Back
Ide5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28
RulenameVaronis - Informational alerts detected
DescriptionIdentifies informational alerts generated by Varonis that provide contextual signals supporting correlation, enrichment, and overall security visibility.
SeverityInformational
TacticsCollection
Exfiltration
TechniquesT1530
T1213
T1567
Required data connectorsVaronisSaaSAlertsPush
KindScheduled
Query frequency5m
Query period5m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VaronisSaaS/Analytic%20Rules/VaronisInformationalAlertsDetected.yaml
Version1.0.1
Arm templatee5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28.json
Deploy To Azure
VaronisAlertsV2_CL
| where AlertSeverity_s == "Informational"
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: false
  createIncident: true
name: Varonis - Informational alerts detected
triggerOperator: gt
query: |
  VaronisAlertsV2_CL
  | where AlertSeverity_s == "Informational"
queryFrequency: 5m
description: |
  'Identifies informational alerts generated by Varonis that provide contextual signals supporting correlation, enrichment, and overall security visibility.'
id: e5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28
triggerThreshold: 0
queryPeriod: 5m
version: 1.0.1
kind: Scheduled
customDetails:
  AlertCategory: AlertCategory_s
  VaronisAlertGuid: AlertId_g
  Status: Status_s
  MitreTactic: MitreTacticName_s
  EventsCount: EventsCount_d
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Informational
requiredDataConnectors:
- connectorId: VaronisSaaSAlertsPush
  dataTypes:
  - VaronisAlertsV2_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VaronisSaaS/Analytic%20Rules/VaronisInformationalAlertsDetected.yaml
alertDetailsOverride:
  alertDescriptionFormat: 'Varonis detected activity for policy {{ThreatDetectionPolicyName_s}} in category {{AlertCategory_s}}. Users: {{UserNames_s}}.'
  alertDisplayNameFormat: 'Varonis alert: {{ThreatDetectionPolicyName_s}} ({{AlertSeverity_s}})'
relevantTechniques:
- T1530
- T1213
- T1567
tactics:
- Collection
- Exfiltration
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: UserNames_s
  - identifier: Name
    columnName: UserSamAccountNames_s
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: DeviceNames_s
  entityType: Host
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/e5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/e5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Varonis detected activity for policy {{ThreatDetectionPolicyName_s}} in category {{AlertCategory_s}}. Users: {{UserNames_s}}.",
          "alertDisplayNameFormat": "Varonis alert: {{ThreatDetectionPolicyName_s}} ({{AlertSeverity_s}})"
        },
        "alertRuleTemplateName": "e5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28",
        "customDetails": {
          "AlertCategory": "AlertCategory_s",
          "EventsCount": "EventsCount_d",
          "MitreTactic": "MitreTacticName_s",
          "Status": "Status_s",
          "VaronisAlertGuid": "AlertId_g"
        },
        "description": "'Identifies informational alerts generated by Varonis that provide contextual signals supporting correlation, enrichment, and overall security visibility.'\n",
        "displayName": "Varonis - Informational alerts detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "UserNames_s",
                "identifier": "FullName"
              },
              {
                "columnName": "UserSamAccountNames_s",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "DeviceNames_s",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": false,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VaronisSaaS/Analytic%20Rules/VaronisInformationalAlertsDetected.yaml",
        "query": "VaronisAlertsV2_CL\n| where AlertSeverity_s == \"Informational\"\n",
        "queryFrequency": "PT5M",
        "queryPeriod": "PT5M",
        "severity": "Informational",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Collection",
          "Exfiltration"
        ],
        "techniques": [
          "T1213",
          "T1530",
          "T1567"
        ],
        "templateVersion": "1.0.1",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}