Query Details

CAND 001

Query

let CorrelationWindow = 4h;  // PLACEHOLDER - maximum allowed delay between a completed AI tool run and downstream alert evidence for the same account
let SuspiciousPromptTerms = dynamic([]);  // PLACEHOLDER - tenant-specific prompt-safety bypass or prohibited-instruction terms to focus AI input telemetry
let RequiredAlertCategories = dynamic([]);  // PLACEHOLDER - optional downstream alert categories to require when the tenant has AI, DLP, or runtime-protection categories
let AIToolRuns =
CloudAppEvents
| where ingestion_time() > ago(5h)
| where ActionType =~ "SentinelAIToolRunCompleted"
| where isnotempty(AccountObjectId)
| extend ToolName = tostring(RawEventData.ToolName),
         InputParameters = tostring(RawEventData.InputParameters),
         APIsCalled = tostring(RawEventData.APIsCalled),
         TablesRead = tostring(RawEventData.TablesRead),
         DatabasesRead = tostring(RawEventData.DatabasesRead)
| where isnotempty(InputParameters)
| where array_length(SuspiciousPromptTerms) == 0 or InputParameters has_any (SuspiciousPromptTerms)
| project AIToolRunTimestamp = Timestamp, ReportId, AccountObjectId, AccountDisplayName, AccountId, Application, ApplicationId, IPAddress, ToolName, InputParameters, APIsCalled, TablesRead, DatabasesRead;
AlertEvidence
| where ingestion_time() > ago(1h)
| where isnotempty(AlertId)
| where isnotempty(AccountObjectId)
| where array_length(RequiredAlertCategories) == 0 or Categories has_any (RequiredAlertCategories)
| project Timestamp, AlertId, AlertTitle = Title, AlertCategories = Categories, AttackTechniques, ServiceSource, DetectionSource, EvidenceEntityType = EntityType, EvidenceRole, EvidenceSeverity = Severity, AccountObjectId, AccountUpn, EvidenceApplication = Application, EvidenceApplicationId = ApplicationId
| join kind=inner (AIToolRuns) on AccountObjectId
| where Timestamp between (AIToolRunTimestamp .. AIToolRunTimestamp + CorrelationWindow)
| summarize AIToolRunCount = dcount(ReportId), AIToolRunReportIds = make_set(ReportId, 5), AIToolRunTools = make_set(ToolName, 5), AlertCount = dcount(AlertId), AlertIds = make_set(AlertId, 5), Alerts = make_set(AlertTitle, 5), AlertCategorySet = make_set(AlertCategories, 5), EvidenceSources = make_set(ServiceSource, 5), arg_max(Timestamp, *) by AlertId, AccountObjectId
| project Timestamp, AlertId, AccountObjectId, AccountUpn, AccountDisplayName, AccountId, Application, ApplicationId, IPAddress, AIToolRunTimestamp, AIToolRunCount, AIToolRunReportIds, AIToolRunTools, InputParameters, APIsCalled, TablesRead, DatabasesRead, AlertCount, AlertIds, Alerts, AlertCategorySet, EvidenceSources, AttackTechniques, DetectionSource, EvidenceEntityType, EvidenceRole, EvidenceSeverity

Explanation

This KQL query is designed to correlate AI tool runs with security alerts for specific user accounts within a cloud environment. Here's a simplified breakdown of what the query does:

  1. Define Parameters:

    • CorrelationWindow: A 4-hour window to match AI tool runs with alerts.
    • SuspiciousPromptTerms: A list of terms indicating potentially unsafe AI inputs.
    • RequiredAlertCategories: A list of alert categories that must be present.
  2. Extract AI Tool Runs:

    • From the CloudAppEvents table, it selects events from the last 5 hours where an AI tool run was completed.
    • Filters for events with non-empty account IDs and input parameters.
    • If SuspiciousPromptTerms is specified, it checks if the input parameters contain any of these terms.
    • Projects relevant details like tool name, input parameters, APIs called, etc.
  3. Extract Alert Evidence:

    • From the AlertEvidence table, it selects alerts from the last hour with non-empty alert and account IDs.
    • If RequiredAlertCategories is specified, it checks if the alert categories match any of these.
    • Projects relevant alert details like alert title, categories, and severity.
  4. Join and Correlate:

    • Joins the AI tool runs and alert evidence on the account ID.
    • Filters to ensure the alert timestamp falls within the 4-hour window after the AI tool run.
  5. Summarize Results:

    • Counts distinct AI tool runs and alerts for each account.
    • Collects sets of report IDs, tool names, alert IDs, alert titles, and categories.
    • Selects the most recent timestamp for each alert and projects a comprehensive set of details for analysis.

In summary, this query identifies and summarizes instances where AI tool activities and security alerts are potentially related, focusing on specific accounts and using defined parameters to filter and correlate data.