NordPass - User deletes items in bulk
| Id | f72f630f-c890-49fe-b747-80f4fb3b6348 |
| Rulename | NordPass - User deletes items in bulk |
| Description | This will alert you if a user deletes items in bulk, namely, more than 10 items or in the span of 10 minutes. If a mix of bulk and one-off deletions were performed, this will group all actions and report the total number of items deleted. |
| Severity | High |
| Tactics | Impact Collection |
| Techniques | T1485 T1074 |
| Required data connectors | NordPass |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 10m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NordPass/Analytics Rules/nordpass_items_bulk_delete.yaml |
| Version | 1.0.0 |
| Arm template | f72f630f-c890-49fe-b747-80f4fb3b6348.json |
NordPassEventLogs_CL
| where action == "items_deleted" and event_type == "item_delete"
| extend item_count = array_length(todynamic(metadata).items)
| summarize total_items = sum(item_count) by user_email
| where total_items >= 10
queryPeriod: 10m
query: |
NordPassEventLogs_CL
| where action == "items_deleted" and event_type == "item_delete"
| extend item_count = array_length(todynamic(metadata).items)
| summarize total_items = sum(item_count) by user_email
| where total_items >= 10
name: NordPass - User deletes items in bulk
entityMappings:
- fieldMappings:
- columnName: user_email
identifier: MailboxPrimaryAddress
entityType: Mailbox
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NordPass/Analytics Rules/nordpass_items_bulk_delete.yaml
description: |
This will alert you if a user deletes items in bulk, namely, more than 10 items or in the span of 10 minutes.
If a mix of bulk and one-off deletions were performed, this will group all actions and report the total number of items deleted.
kind: Scheduled
version: 1.0.0
displayName: User deletes items in bulk
queryFrequency: 5m
severity: High
requiredDataConnectors:
- connectorId: NordPass
dataTypes:
- NordPassEventLogs_CL
triggerOperator: gt
triggerThreshold: 0
incidentConfiguration:
createIncident: false
customDetails:
User: user_email
ItemCount: total_items
tactics:
- Impact
- Collection
id: f72f630f-c890-49fe-b747-80f4fb3b6348
relevantTechniques:
- T1485
- T1074