Analytic rule catalog
Contrast ADR - Exploited Attack Event
Back
| Id | ae4f67a6-0713-4a26-ae61-284e67b408c1 |
| Rulename | Contrast ADR - Exploited Attack Event |
| Description | Detects successful exploitation of security vulnerabilities across all environments as identified by Contrast ADR. This rule captures confirmed exploited attacks that bypassed application security controls and require security team investigation. |
| Severity | High |
| Tactics | InitialAccess Execution DefenseEvasion LateralMovement CommandAndControl |
| Techniques | T1190 T1059 T1055 T1210 T1008 |
| Required data connectors | ContrastADRCCF |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic%20Rules/Contrast_ADR_Exploited_Attack_Event.yaml |
| Version | 1.0.1 |
| Arm template | ae4f67a6-0713-4a26-ae61-284e67b408c1.json |
ContrastADRAttackEvents_CL
| where result =~ "exploited"
incidentConfiguration:
groupingConfiguration:
lookbackDuration: PT1H
enabled: true
reopenClosedIncident: false
matchingMethod: Selected
groupByEntities:
- IP
- Host
createIncident: true
name: Contrast ADR - Exploited Attack Event
triggerOperator: gt
query: |
ContrastADRAttackEvents_CL
| where result =~ "exploited"
queryFrequency: 5m
description: |
'Detects successful exploitation of security vulnerabilities across all environments as identified by Contrast ADR. This rule captures confirmed exploited attacks that bypassed application security controls and require security team investigation.'
id: ae4f67a6-0713-4a26-ae61-284e67b408c1
triggerThreshold: 0
queryPeriod: 5m
version: 1.0.1
kind: Scheduled
customDetails:
Environment: environment
TargetHost: host_hostname
AttackResult: result
ApplicationName: application_name
AttackedEndpoint: request_headers_referer
AttackRule: rule
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: ContrastADRCCF
dataTypes:
- ContrastADRAttackEvents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic%20Rules/Contrast_ADR_Exploited_Attack_Event.yaml
alertDetailsOverride:
alertDescriptionFormat: '{{result}} on {{request_headers_referer}} endpoint of {{application_name}} '
alertDisplayNameFormat: '{{result}} {{rule}} from {{sourceIp}} '
relevantTechniques:
- T1190
- T1059
- T1055
- T1210
- T1008
tactics:
- InitialAccess
- Execution
- DefenseEvasion
- LateralMovement
- CommandAndControl
entityMappings:
- fieldMappings:
- identifier: Address
columnName: sourceIp
entityType: IP
- fieldMappings:
- identifier: HostName
columnName: host_hostname
entityType: Host
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/ae4f67a6-0713-4a26-ae61-284e67b408c1')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/ae4f67a6-0713-4a26-ae61-284e67b408c1')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "{{result}} on {{request_headers_referer}} endpoint of {{application_name}} ",
"alertDisplayNameFormat": "{{result}} {{rule}} from {{sourceIp}} "
},
"alertRuleTemplateName": "ae4f67a6-0713-4a26-ae61-284e67b408c1",
"customDetails": {
"ApplicationName": "application_name",
"AttackedEndpoint": "request_headers_referer",
"AttackResult": "result",
"AttackRule": "rule",
"Environment": "environment",
"TargetHost": "host_hostname"
},
"description": "'Detects successful exploitation of security vulnerabilities across all environments as identified by Contrast ADR. This rule captures confirmed exploited attacks that bypassed application security controls and require security team investigation.'\n",
"displayName": "Contrast ADR - Exploited Attack Event",
"enabled": true,
"entityMappings": [
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "sourceIp",
"identifier": "Address"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "host_hostname",
"identifier": "HostName"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByEntities": [
"IP",
"Host"
],
"lookbackDuration": "PT1H",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContrastADR/Analytic%20Rules/Contrast_ADR_Exploited_Attack_Event.yaml",
"query": "ContrastADRAttackEvents_CL\n| where result =~ \"exploited\"\n",
"queryFrequency": "PT5M",
"queryPeriod": "PT5M",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"DefenseEvasion",
"Execution",
"InitialAccess",
"LateralMovement"
],
"techniques": [
"T1008",
"T1055",
"T1059",
"T1190",
"T1210"
],
"templateVersion": "1.0.1",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}