Back
Idbd550c7f-5455-48de-b23d-30fced82d02b
RulenamePRODAFT USTA - Payment card exposed
DescriptionIdentifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a

compromised payment card belonging to the monitored company. These typically originate

from card breaches, skimmers, or infostealer infections and indicate that a payment card

may be available to fraudsters. The full card number is never stored - only the BIN,

last 4 digits, brand, and length are retained. Investigate the exposure and, where the

card is your own, coordinate reissue with the issuing bank.
SeverityMedium
TacticsImpact
TechniquesT1657
Required data connectorsPRODAFTUstaPCFICCPDefinition
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/PaymentCardExposed.yaml
Version1.0.0
Arm templatebd550c7f-5455-48de-b23d-30fced82d02b.json
Deploy To Azure
PRODAFTUstaCompromisedCards
| where Created > ago(1h)
| project
    TimeGenerated,
    Created,
    TicketId,
    CompanyName,
    CardBrand,
    CardBin,
    CardLast4,
    CardMasked,
    CardLength,
    ExpirationDate,
    Status
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 1h
    reopenClosedIncident: false
    matchingMethod: AnyAlert
    enabled: true
  createIncident: true
name: PRODAFT USTA - Payment card exposed
triggerOperator: gt
query: |
  PRODAFTUstaCompromisedCards
  | where Created > ago(1h)
  | project
      TimeGenerated,
      Created,
      TicketId,
      CompanyName,
      CardBrand,
      CardBin,
      CardLast4,
      CardMasked,
      CardLength,
      ExpirationDate,
      Status
queryFrequency: 1h
description: |
  'Identifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a
  compromised payment card belonging to the monitored company. These typically originate
  from card breaches, skimmers, or infostealer infections and indicate that a payment card
  may be available to fraudsters. The full card number is never stored - only the BIN,
  last 4 digits, brand, and length are retained. Investigate the exposure and, where the
  card is your own, coordinate reissue with the issuing bank.'
id: bd550c7f-5455-48de-b23d-30fced82d02b
triggerThreshold: 0
queryPeriod: 1h
status: Available
kind: Scheduled
customDetails:
  Card: CardMasked
  Company: CompanyName
  Expiration: ExpirationDate
  Brand: CardBrand
  Ticket: TicketId
  Status: Status
relevantTechniques:
- T1657
severity: Medium
requiredDataConnectors:
- connectorId: PRODAFTUstaPCFICCPDefinition
  dataTypes:
  - PRODAFTUstaCompromisedCards_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/PaymentCardExposed.yaml
tactics:
- Impact
version: 1.0.0
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/bd550c7f-5455-48de-b23d-30fced82d02b')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/bd550c7f-5455-48de-b23d-30fced82d02b')]",
      "properties": {
        "alertRuleTemplateName": "bd550c7f-5455-48de-b23d-30fced82d02b",
        "customDetails": {
          "Brand": "CardBrand",
          "Card": "CardMasked",
          "Company": "CompanyName",
          "Expiration": "ExpirationDate",
          "Status": "Status",
          "Ticket": "TicketId"
        },
        "description": "'Identifies a new PRODAFT USTA Payment Card Fraud Intelligence ticket that exposes a\ncompromised payment card belonging to the monitored company. These typically originate\nfrom card breaches, skimmers, or infostealer infections and indicate that a payment card\nmay be available to fraudsters. The full card number is never stored - only the BIN,\nlast 4 digits, brand, and length are retained. Investigate the exposure and, where the\ncard is your own, coordinate reissue with the issuing bank.'\n",
        "displayName": "PRODAFT USTA - Payment card exposed",
        "enabled": true,
        "entityMappings": null,
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT1H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/PRODAFT%20USTA%20-%20Payment%20Card%20Fraud%20Intelligence/Analytic%20Rules/PaymentCardExposed.yaml",
        "query": "PRODAFTUstaCompromisedCards\n| where Created > ago(1h)\n| project\n    TimeGenerated,\n    Created,\n    TicketId,\n    CompanyName,\n    CardBrand,\n    CardBin,\n    CardLast4,\n    CardMasked,\n    CardLength,\n    ExpirationDate,\n    Status\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Impact"
        ],
        "techniques": [
          "T1657"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}