Back
Idb1a2c3d4-1234-5678-90ab-cdef12345001
RulenameTailscale: Device key expiring within 7 days
DescriptionIdentifies tailnet devices whose machine key expires within the next 7 days and where key expiry is not disabled. Surface proactively so renewal can be scheduled rather than forced during an outage.
SeverityMedium
TacticsInitialAccess
TechniquesT1078
Required data connectorsTailscaleCCF
KindScheduled
Query frequency6h
Query period6h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscaleDeviceKeyExpiringSoon.yaml
Version1.0.0
Arm templateb1a2c3d4-1234-5678-90ab-cdef12345001.json
Deploy To Azure
Tailscale_Devices_CL
| where TimeGenerated > ago(6h)
| summarize arg_max(TimeGenerated, *) by DeviceId
| where KeyExpiryDisabled == false
| where isnotnull(Expires)
| where Expires between (now() .. now() + 7d)
| extend DaysToExpiry = datetime_diff('day', Expires, now())
| project TimeGenerated, DeviceName, Hostname, User, Os, DaysToExpiry, Expires, LastSeen
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: P1D
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'Tailscale: Device key expiring within 7 days'
triggerOperator: gt
query: |
  Tailscale_Devices_CL
  | where TimeGenerated > ago(6h)
  | summarize arg_max(TimeGenerated, *) by DeviceId
  | where KeyExpiryDisabled == false
  | where isnotnull(Expires)
  | where Expires between (now() .. now() + 7d)
  | extend DaysToExpiry = datetime_diff('day', Expires, now())
  | project TimeGenerated, DeviceName, Hostname, User, Os, DaysToExpiry, Expires, LastSeen
queryFrequency: 6h
description: |
  Identifies tailnet devices whose machine key expires within the next 7 days and where key expiry is not disabled. Surface proactively so renewal can be scheduled rather than forced during an outage.
id: b1a2c3d4-1234-5678-90ab-cdef12345001
triggerThreshold: 0
queryPeriod: 6h
version: 1.0.0
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: TailscaleCCF
  dataTypes:
  - Tailscale_Devices_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscaleDeviceKeyExpiringSoon.yaml
relevantTechniques:
- T1078
tactics:
- InitialAccess
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
- fieldMappings:
  - identifier: FullName
    columnName: User
  entityType: Account
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b1a2c3d4-1234-5678-90ab-cdef12345001')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b1a2c3d4-1234-5678-90ab-cdef12345001')]",
      "properties": {
        "alertRuleTemplateName": "b1a2c3d4-1234-5678-90ab-cdef12345001",
        "customDetails": null,
        "description": "Identifies tailnet devices whose machine key expires within the next 7 days and where key expiry is not disabled. Surface proactively so renewal can be scheduled rather than forced during an outage.\n",
        "displayName": "Tailscale: Device key expiring within 7 days",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "User",
                "identifier": "FullName"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "P1D",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscaleDeviceKeyExpiringSoon.yaml",
        "query": "Tailscale_Devices_CL\n| where TimeGenerated > ago(6h)\n| summarize arg_max(TimeGenerated, *) by DeviceId\n| where KeyExpiryDisabled == false\n| where isnotnull(Expires)\n| where Expires between (now() .. now() + 7d)\n| extend DaysToExpiry = datetime_diff('day', Expires, now())\n| project TimeGenerated, DeviceName, Hostname, User, Os, DaysToExpiry, Expires, LastSeen\n",
        "queryFrequency": "PT6H",
        "queryPeriod": "PT6H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "InitialAccess"
        ],
        "techniques": [
          "T1078"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}