Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

CYFIRMA - Attack Surface - Configuration Medium Rule

Back
Ide1f88d08-5c32-4d35-a8ce-2f21cdb4b6de
RulenameCYFIRMA - Attack Surface - Configuration Medium Rule
DescriptionThis alert is generated when CYFIRMA detects a critical misconfiguration in a public-facing asset or service.

Such misconfigurations may include exposed admin interfaces, default credentials, open directory listings, or insecure protocols, which significantly increase the attack surface."
SeverityMedium
TacticsInitialAccess
Discovery
Persistence
Execution
DefenseEvasion
CredentialAccess
Collection
Reconnaissance
TechniquesT1190
T1087
T1046
T1136
T1059
T1566
T1070
T1027
T1505
T1555
T1114
T1595
Required data connectorsCyfirmaAttackSurfaceAlertsConnector
KindScheduled
Query frequency5m
Query period5m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyfirma Attack Surface/Analytic Rules/ASConfigurationsMediumRule.yaml
Version1.0.1
Arm templatee1f88d08-5c32-4d35-a8ce-2f21cdb4b6de.json
Deploy To Azure
// Medium Severity - Attack Surface - Misconfiguration Detected
let timeFrame = 5m;
CyfirmaASConfigurationAlerts_CL
| where severity == 'High' and TimeGenerated between (ago(timeFrame) .. now())
| extend
    Description=description,
    FirstSeen=first_seen,
    LastSeen=last_seen,
    RiskScore=risk_score,
    Domain=sub_domain,
    TopDomain=top_domain,
    NetworkIP=ip,
    AlertUID=alert_uid,
    UID=uid,
    Softwares=software,
    WebAppFirewall=web_app_firewall,
    ClickJackingDefence=click_jacking_defence,
    ContentSecurityPolicy=content_security_policy,
    CookieXssProtection=cookie_xss_protection,
    DataInjectionDefence=data_injection_defence,
    DomainStatus=domain_status,
    MissingEPPCodes=missing_epp_codes,
    SecureCookie=secure_cookie,
    SetCookieHttpsOnly=set_cookie_https_only,
    XFrameOptions=x_frame_options,
    X_XssProtection=x_xss_protection,
    ProviderName='CYFIRMA',
    ProductName='DeCYFIR/DeTCT'
| project
    TimeGenerated,
    Description,
    Domain,
    TopDomain,
    RiskScore,
    FirstSeen,
    LastSeen,
    NetworkIP,
    AlertUID,
    UID,
    Softwares,
    WebAppFirewall,
    ClickJackingDefence,
    ContentSecurityPolicy,
    CookieXssProtection,
    DataInjectionDefence,
    DomainStatus,
    MissingEPPCodes,
    SecureCookie,
    SetCookieHttpsOnly,
    XFrameOptions,
    X_XssProtection,
    ProviderName,
    ProductName
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cyfirma Attack Surface/Analytic Rules/ASConfigurationsMediumRule.yaml
customDetails:
  X_XssProtection: X_XssProtection
  InjectionDefence: DataInjectionDefence
  SetCookieHttpsOnly: SetCookieHttpsOnly
  Softwares: Softwares
  RiskScore: RiskScore
  XFrameOptions: XFrameOptions
  DomainStatus: DomainStatus
  UID: UID
  WebAppFirewall: WebAppFirewall
  CookieXssProtection: CookieXssProtection
  FirstSeen: FirstSeen
  AlertUID: AlertUID
  SecureCookie: SecureCookie
  LastSeen: LastSeen
  SecurityPolicy: ContentSecurityPolicy
  MissingEPPCodes: MissingEPPCodes
  TimeGenerated: TimeGenerated
  ClickJackingDefence: ClickJackingDefence
relevantTechniques:
- T1190
- T1087
- T1046
- T1136
- T1059
- T1566
- T1070
- T1027
- T1505
- T1555
- T1114
- T1595
entityMappings:
- entityType: DNS
  fieldMappings:
  - identifier: DomainName
    columnName: Domain
- entityType: Host
  fieldMappings:
  - identifier: HostName
    columnName: TopDomain
  - identifier: DnsDomain
    columnName: Domain
- entityType: IP
  fieldMappings:
  - identifier: Address
    columnName: NetworkIP
alertDetailsOverride:
  alertDisplayNameFormat: 'CYFIRMA - Medium Risk Misconfiguration Identified in Assets - Domain: {{Domain}} , IP: {{NetworkIP}}'
  alertDescriptionFormat: CYFIRMA - Medium Risk Misconfiguration Identified in Assets - {{Description}}
  alertDynamicProperties:
  - value: ProductName
    alertProperty: ProductName
  - value: ProviderName
    alertProperty: ProviderName
status: Available
id: e1f88d08-5c32-4d35-a8ce-2f21cdb4b6de
query: |
  // Medium Severity - Attack Surface - Misconfiguration Detected
  let timeFrame = 5m;
  CyfirmaASConfigurationAlerts_CL
  | where severity == 'High' and TimeGenerated between (ago(timeFrame) .. now())
  | extend
      Description=description,
      FirstSeen=first_seen,
      LastSeen=last_seen,
      RiskScore=risk_score,
      Domain=sub_domain,
      TopDomain=top_domain,
      NetworkIP=ip,
      AlertUID=alert_uid,
      UID=uid,
      Softwares=software,
      WebAppFirewall=web_app_firewall,
      ClickJackingDefence=click_jacking_defence,
      ContentSecurityPolicy=content_security_policy,
      CookieXssProtection=cookie_xss_protection,
      DataInjectionDefence=data_injection_defence,
      DomainStatus=domain_status,
      MissingEPPCodes=missing_epp_codes,
      SecureCookie=secure_cookie,
      SetCookieHttpsOnly=set_cookie_https_only,
      XFrameOptions=x_frame_options,
      X_XssProtection=x_xss_protection,
      ProviderName='CYFIRMA',
      ProductName='DeCYFIR/DeTCT'
  | project
      TimeGenerated,
      Description,
      Domain,
      TopDomain,
      RiskScore,
      FirstSeen,
      LastSeen,
      NetworkIP,
      AlertUID,
      UID,
      Softwares,
      WebAppFirewall,
      ClickJackingDefence,
      ContentSecurityPolicy,
      CookieXssProtection,
      DataInjectionDefence,
      DomainStatus,
      MissingEPPCodes,
      SecureCookie,
      SetCookieHttpsOnly,
      XFrameOptions,
      X_XssProtection,
      ProviderName,
      ProductName  
queryPeriod: 5m
name: CYFIRMA - Attack Surface - Configuration Medium Rule
version: 1.0.1
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Medium
kind: Scheduled
triggerOperator: gt
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    enabled: false
    reopenClosedIncident: false
    lookbackDuration: PT5H
    matchingMethod: AllEntities
description: |
  This alert is generated when CYFIRMA detects a critical misconfiguration in a public-facing asset or service. 
  Such misconfigurations may include exposed admin interfaces, default credentials, open directory listings, or insecure protocols, which significantly increase the attack surface."  
queryFrequency: 5m
requiredDataConnectors:
- dataTypes:
  - CyfirmaASConfigurationAlerts_CL
  connectorId: CyfirmaAttackSurfaceAlertsConnector
tactics:
- InitialAccess
- Discovery
- Persistence
- Execution
- DefenseEvasion
- CredentialAccess
- Collection
- Reconnaissance