VectraDetections
| where Type == "account"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra XDR/Analytic Rules/Detection_Account.yaml
suppressionEnabled: false
customDetails:
detection_id: detection_id
entity_type: entity_type
tags: tags
mitre_techniques: mitre
entity_id: entity_id
relevantTechniques:
- T1546
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: entity_uid
alertDetailsOverride:
alertDisplayNameFormat: Vectra AI Detection- {{detection}}
alertDescriptionFormat: Vectra AI has detected {{category}} - {{detection} on entity {{entity_uid}}.
alertDynamicProperties:
- value: detection_url
alertProperty: AlertLink
status: Available
suppressionDuration: PT1H
id: e796701f-6b39-4c54-bf8a-1d543a990784
query: |
VectraDetections
| where Type == "account"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
queryPeriod: 10m
name: Vectra Create Detection Alert for Accounts
version: 1.0.1
eventGroupingSettings:
aggregationKind: AlertPerResult
severity: Medium
kind: Scheduled
triggerOperator: GreaterThan
incidentConfiguration:
createIncident: false
groupingConfiguration:
enabled: false
reopenClosedIncident: false
lookbackDuration: PT5H
matchingMethod: AllEntities
description: This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra Platform
queryFrequency: 10m
requiredDataConnectors:
- dataTypes:
- Detections_Data_CL
connectorId: VectraXDR
tactics:
- Persistence