{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
      "properties": {
        "alertRuleTemplateName": "b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41",
        "customDetails": null,
        "description": "Detects activity involving risky or low Cloud Confidence Level (CCL) applications,\nblocked application actions, or sensitive activities (upload, share, download) on\nunsanctioned apps. Helps surface Shadow IT and potential data leakage via risky\ncloud applications.\n",
        "displayName": "Netskope - Suspicious Application Activity (Low Confidence / Risky App)",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "User",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "Userip",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml",
        "query": "let riskyCcl = dynamic([\"low\", \"poor\"]);\nlet sensitiveActivities = dynamic([\"Upload\", \"Share\", \"Download\", \"Post\", \"Send\"]);\nNetskopeAlertEvents_CL\n| where TimeGenerated > ago(1h)\n| where isnotempty(App)\n| where tolower(Ccl) in (riskyCcl)\n     or Action =~ \"block\"\n     or (Activity in~ (sensitiveActivities) and tolower(Ccl) != \"excellent\")\n| summarize\n    EventCount = count(),\n    Activities = make_set(Activity, 20),\n    Actions = make_set(Action, 10),\n    CCLs = make_set(Ccl, 10),\n    Categories = make_set(Appcategory, 20),\n    DistinctApps = dcount(App),\n    Apps = make_set(App, 20),\n    LastSeen = max(TimeGenerated)\n    by User, Userip, Hostname, DeviceClassification\n| where EventCount > 5 or DistinctApps > 3\n| extend RiskIndicators = strcat_array(array_concat(\n    iff(set_has_element(CCLs, \"low\") or set_has_element(CCLs, \"poor\"), dynamic([\"Low Confidence App\"]), dynamic([])),\n    iff(set_has_element(Actions, \"block\"), dynamic([\"Blocked Activity\"]), dynamic([])),\n    iff(DistinctApps > 3, dynamic([\"Multiple Risky Apps\"]), dynamic([]))\n), \", \")\n| order by EventCount desc\n| project\n    LastSeen,\n    User,\n    Userip,\n    Hostname,\n    DeviceClassification,\n    EventCount,\n    DistinctApps,\n    Apps,\n    Categories,\n    Activities,\n    Actions,\n    CCLs,\n    RiskIndicators\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Exfiltration"
        ],
        "techniques": [
          "T1102",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}
