Analytic rule catalog
Google SecOps - Detection Alerts
Back
| Id | f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a |
| Rulename | Google SecOps - Detection Alerts |
| Description | Creates one incident per active Google Security Operations detection alert in Microsoft Sentinel. Covers all rule types and severity levels with no additional filtering, providing broad visibility across all Google SecOps alerts. Use alongside focused rules for complete detection coverage. |
| Severity | Medium |
| Tactics | InitialAccess DefenseEvasion LateralMovement PrivilegeEscalation CommandAndControl |
| Techniques | T1078 T1021 T1566 |
| Required data connectors | GSDetectionAlerts |
| Kind | Scheduled |
| Query frequency | 10m |
| Query period | 10m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GoogleSecOps/Analytic%20Rules/GoogleSecOps-DetectionAlerts.yaml |
| Version | 1.0.0 |
| Arm template | f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a.json |
GoogleSecOpsDetectionAlerts
| where alertState == "ALERTING"
incidentConfiguration:
groupingConfiguration:
groupByCustomDetails:
- alert_identifier
lookbackDuration: P1D
enabled: true
reopenClosedIncident: false
matchingMethod: Selected
createIncident: true
name: Google SecOps - Detection Alerts
triggerOperator: gt
query: |
GoogleSecOpsDetectionAlerts
| where alertState == "ALERTING"
queryFrequency: 10m
description: |
Creates one incident per active Google Security Operations detection alert in Microsoft Sentinel. Covers all rule types and severity levels with no additional filtering, providing broad visibility across all Google SecOps alerts. Use alongside focused rules for complete detection coverage.
id: f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a
triggerThreshold: 0
queryPeriod: 10m
version: 1.0.0
kind: Scheduled
customDetails:
CorrelationIP: varCorrelationIp
RuleId: ruleId
PrincipalIP: varPrincipalIp
RuleName: ruleName
RiskScore: riskScore
TargetIP: varTargetIp
PrincipalHostname: varPrincipalHostname
alert_identifier: id
RuleType: ruleType
AlertState: alertState
DetectionType: detectionType
Severity: severity
DetectionTime: detectionTime
TargetUser: varTargetUserUserid
TargetHostname: varTargetHostname
PrincipalUser: varPrincipalUserUserid
SourceUser: varSourceUserUserid
SourceHostname: varSourceHostname
SourceIP: varSourceIp
status: Available
eventGroupingSettings:
aggregationKind: AlertPerResult
severity: Medium
requiredDataConnectors:
- connectorId: GSDetectionAlerts
dataTypes:
- DetectionAlerts_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GoogleSecOps/Analytic%20Rules/GoogleSecOps-DetectionAlerts.yaml
alertDetailsOverride:
alertDescriptionFormat: 'Google SecOps detection alert. Rule: {{ruleName}}. Severity: {{severity}}. Type: {{ruleType}}.'
alertDisplayNameFormat: 'Google SecOps Alert: {{ruleName}} : {{id}}'
relevantTechniques:
- T1078
- T1021
- T1566
tactics:
- InitialAccess
- DefenseEvasion
- LateralMovement
- PrivilegeEscalation
- CommandAndControl
entityMappings:
- fieldMappings:
- identifier: Address
columnName: varPrincipalIp
entityType: IP
- fieldMappings:
- identifier: Address
columnName: varTargetIp
entityType: IP
- fieldMappings:
- identifier: Address
columnName: varSourceIp
entityType: IP
- fieldMappings:
- identifier: Address
columnName: varCorrelationIp
entityType: IP
- fieldMappings:
- identifier: Url
columnName: urlBackToProduct
entityType: URL
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a')]",
"properties": {
"alertDetailsOverride": {
"alertDescriptionFormat": "Google SecOps detection alert. Rule: {{ruleName}}. Severity: {{severity}}. Type: {{ruleType}}.",
"alertDisplayNameFormat": "Google SecOps Alert: {{ruleName}} : {{id}}"
},
"alertRuleTemplateName": "f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a",
"customDetails": {
"alert_identifier": "id",
"AlertState": "alertState",
"CorrelationIP": "varCorrelationIp",
"DetectionTime": "detectionTime",
"DetectionType": "detectionType",
"PrincipalHostname": "varPrincipalHostname",
"PrincipalIP": "varPrincipalIp",
"PrincipalUser": "varPrincipalUserUserid",
"RiskScore": "riskScore",
"RuleId": "ruleId",
"RuleName": "ruleName",
"RuleType": "ruleType",
"Severity": "severity",
"SourceHostname": "varSourceHostname",
"SourceIP": "varSourceIp",
"SourceUser": "varSourceUserUserid",
"TargetHostname": "varTargetHostname",
"TargetIP": "varTargetIp",
"TargetUser": "varTargetUserUserid"
},
"description": "Creates one incident per active Google Security Operations detection alert in Microsoft Sentinel. Covers all rule types and severity levels with no additional filtering, providing broad visibility across all Google SecOps alerts. Use alongside focused rules for complete detection coverage.\n",
"displayName": "Google SecOps - Detection Alerts",
"enabled": true,
"entityMappings": [
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "varPrincipalIp",
"identifier": "Address"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "varTargetIp",
"identifier": "Address"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "varSourceIp",
"identifier": "Address"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "varCorrelationIp",
"identifier": "Address"
}
]
},
{
"entityType": "URL",
"fieldMappings": [
{
"columnName": "urlBackToProduct",
"identifier": "Url"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByCustomDetails": [
"alert_identifier"
],
"lookbackDuration": "P1D",
"matchingMethod": "Selected",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/GoogleSecOps/Analytic%20Rules/GoogleSecOps-DetectionAlerts.yaml",
"query": "GoogleSecOpsDetectionAlerts\n| where alertState == \"ALERTING\"\n",
"queryFrequency": "PT10M",
"queryPeriod": "PT10M",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"DefenseEvasion",
"InitialAccess",
"LateralMovement",
"PrivilegeEscalation"
],
"techniques": [
"T1021",
"T1078",
"T1566"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}