SINECSecurityGuard_CL
| where ipv4_is_private(source_ip) or ipv4_is_private(destination_ip)
| project source_ip, destination_ip, signature_id, signature_name
version: 1.0.0
description: The security analytic rule is designed to scrutinize network activity involving private IP addresses within an organization's internal network. By filtering log entries to include only those where either the source or the destination IP is private, the rule focuses on internal communications that could indicate unauthorized access, internal threats, or other security anomalies.
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: source_ip
- entityType: IP
fieldMappings:
- identifier: Address
columnName: destination_ip
eventGroupingSettings:
aggregationKind: AlertPerResult
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SINEC Security Guard/Analytic Rules/SSG_Azure_Sentinel_analytic_rule.yaml
tactics:
- Impact
relevantTechniques:
- T1486
alertDetailsOverride:
alertDynamicProperties: []
alertDisplayNameFormat: '{{signature_name}} '
alertDescriptionFormat: 'Alert {{signature_name}} generated from {{source_ip}} to {{destination_ip}} '
suppressionEnabled: false
severity: HIGH
kind: NRT
incidentConfiguration:
groupingConfiguration:
groupByEntities:
- IP
enabled: true
groupByAlertDetails: []
groupByCustomDetails:
- Source_IP
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5m
createIncident: true
id: d41fa731-45a2-4b23-bb1d-29896fbc5298
query: |
SINECSecurityGuard_CL
| where ipv4_is_private(source_ip) or ipv4_is_private(destination_ip)
| project source_ip, destination_ip, signature_id, signature_name
suppressionDuration: 5h
customDetails:
Source_IP: source_ip
name: SSG_Security_Incidents