VectraDetections
| where Type == "account"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
matchingMethod: AllEntities
enabled: false
reopenClosedIncident: false
lookbackDuration: PT5H
createIncident: false
triggerThreshold: 0
relevantTechniques:
- T1546
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: entity_uid
query: |
VectraDetections
| where Type == "account"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
requiredDataConnectors:
- connectorId: VectraXDR
dataTypes:
- Detections_Data_CL
customDetails:
detection_id: detection_id
entity_type: entity_type
mitre_techniques: mitre
tags: tags
entity_id: entity_id
alertDetailsOverride:
alertDynamicProperties:
- alertProperty: AlertLink
value: detection_url
alertDisplayNameFormat: Vectra AI Detection- {{detection}}
alertDescriptionFormat: Vectra AI has detected {{category}} - {{detection} on entity {{entity_uid}}.
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra XDR/Analytic Rules/Detection_Account.yaml
suppressionEnabled: false
queryPeriod: 10m
tactics:
- Persistence
name: Vectra Create Detection Alert for Accounts
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
description: This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra Platform
id: e796701f-6b39-4c54-bf8a-1d543a990784
version: 1.0.1
triggerOperator: GreaterThan
queryFrequency: 10m
severity: Medium
suppressionDuration: PT1H