Analytic rule catalog
ContraForce - Destructive workspace action
Back
| Id | c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84 |
| Rulename | ContraForce - Destructive workspace action |
| Description | Identifies destructive actions against the ContraForce workspace or its account: workspace deletion, account deactivation, and account purge. These actions terminate or remove the security service delivery for the affected workspace and should always correspond to a planned offboarding; anything else warrants immediate investigation. |
| Severity | High |
| Tactics | Impact |
| Techniques | T1485 T1531 |
| Required data connectors | ContraForceEvents |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 1d |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContraForce/Analytic%20Rules/ContraForceDestructiveWorkspaceAction.yaml |
| Version | 1.0.0 |
| Arm template | c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84.json |
ContraForceEvents_CL
| where ingestion_time() > ago(5m)
| where ActivityType in ("WorkspaceDeleted", "AccountDeactivated", "AccountPurged")
| extend Meta = parse_json(Metadata)
| project TimeGenerated, EventId, CfWorkspaceId, ActivityType, ActivityAction,
ActorName, ActorEmail, TargetResourceType, TargetResourceId, TargetResourceName, Metadata
incidentConfiguration:
groupingConfiguration:
groupByCustomDetails:
- EventId
lookbackDuration: PT2H
enabled: true
reopenClosedIncident: false
matchingMethod: Selected
createIncident: true
name: ContraForce - Destructive workspace action
triggerOperator: gt
query: |
ContraForceEvents_CL
| where ingestion_time() > ago(5m)
| where ActivityType in ("WorkspaceDeleted", "AccountDeactivated", "AccountPurged")
| extend Meta = parse_json(Metadata)
| project TimeGenerated, EventId, CfWorkspaceId, ActivityType, ActivityAction,
ActorName, ActorEmail, TargetResourceType, TargetResourceId, TargetResourceName, Metadata
queryFrequency: 5m
description: |
'Identifies destructive actions against the ContraForce workspace or its account: workspace
deletion, account deactivation, and account purge. These actions terminate or remove the
security service delivery for the affected workspace and should always correspond to a
planned offboarding; anything else warrants immediate investigation.'
id: c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.0
kind: Scheduled
customDetails:
TargetResourceId: TargetResourceId
CfWorkspaceId: CfWorkspaceId
ActorEmail: ActorEmail
EventId: EventId
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: ContraForceEvents
dataTypes:
- ContraForceEvents_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContraForce/Analytic%20Rules/ContraForceDestructiveWorkspaceAction.yaml
alertDetailsOverride:
alertDescriptionFormat: '{{ActorName}} performed {{ActivityType}} on {{TargetResourceName}}.'
alertDisplayNameFormat: 'ContraForce destructive action: {{ActivityType}} on {{TargetResourceName}}'
relevantTechniques:
- T1485
- T1531
tactics:
- Impact
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "{{ActorName}} performed {{ActivityType}} on {{TargetResourceName}}.",
"alertDisplayNameFormat": "ContraForce destructive action: {{ActivityType}} on {{TargetResourceName}}"
},
"alertRuleTemplateName": "c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84",
"customDetails": {
"ActorEmail": "ActorEmail",
"CfWorkspaceId": "CfWorkspaceId",
"EventId": "EventId",
"TargetResourceId": "TargetResourceId"
},
"description": "'Identifies destructive actions against the ContraForce workspace or its account: workspace\ndeletion, account deactivation, and account purge. These actions terminate or remove the\nsecurity service delivery for the affected workspace and should always correspond to a\nplanned offboarding; anything else warrants immediate investigation.'\n",
"displayName": "ContraForce - Destructive workspace action",
"enabled": true,
"entityMappings": null,
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByCustomDetails": [
"EventId"
],
"lookbackDuration": "PT2H",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ContraForce/Analytic%20Rules/ContraForceDestructiveWorkspaceAction.yaml",
"query": "ContraForceEvents_CL\n| where ingestion_time() > ago(5m)\n| where ActivityType in (\"WorkspaceDeleted\", \"AccountDeactivated\", \"AccountPurged\")\n| extend Meta = parse_json(Metadata)\n| project TimeGenerated, EventId, CfWorkspaceId, ActivityType, ActivityAction,\n ActorName, ActorEmail, TargetResourceType, TargetResourceId, TargetResourceName, Metadata\n",
"queryFrequency": "PT5M",
"queryPeriod": "P1D",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Impact"
],
"techniques": [
"T1485",
"T1531"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}