Back
Idb2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41
RulenameNetskope - Suspicious Application Activity (Low Confidence / Risky App)
DescriptionDetects activity involving risky or low Cloud Confidence Level (CCL) applications,

blocked application actions, or sensitive activities (upload, share, download) on

unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky

cloud applications.
SeverityMedium
TacticsExfiltration
CommandAndControl
TechniquesT1567
T1102
Required data connectorsNetskopeAlertEventsConnector
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml
Version1.0.0
Arm templateb2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41.json
Deploy To Azure
let riskyCcl = dynamic(["low", "poor"]);
let sensitiveActivities = dynamic(["Upload", "Share", "Download", "Post", "Send"]);
NetskopeAlertEvents_CL
| where TimeGenerated > ago(1h)
| where isnotempty(App)
| where tolower(Ccl) in (riskyCcl)
     or Action =~ "block"
     or (Activity in~ (sensitiveActivities) and tolower(Ccl) != "excellent")
| summarize
    EventCount = count(),
    Activities = make_set(Activity, 20),
    Actions = make_set(Action, 10),
    CCLs = make_set(Ccl, 10),
    Categories = make_set(Appcategory, 20),
    DistinctApps = dcount(App),
    Apps = make_set(App, 20),
    LastSeen = max(TimeGenerated)
    by User, Userip, Hostname, DeviceClassification
| where EventCount > 5 or DistinctApps > 3
| extend RiskIndicators = strcat_array(array_concat(
    iff(set_has_element(CCLs, "low") or set_has_element(CCLs, "poor"), dynamic(["Low Confidence App"]), dynamic([])),
    iff(set_has_element(Actions, "block"), dynamic(["Blocked Activity"]), dynamic([])),
    iff(DistinctApps > 3, dynamic(["Multiple Risky Apps"]), dynamic([]))
), ", ")
| order by EventCount desc
| project
    LastSeen,
    User,
    Userip,
    Hostname,
    DeviceClassification,
    EventCount,
    DistinctApps,
    Apps,
    Categories,
    Activities,
    Actions,
    CCLs,
    RiskIndicators
name: Netskope - Suspicious Application Activity (Low Confidence / Risky App)
triggerOperator: gt
query: |
  let riskyCcl = dynamic(["low", "poor"]);
  let sensitiveActivities = dynamic(["Upload", "Share", "Download", "Post", "Send"]);
  NetskopeAlertEvents_CL
  | where TimeGenerated > ago(1h)
  | where isnotempty(App)
  | where tolower(Ccl) in (riskyCcl)
       or Action =~ "block"
       or (Activity in~ (sensitiveActivities) and tolower(Ccl) != "excellent")
  | summarize
      EventCount = count(),
      Activities = make_set(Activity, 20),
      Actions = make_set(Action, 10),
      CCLs = make_set(Ccl, 10),
      Categories = make_set(Appcategory, 20),
      DistinctApps = dcount(App),
      Apps = make_set(App, 20),
      LastSeen = max(TimeGenerated)
      by User, Userip, Hostname, DeviceClassification
  | where EventCount > 5 or DistinctApps > 3
  | extend RiskIndicators = strcat_array(array_concat(
      iff(set_has_element(CCLs, "low") or set_has_element(CCLs, "poor"), dynamic(["Low Confidence App"]), dynamic([])),
      iff(set_has_element(Actions, "block"), dynamic(["Blocked Activity"]), dynamic([])),
      iff(DistinctApps > 3, dynamic(["Multiple Risky Apps"]), dynamic([]))
  ), ", ")
  | order by EventCount desc
  | project
      LastSeen,
      User,
      Userip,
      Hostname,
      DeviceClassification,
      EventCount,
      DistinctApps,
      Apps,
      Categories,
      Activities,
      Actions,
      CCLs,
      RiskIndicators
queryFrequency: 1h
description: |
  Detects activity involving risky or low Cloud Confidence Level (CCL) applications,
  blocked application actions, or sensitive activities (upload, share, download) on
  unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky
  cloud applications.
id: b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeAlertEventsConnector
  dataTypes:
  - NetskopeAlertEvents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml
relevantTechniques:
- T1567
- T1102
tactics:
- Exfiltration
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: User
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: Userip
  entityType: IP
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41')]",
      "properties": {
        "alertRuleTemplateName": "b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41",
        "customDetails": null,
        "description": "Detects activity involving risky or low Cloud Confidence Level (CCL) applications,\nblocked application actions, or sensitive activities (upload, share, download) on\nunsanctioned apps. Helps surface Shadow IT and potential data leakage via risky\ncloud applications.\n",
        "displayName": "Netskope - Suspicious Application Activity (Low Confidence / Risky App)",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "User",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "Userip",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeAlertEvents/Analytic%20Rules/NetskopeAlertEvents_Rule2.yaml",
        "query": "let riskyCcl = dynamic([\"low\", \"poor\"]);\nlet sensitiveActivities = dynamic([\"Upload\", \"Share\", \"Download\", \"Post\", \"Send\"]);\nNetskopeAlertEvents_CL\n| where TimeGenerated > ago(1h)\n| where isnotempty(App)\n| where tolower(Ccl) in (riskyCcl)\n     or Action =~ \"block\"\n     or (Activity in~ (sensitiveActivities) and tolower(Ccl) != \"excellent\")\n| summarize\n    EventCount = count(),\n    Activities = make_set(Activity, 20),\n    Actions = make_set(Action, 10),\n    CCLs = make_set(Ccl, 10),\n    Categories = make_set(Appcategory, 20),\n    DistinctApps = dcount(App),\n    Apps = make_set(App, 20),\n    LastSeen = max(TimeGenerated)\n    by User, Userip, Hostname, DeviceClassification\n| where EventCount > 5 or DistinctApps > 3\n| extend RiskIndicators = strcat_array(array_concat(\n    iff(set_has_element(CCLs, \"low\") or set_has_element(CCLs, \"poor\"), dynamic([\"Low Confidence App\"]), dynamic([])),\n    iff(set_has_element(Actions, \"block\"), dynamic([\"Blocked Activity\"]), dynamic([])),\n    iff(DistinctApps > 3, dynamic([\"Multiple Risky Apps\"]), dynamic([]))\n), \", \")\n| order by EventCount desc\n| project\n    LastSeen,\n    User,\n    Userip,\n    Hostname,\n    DeviceClassification,\n    EventCount,\n    DistinctApps,\n    Apps,\n    Categories,\n    Activities,\n    Actions,\n    CCLs,\n    RiskIndicators\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Exfiltration"
        ],
        "techniques": [
          "T1102",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}