Analytic rule catalog
Netskope - Anomalous User Behavior High Volume from Unmanaged Device
Back
| Id | fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9 |
| Rulename | Netskope - Anomalous User Behavior (High Volume from Unmanaged Device) |
| Description | Detects anomalous user behavior including high data volume transfers from unmanaged devices, unusual access patterns, and suspicious application usage. |
| Severity | Medium |
| Tactics | Exfiltration Collection |
| Techniques | T1567 T1074 |
| Required data connectors | NetskopeWebTxConnector |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeWebTx/Analytic%20Rules/NetskopeWebtx_Rule1.yaml |
| Version | 1.0.0 |
| Arm template | fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9.json |
let highVolumeThresholdGB = 1;
NetskopeWebTransactions_CL
| where TimeGenerated > ago(1h)
| where isnotempty(CsUsername)
| summarize
TotalBytes = sum(Bytes),
UploadBytes = sum(CsBytes),
DownloadBytes = sum(ScBytes),
UniqueApps = dcount(XCsApp),
Apps = make_set(XCsApp, 20),
UniqueHosts = dcount(CsHost),
Activities = make_set(XCsAppActivity),
Countries = make_set(XCCountry),
Devices = make_set(XCDevice),
AccessMethods = make_set(XCsAccessMethod),
EventCount = count()
by CsUsername, XCDevice, XCsAccessMethod
| extend
TotalGB = round(TotalBytes / 1073741824.0, 3),
UploadGB = round(UploadBytes / 1073741824.0, 3),
DownloadGB = round(DownloadBytes / 1073741824.0, 3)
| where TotalGB > highVolumeThresholdGB
| extend IsUnmanagedDevice = XCDevice =~ 'unmanaged' or XCDevice =~ 'BYOD' or XCDevice =~ 'Personal' or XCDevice =~ 'Unknown' or XCsAccessMethod != 'Client'
| where IsUnmanagedDevice or TotalGB > 5 or UniqueApps > 20
| extend RiskIndicators = strcat_array(array_concat(
iff(IsUnmanagedDevice, dynamic(['Unmanaged Device']), dynamic([])),
iff(TotalGB > 5, dynamic(['High Data Volume']), dynamic([])),
iff(UniqueApps > 20, dynamic(['Many Apps Accessed']), dynamic([])),
iff(array_length(Countries) > 1, dynamic(['Multiple Countries']), dynamic([]))
), ', ')
| project
TimeGenerated = now(),
User = CsUsername,
Device = XCDevice,
AccessMethod = XCsAccessMethod,
TotalDataGB = TotalGB,
UploadGB,
DownloadGB,
UniqueApplications = UniqueApps,
Applications = Apps,
UniqueHosts,
Activities,
Countries,
EventCount,
IsUnmanagedDevice,
RiskIndicators
name: Netskope - Anomalous User Behavior (High Volume from Unmanaged Device)
triggerOperator: gt
query: |
let highVolumeThresholdGB = 1;
NetskopeWebTransactions_CL
| where TimeGenerated > ago(1h)
| where isnotempty(CsUsername)
| summarize
TotalBytes = sum(Bytes),
UploadBytes = sum(CsBytes),
DownloadBytes = sum(ScBytes),
UniqueApps = dcount(XCsApp),
Apps = make_set(XCsApp, 20),
UniqueHosts = dcount(CsHost),
Activities = make_set(XCsAppActivity),
Countries = make_set(XCCountry),
Devices = make_set(XCDevice),
AccessMethods = make_set(XCsAccessMethod),
EventCount = count()
by CsUsername, XCDevice, XCsAccessMethod
| extend
TotalGB = round(TotalBytes / 1073741824.0, 3),
UploadGB = round(UploadBytes / 1073741824.0, 3),
DownloadGB = round(DownloadBytes / 1073741824.0, 3)
| where TotalGB > highVolumeThresholdGB
| extend IsUnmanagedDevice = XCDevice =~ 'unmanaged' or XCDevice =~ 'BYOD' or XCDevice =~ 'Personal' or XCDevice =~ 'Unknown' or XCsAccessMethod != 'Client'
| where IsUnmanagedDevice or TotalGB > 5 or UniqueApps > 20
| extend RiskIndicators = strcat_array(array_concat(
iff(IsUnmanagedDevice, dynamic(['Unmanaged Device']), dynamic([])),
iff(TotalGB > 5, dynamic(['High Data Volume']), dynamic([])),
iff(UniqueApps > 20, dynamic(['Many Apps Accessed']), dynamic([])),
iff(array_length(Countries) > 1, dynamic(['Multiple Countries']), dynamic([]))
), ', ')
| project
TimeGenerated = now(),
User = CsUsername,
Device = XCDevice,
AccessMethod = XCsAccessMethod,
TotalDataGB = TotalGB,
UploadGB,
DownloadGB,
UniqueApplications = UniqueApps,
Applications = Apps,
UniqueHosts,
Activities,
Countries,
EventCount,
IsUnmanagedDevice,
RiskIndicators
queryFrequency: 1h
description: |
Detects anomalous user behavior including high data volume transfers from unmanaged devices, unusual access patterns, and suspicious application usage.
