Back
Idb2c3d4e5-f6a7-8901-bcde-f12345678902
RulenameGTI - High and Critical Priority Alerts
DescriptionTriggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL

is ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring

immediate attention based on relevance, severity, and potential business impact.

Each unique Alert ID is grouped into a single incident.
SeverityHigh
TacticsInitialAccess
Impact
CredentialAccess
Exfiltration
TechniquesT1566
T1078
T1552
T1486
T1567
Required data connectorsGoogleThreatIntelligenceRelevanceSystemAlertsAPI
KindScheduled
Query frequency5m
Query period5m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml
Version1.0.0
Arm templateb2c3d4e5-f6a7-8901-bcde-f12345678902.json
Deploy To Azure
GTIRelevanceSystemAlerts
| where PriorityLevel in ("HIGH", "CRITICAL")
| extend
    DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, "")
| project
    TimeGenerated,
    AlertId,
    AlertName          = DisplayName,
    AlertState         = State,
    PriorityLevel,
    PriorityReasoning,
    SeverityLevel,
    SeverityConfidence,
    DetailType,
    DetailSeverity,
    RelevanceLevel,
    FindingCount,
    AiSummary,
    AuditCreateTime,
    AuditUpdateTime
requiredDataConnectors:
- dataTypes:
  - RelevanceSystemAlerts_CL
  connectorId: GoogleThreatIntelligenceRelevanceSystemAlertsAPI
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml
version: 1.0.0
status: Available
alertDetailsOverride:
  alertDescriptionFormat: |
    Priority: {{PriorityLevel}}

    Priority Reasoning: {{PriorityReasoning}}

    Summary: {{AiSummary}}
  alertDisplayNameFormat: 'GTI High/Critical Priority Alert: {{AlertName}}'
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: P5D
    matchingMethod: Selected
    reopenClosedIncident: false
    enabled: true
    groupByCustomDetails:
    - AlertId
  createIncident: true
queryFrequency: 5m
query: |
  GTIRelevanceSystemAlerts
  | where PriorityLevel in ("HIGH", "CRITICAL")
  | extend
      DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, "")
  | project
      TimeGenerated,
      AlertId,
      AlertName          = DisplayName,
      AlertState         = State,
      PriorityLevel,
      PriorityReasoning,
      SeverityLevel,
      SeverityConfidence,
      DetailType,
      DetailSeverity,
      RelevanceLevel,
      FindingCount,
      AiSummary,
      AuditCreateTime,
      AuditUpdateTime
tactics:
- InitialAccess
- Impact
- CredentialAccess
- Exfiltration
relevantTechniques:
- T1566
- T1078
- T1552
- T1486
- T1567
id: b2c3d4e5-f6a7-8901-bcde-f12345678902
triggerThreshold: 0
triggerOperator: gt
name: GTI - High and Critical Priority Alerts
queryPeriod: 5m
severity: High
customDetails:
  DetailType: DetailType
  FindingCount: FindingCount
  AlertId: AlertId
  SeverityLevel: SeverityLevel
  AlertState: AlertState
  PriorityLevel: PriorityLevel
kind: Scheduled
eventGroupingSettings:
  aggregationKind: AlertPerResult
description: |
  Triggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL
  is ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring
  immediate attention based on relevance, severity, and potential business impact.
  Each unique Alert ID is grouped into a single incident.
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b2c3d4e5-f6a7-8901-bcde-f12345678902')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b2c3d4e5-f6a7-8901-bcde-f12345678902')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Priority: {{PriorityLevel}}\n\nPriority Reasoning: {{PriorityReasoning}}\n\nSummary: {{AiSummary}}\n",
          "alertDisplayNameFormat": "GTI High/Critical Priority Alert: {{AlertName}}"
        },
        "alertRuleTemplateName": "b2c3d4e5-f6a7-8901-bcde-f12345678902",
        "customDetails": {
          "AlertId": "AlertId",
          "AlertState": "AlertState",
          "DetailType": "DetailType",
          "FindingCount": "FindingCount",
          "PriorityLevel": "PriorityLevel",
          "SeverityLevel": "SeverityLevel"
        },
        "description": "Triggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL\nis ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring\nimmediate attention based on relevance, severity, and potential business impact.\nEach unique Alert ID is grouped into a single incident.\n",
        "displayName": "GTI - High and Critical Priority Alerts",
        "enabled": true,
        "entityMappings": null,
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "AlertId"
            ],
            "lookbackDuration": "P5D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml",
        "query": "GTIRelevanceSystemAlerts\n| where PriorityLevel in (\"HIGH\", \"CRITICAL\")\n| extend\n    DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, \"\")\n| project\n    TimeGenerated,\n    AlertId,\n    AlertName          = DisplayName,\n    AlertState         = State,\n    PriorityLevel,\n    PriorityReasoning,\n    SeverityLevel,\n    SeverityConfidence,\n    DetailType,\n    DetailSeverity,\n    RelevanceLevel,\n    FindingCount,\n    AiSummary,\n    AuditCreateTime,\n    AuditUpdateTime\n",
        "queryFrequency": "PT5M",
        "queryPeriod": "PT5M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess",
          "Exfiltration",
          "Impact",
          "InitialAccess"
        ],
        "techniques": [
          "T1078",
          "T1486",
          "T1552",
          "T1566",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}