Query Details

CAND 001 Sentinel

Query

// Microsoft Sentinel / Log Analytics adaptation of CAND-001.
// Complete and validate all three placeholders before creating an analytics rule.
let CorrelationWindow = 4h;  // PLACEHOLDER - tune from count-only workspace replay
let SuspiciousPromptTerms = dynamic([]);  // PLACEHOLDER - approved tenant-specific terms; empty matches all nonempty inputs
let RequiredAlertCategories = dynamic([]);  // PLACEHOLDER - approved category values; empty matches all categories
let AIToolRuns =
    CloudAppEvents
    | where TimeGenerated > ago(5h)
    | where ActionType =~ "SentinelAIToolRunCompleted"
    | where isnotempty(AccountObjectId)
    | extend
        ToolName=tostring(RawEventData.ToolName),
        InputParameters=tostring(RawEventData.InputParameters),
        APIsCalled=tostring(RawEventData.APIsCalled),
        TablesRead=tostring(RawEventData.TablesRead),
        DatabasesRead=tostring(RawEventData.DatabasesRead)
    | where isnotempty(InputParameters)
    | where array_length(SuspiciousPromptTerms) == 0
        or InputParameters has_any (SuspiciousPromptTerms)
    | project
        AIToolRunTimestamp=TimeGenerated,
        ReportId,
        AccountObjectId,
        AccountDisplayName,
        AccountId,
        Application,
        ApplicationId,
        IPAddress,
        ToolName,
        InputParameters,
        APIsCalled,
        TablesRead,
        DatabasesRead;
AlertEvidence
| where TimeGenerated > ago(1h)
| where isnotempty(AlertId) and isnotempty(AccountObjectId)
| where array_length(RequiredAlertCategories) == 0
    or Categories has_any (RequiredAlertCategories)
| project
    AlertTimestamp=TimeGenerated,
    AlertId,
    AlertTitle=Title,
    AlertCategories=Categories,
    AttackTechniques,
    ServiceSource,
    DetectionSource,
    EvidenceEntityType=EntityType,
    EvidenceRole,
    EvidenceSeverity=Severity,
    AccountObjectId,
    AccountUpn,
    EvidenceApplication=Application,
    EvidenceApplicationId=ApplicationId
| join kind=inner (AIToolRuns) on AccountObjectId
| where AlertTimestamp between (AIToolRunTimestamp .. AIToolRunTimestamp + CorrelationWindow)
| summarize
    AIToolRunCount=dcount(ReportId),
    AIToolRunReportIds=make_set(ReportId, 5),
    AIToolRunTools=make_set(ToolName, 5),
    AlertCount=dcount(AlertId),
    AlertIds=make_set(AlertId, 5),
    Alerts=make_set(AlertTitle, 5),
    AlertCategorySet=make_set(AlertCategories, 5),
    EvidenceSources=make_set(ServiceSource, 5),
    arg_max(AlertTimestamp, *)
    by AlertId, AccountObjectId
| project
    TimeGenerated=AlertTimestamp,
    AlertId,
    AccountObjectId,
    AccountUpn,
    AccountDisplayName,
    AccountId,
    Application,
    ApplicationId,
    IPAddress,
    AIToolRunTimestamp,
    AIToolRunCount,
    AIToolRunReportIds,
    AIToolRunTools,
    InputParameters,
    APIsCalled,
    TablesRead,
    DatabasesRead,
    AlertCount,
    AlertIds,
    Alerts,
    AlertCategorySet,
    EvidenceSources,
    AttackTechniques,
    DetectionSource,
    EvidenceEntityType,
    EvidenceRole,
    EvidenceSeverity

Explanation

This query is designed to identify and correlate suspicious activities involving AI tool usage and security alerts within a Microsoft Sentinel or Log Analytics environment. Here's a simplified breakdown of what the query does:

  1. Set Parameters:

    • CorrelationWindow: A time window of 4 hours is set for correlating events.
    • SuspiciousPromptTerms: A list of terms that, if found in AI tool inputs, are considered suspicious. Currently empty, meaning all non-empty inputs are considered.
    • RequiredAlertCategories: A list of alert categories to filter on. Currently empty, meaning all categories are considered.
  2. Extract AI Tool Runs:

    • From the CloudAppEvents table, it selects events from the last 5 hours where an AI tool run was completed.
    • Filters for events with non-empty account IDs and input parameters.
    • Further filters based on suspicious terms if provided.
    • Projects relevant details like tool name, input parameters, APIs called, etc.
  3. Extract Alerts:

    • From the AlertEvidence table, it selects alerts from the last hour with non-empty alert and account IDs.
    • Filters based on required alert categories if provided.
    • Projects relevant alert details like alert title, categories, techniques, etc.
  4. Correlate AI Tool Runs with Alerts:

    • Joins the AI tool runs with alerts based on the account ID.
    • Ensures the alert timestamp falls within the correlation window of the AI tool run timestamp.
  5. Summarize Results:

    • Counts distinct AI tool runs and alerts per account.
    • Collects sets of report IDs, tool names, alert IDs, alert titles, and categories.
    • Identifies the most recent alert per account and projects the final set of details.

The result is a summarized view of accounts that have both AI tool usage and security alerts within a specified time window, providing insights into potentially suspicious activities.