VectraDetections
| where Type == "host"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
version: 1.0.1
id: fb861539-da19-4266-831f-99459b8e7605
kind: Scheduled
requiredDataConnectors:
- connectorId: VectraXDR
dataTypes:
- Detections_Data_CL
alertDetailsOverride:
alertDynamicProperties:
- value: detection_url
alertProperty: AlertLink
alertDescriptionFormat: Vectra AI has detected {{category}} - {{detection}} on entity {{entity_uid}}.
alertDisplayNameFormat: Vectra AI Detection- {{detection}}
suppressionDuration: PT1H
entityMappings:
- fieldMappings:
- columnName: entity_uid
identifier: HostName
entityType: Host
name: Vectra Create Detection Alert for Hosts
queryFrequency: 10m
triggerThreshold: 0
tactics:
- Persistence
customDetails:
entity_id: entity_id
mitre_techniques: mitre
detection_id: detection_id
entity_type: entity_type
tags: tags
description: This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra Platform
status: Available
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Vectra XDR/Analytic Rules/Detection_Host.yaml
triggerOperator: GreaterThan
relevantTechniques:
- T1546
queryPeriod: 10m
severity: Medium
incidentConfiguration:
createIncident: false
groupingConfiguration:
lookbackDuration: PT5H
reopenClosedIncident: false
matchingMethod: AllEntities
enabled: false
suppressionEnabled: false
query: |
VectraDetections
| where Type == "host"
| extend
entity_uid = ['Entity UID'],
entity_id = ['Entity ID'],
entity_type = ['Entity Type'],
detection_id = ['Detection ID'],
detection = ['Detection Name'],
category = ['Detection Category'],
detection_url = ['Vectra Pivot'],
mitre = Mitre,
tags = Tags
| summarize arg_max(TimeGenerated, *) by ['Detection ID'], entity_uid
eventGroupingSettings:
aggregationKind: AlertPerResult