id: fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: NetskopeWebTxConnector
dataTypes:
- NetskopeWebTransactions_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeWebTx/Analytic%20Rules/NetskopeWebtx_Rule1.yaml
relevantTechniques:
- T1567
- T1074
tactics:
- Exfiltration
- Collection
entityMappings:
- fieldMappings:
- identifier: Name
columnName: User
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Device
entityType: Host
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9')]",
"properties": {
"alertRuleTemplateName": "fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9",
"customDetails": null,
"description": "Detects anomalous user behavior including high data volume transfers from unmanaged devices, unusual access patterns, and suspicious application usage.\n",
"displayName": "Netskope - Anomalous User Behavior (High Volume from Unmanaged Device)",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "User",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Device",
"identifier": "HostName"
}
]
}
],
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NetskopeWebTx/Analytic%20Rules/NetskopeWebtx_Rule1.yaml",
"query": "let highVolumeThresholdGB = 1;\nNetskopeWebTransactions_CL\n| where TimeGenerated > ago(1h)\n| where isnotempty(CsUsername)\n| summarize \n TotalBytes = sum(Bytes),\n UploadBytes = sum(CsBytes),\n DownloadBytes = sum(ScBytes),\n UniqueApps = dcount(XCsApp),\n Apps = make_set(XCsApp, 20),\n UniqueHosts = dcount(CsHost),\n Activities = make_set(XCsAppActivity),\n Countries = make_set(XCCountry),\n Devices = make_set(XCDevice),\n AccessMethods = make_set(XCsAccessMethod),\n EventCount = count()\n by CsUsername, XCDevice, XCsAccessMethod\n| extend \n TotalGB = round(TotalBytes / 1073741824.0, 3),\n UploadGB = round(UploadBytes / 1073741824.0, 3),\n DownloadGB = round(DownloadBytes / 1073741824.0, 3)\n| where TotalGB > highVolumeThresholdGB\n| extend IsUnmanagedDevice = XCDevice =~ 'unmanaged' or XCDevice =~ 'BYOD' or XCDevice =~ 'Personal' or XCDevice =~ 'Unknown' or XCsAccessMethod != 'Client'\n| where IsUnmanagedDevice or TotalGB > 5 or UniqueApps > 20\n| extend RiskIndicators = strcat_array(array_concat(\n iff(IsUnmanagedDevice, dynamic(['Unmanaged Device']), dynamic([])),\n iff(TotalGB > 5, dynamic(['High Data Volume']), dynamic([])),\n iff(UniqueApps > 20, dynamic(['Many Apps Accessed']), dynamic([])),\n iff(array_length(Countries) > 1, dynamic(['Multiple Countries']), dynamic([]))\n), ', ')\n| project \n TimeGenerated = now(),\n User = CsUsername,\n Device = XCDevice,\n AccessMethod = XCsAccessMethod,\n TotalDataGB = TotalGB,\n UploadGB,\n DownloadGB,\n UniqueApplications = UniqueApps,\n Applications = Apps,\n UniqueHosts,\n Activities,\n Countries,\n EventCount,\n IsUnmanagedDevice,\n RiskIndicators\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Collection",
"Exfiltration"
],
"techniques": [
"T1074",
"T1567"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}