Analytic rule catalog
Netskope - Suspicious Application Activity Low Confidence Risky App
Back
| Id | b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41 |
| Rulename | Netskope - Suspicious Application Activity (Low Confidence / Risky App) |
| Description | Detects activity involving risky or low Cloud Confidence Level (CCL) applications, blocked application actions, or sensitive activities (upload, share, download) on unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky cloud applications. |
| Severity | Medium |
| Tactics | Exfiltration CommandAndControl |
| Techniques | T1567 T1102 |
| Required data connectors | NetskopeAlertEventsConnector |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml |
| Version | 1.0.0 |
| Arm template | b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41.json |
let riskyCcl = dynamic(["low", "poor"]);
let sensitiveActivities = dynamic(["Upload", "Share", "Download", "Post", "Send"]);
NetskopeAlertEvents_CL
| where TimeGenerated > ago(1h)
| where isnotempty(App)
| where tolower(Ccl) in (riskyCcl)
or Action =~ "block"
or (Activity in~ (sensitiveActivities) and tolower(Ccl) != "excellent")
| summarize
EventCount = count(),
Activities = make_set(Activity, 20),
Actions = make_set(Action, 10),
CCLs = make_set(Ccl, 10),
Categories = make_set(Appcategory, 20),
DistinctApps = dcount(App),
Apps = make_set(App, 20),
LastSeen = max(TimeGenerated)
by User, Userip, Hostname, DeviceClassification
| where EventCount > 5 or DistinctApps > 3
| extend RiskIndicators = strcat_array(array_concat(
iff(set_has_element(CCLs, "low") or set_has_element(CCLs, "poor"), dynamic(["Low Confidence App"]), dynamic([])),
iff(set_has_element(Actions, "block"), dynamic(["Blocked Activity"]), dynamic([])),
iff(DistinctApps > 3, dynamic(["Multiple Risky Apps"]), dynamic([]))
), ", ")
| order by EventCount desc
| project
LastSeen,
User,
Userip,
Hostname,
DeviceClassification,
EventCount,
DistinctApps,
Apps,
Categories,
Activities,
Actions,
CCLs,
RiskIndicators
name: Netskope - Suspicious Application Activity (Low Confidence / Risky App)
triggerOperator: gt
query: |
let riskyCcl = dynamic(["low", "poor"]);
let sensitiveActivities = dynamic(["Upload", "Share", "Download", "Post", "Send"]);
NetskopeAlertEvents_CL
| where TimeGenerated > ago(1h)
| where isnotempty(App)
| where tolower(Ccl) in (riskyCcl)
or Action =~ "block"
or (Activity in~ (sensitiveActivities) and tolower(Ccl) != "excellent")
| summarize
EventCount = count(),
Activities = make_set(Activity, 20),
Actions = make_set(Action, 10),
CCLs = make_set(Ccl, 10),
Categories = make_set(Appcategory, 20),
DistinctApps = dcount(App),
Apps = make_set(App, 20),
LastSeen = max(TimeGenerated)
by User, Userip, Hostname, DeviceClassification
| where EventCount > 5 or DistinctApps > 3
| extend RiskIndicators = strcat_array(array_concat(
iff(set_has_element(CCLs, "low") or set_has_element(CCLs, "poor"), dynamic(["Low Confidence App"]), dynamic([])),
iff(set_has_element(Actions, "block"), dynamic(["Blocked Activity"]), dynamic([])),
iff(DistinctApps > 3, dynamic(["Multiple Risky Apps"]), dynamic([]))
), ", ")
| order by EventCount desc
| project
LastSeen,
User,
Userip,
Hostname,
DeviceClassification,
EventCount,
DistinctApps,
Apps,
Categories,
Activities,
Actions,
CCLs,
RiskIndicators
queryFrequency: 1h
description: |
Detects activity involving risky or low Cloud Confidence Level (CCL) applications,
blocked application actions, or sensitive activities (upload, share, download) on
unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky
cloud applications.
id: b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeAlertEventsConnector
dataTypes:
- NetskopeAlertEvents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml
relevantTechniques:
- T1567
- T1102
tactics:
- Exfiltration
- CommandAndControl
entityMappings:
- fieldMappings:
- identifier: Name
columnName: User
entityType: Account
- fieldMappings:
- identifier: Address
columnName: Userip
entityType: IP
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
"properties": {
"alertRuleTemplateName": "b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41",
"customDetails": null,
"description": "Detects activity involving risky or low Cloud Confidence Level (CCL) applications,\nblocked application actions, or sensitive activities (upload, share, download) on\nunsanctioned apps. Helps surface Shadow IT and potential data leakage via risky\ncloud applications.\n",
"displayName": "Netskope - Suspicious Application Activity (Low Confidence / Risky App)",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "User",
"identifier": "Name"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "Userip",
"identifier": "Address"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
}
],
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml",
"query": "let riskyCcl = dynamic([\"low\", \"poor\"]);\nlet sensitiveActivities = dynamic([\"Upload\", \"Share\", \"Download\", \"Post\", \"Send\"]);\nNetskopeAlertEvents_CL\n| where TimeGenerated > ago(1h)\n| where isnotempty(App)\n| where tolower(Ccl) in (riskyCcl)\n or Action =~ \"block\"\n or (Activity in~ (sensitiveActivities) and tolower(Ccl) != \"excellent\")\n| summarize\n EventCount = count(),\n Activities = make_set(Activity, 20),\n Actions = make_set(Action, 10),\n CCLs = make_set(Ccl, 10),\n Categories = make_set(Appcategory, 20),\n DistinctApps = dcount(App),\n Apps = make_set(App, 20),\n LastSeen = max(TimeGenerated)\n by User, Userip, Hostname, DeviceClassification\n| where EventCount > 5 or DistinctApps > 3\n| extend RiskIndicators = strcat_array(array_concat(\n iff(set_has_element(CCLs, \"low\") or set_has_element(CCLs, \"poor\"), dynamic([\"Low Confidence App\"]), dynamic([])),\n iff(set_has_element(Actions, \"block\"), dynamic([\"Blocked Activity\"]), dynamic([])),\n iff(DistinctApps > 3, dynamic([\"Multiple Risky Apps\"]), dynamic([]))\n), \", \")\n| order by EventCount desc\n| project\n LastSeen,\n User,\n Userip,\n Hostname,\n DeviceClassification,\n EventCount,\n DistinctApps,\n Apps,\n Categories,\n Activities,\n Actions,\n CCLs,\n RiskIndicators\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"Exfiltration"
],
"techniques": [
"T1102",
"T1567"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}