let query_frequency = 1h;
DataverseActivity
| where TimeGenerated >= ago(query_frequency)
| where Message =~ 'DeleteRecordChangeHistory' or Message =~ 'DeleteAuditData'
| extend CloudAppId = int(32780)
| extend AccountName = tostring(split(UserId, "@")[0])
| extend UPNSuffix = tostring(split(UserId, "@")[1])
| project
TimeGenerated,
UserId,
ClientIp,
UserAgent,
Message,
EntityName,
InstanceUrl,
AccountName,
UPNSuffix,
CloudAppId
tactics:
- DefenseEvasion
id: f1634822-b7e9-44f5-95ac-fa4a04f14513
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Business Applications/Analytic Rules/Dataverse - Audit log data deletion.yaml
alertDetailsOverride:
alertDisplayNameFormat: Dataverse - Audit logs deleted in {{InstanceUrl}}
alertDescriptionFormat: User {{UserId}} deleted audit log data in {{InstanceUrl}}. The message type is {{Message}}.
status: Available
description: Identifies audit log data deletion activity in Dataverse.
version: 3.2.0
severity: Low
triggerThreshold: 0
entityMappings:
- fieldMappings:
- identifier: Name
columnName: AccountName
- identifier: UPNSuffix
columnName: UPNSuffix
entityType: Account
- fieldMappings:
- identifier: AppId
columnName: CloudAppId
- identifier: InstanceName
columnName: InstanceUrl
entityType: CloudApplication
- fieldMappings:
- identifier: Address
columnName: ClientIp
entityType: IP
kind: Scheduled
name: Dataverse - Audit log data deletion
query: |
let query_frequency = 1h;
DataverseActivity
| where TimeGenerated >= ago(query_frequency)
| where Message =~ 'DeleteRecordChangeHistory' or Message =~ 'DeleteAuditData'
| extend CloudAppId = int(32780)
| extend AccountName = tostring(split(UserId, "@")[0])
| extend UPNSuffix = tostring(split(UserId, "@")[1])
| project
TimeGenerated,
UserId,
ClientIp,
UserAgent,
Message,
EntityName,
InstanceUrl,
AccountName,
UPNSuffix,
CloudAppId
queryPeriod: 14d
eventGroupingSettings:
aggregationKind: SingleAlert
queryFrequency: 1h
triggerOperator: gt
requiredDataConnectors:
- connectorId: Dataverse
dataTypes:
- DataverseActivity
relevantTechniques:
- T1070