20change.yaml",
        "query": "UniqkeyEvents_CL\n| where Category == \"policy_management\"\n| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, TargetType, TargetName, ClientSystem, SrcIpAddr",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion",
          "Persistence"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}