Back
Idb2c3d4e5-f6a7-8901-bcde-f12345678902
RulenameGTI - High and Critical Priority Alerts
DescriptionTriggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL

is ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring

immediate attention based on relevance, severity, and potential business impact.

Each unique Alert ID is grouped into a single incident.
SeverityHigh
TacticsInitialAccess
Impact
CredentialAccess
Exfiltration
TechniquesT1566
T1078
T1552
T1486
T1567
Required data connectorsGoogleThreatIntelligenceRelevanceSystemAlertsAPI
KindScheduled
Query frequency5m
Query period5m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml
Version1.0.0
Arm templateb2c3d4e5-f6a7-8901-bcde-f12345678902.json
Deploy To Azure
GTIRelevanceSystemAlerts
| where PriorityLevel in ("HIGH", "CRITICAL")
| extend
    DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, "")
| project
    TimeGenerated,
    AlertId,
    AlertName          = DisplayName,
    AlertState         = State,
    PriorityLevel,
    PriorityReasoning,
    SeverityLevel,
    SeverityConfidence,
    DetailType,
    DetailSeverity,
    RelevanceLevel,
    FindingCount,
    AiSummary,
    AuditCreateTime,
    AuditUpdateTime
severity: High
tactics:
- InitialAccess
- Impact
- CredentialAccess
- Exfiltration
queryFrequency: 5m
id: b2c3d4e5-f6a7-8901-bcde-f12345678902
query: |
  GTIRelevanceSystemAlerts
  | where PriorityLevel in ("HIGH", "CRITICAL")
  | extend
      DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, "")
  | project
      TimeGenerated,
      AlertId,
      AlertName          = DisplayName,
      AlertState         = State,
      PriorityLevel,
      PriorityReasoning,
      SeverityLevel,
      SeverityConfidence,
      DetailType,
      DetailSeverity,
      RelevanceLevel,
      FindingCount,
      AiSummary,
      AuditCreateTime,
      AuditUpdateTime
incidentConfiguration:
  groupingConfiguration:
    enabled: true
    lookbackDuration: P5D
    reopenClosedIncident: false
    matchingMethod: Selected
    groupByCustomDetails:
    - AlertId
  createIncident: true
customDetails:
  DetailType: DetailType
  AlertState: AlertState
  PriorityLevel: PriorityLevel
  AlertId: AlertId
  SeverityLevel: SeverityLevel
  FindingCount: FindingCount
kind: Scheduled
triggerOperator: gt
name: GTI - High and Critical Priority Alerts
version: 1.0.0
status: Available
requiredDataConnectors:
- dataTypes:
  - RelevanceSystemAlerts_CL
  connectorId: GoogleThreatIntelligenceRelevanceSystemAlertsAPI
description: |
  Triggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL
  is ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring
  immediate attention based on relevance, severity, and potential business impact.
  Each unique Alert ID is grouped into a single incident.
relevantTechniques:
- T1566
- T1078
- T1552
- T1486
- T1567
queryPeriod: 5m
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml
triggerThreshold: 0
eventGroupingSettings:
  aggregationKind: AlertPerResult
alertDetailsOverride:
  alertDisplayNameFormat: 'GTI High/Critical Priority Alert: {{AlertName}}'
  alertDescriptionFormat: |
    Priority: {{PriorityLevel}}

    Priority Reasoning: {{PriorityReasoning}}

    Summary: {{AiSummary}}
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b2c3d4e5-f6a7-8901-bcde-f12345678902')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b2c3d4e5-f6a7-8901-bcde-f12345678902')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Priority: {{PriorityLevel}}\n\nPriority Reasoning: {{PriorityReasoning}}\n\nSummary: {{AiSummary}}\n",
          "alertDisplayNameFormat": "GTI High/Critical Priority Alert: {{AlertName}}"
        },
        "alertRuleTemplateName": "b2c3d4e5-f6a7-8901-bcde-f12345678902",
        "customDetails": {
          "AlertId": "AlertId",
          "AlertState": "AlertState",
          "DetailType": "DetailType",
          "FindingCount": "FindingCount",
          "PriorityLevel": "PriorityLevel",
          "SeverityLevel": "SeverityLevel"
        },
        "description": "Triggers an incident whenever a GTI Relevance System Alert with priority level HIGH or CRITICAL\nis ingested. These alerts indicate threats that Google Threat Intelligence has assessed as requiring\nimmediate attention based on relevance, severity, and potential business impact.\nEach unique Alert ID is grouped into a single incident.\n",
        "displayName": "GTI - High and Critical Priority Alerts",
        "enabled": true,
        "entityMappings": null,
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "AlertId"
            ],
            "lookbackDuration": "P5D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Threat%20Intelligence/Analytic%20Rules/RelevanceSystemAlerts/GTI_HighCriticalPriorityAlerts.yaml",
        "query": "GTIRelevanceSystemAlerts\n| where PriorityLevel in (\"HIGH\", \"CRITICAL\")\n| extend\n    DetailSeverity = coalesce(DataLeakSeverity, InsiderThreatSeverity, InitialAccessBrokerSeverity, \"\")\n| project\n    TimeGenerated,\n    AlertId,\n    AlertName          = DisplayName,\n    AlertState         = State,\n    PriorityLevel,\n    PriorityReasoning,\n    SeverityLevel,\n    SeverityConfidence,\n    DetailType,\n    DetailSeverity,\n    RelevanceLevel,\n    FindingCount,\n    AiSummary,\n    AuditCreateTime,\n    AuditUpdateTime\n",
        "queryFrequency": "PT5M",
        "queryPeriod": "PT5M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess",
          "Exfiltration",
          "Impact",
          "InitialAccess"
        ],
        "techniques": [
          "T1078",
          "T1486",
          "T1552",
          "T1566",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}