CAND 001 Sentinel
Query
// Microsoft Sentinel / Log Analytics adaptation of CAND-001.
// Complete and validate all three placeholders before creating an analytics rule.
let CorrelationWindow = 4h; // PLACEHOLDER - tune from count-only workspace replay
let SuspiciousPromptTerms = dynamic([]); // PLACEHOLDER - approved tenant-specific terms; empty matches all nonempty inputs
let RequiredAlertCategories = dynamic([]); // PLACEHOLDER - approved category values; empty matches all categories
let AIToolRuns =
CloudAppEvents
| where TimeGenerated > ago(5h)
| where ActionType =~ "SentinelAIToolRunCompleted"
| where isnotempty(AccountObjectId)
| extend
ToolName=tostring(RawEventData.ToolName),
InputParameters=tostring(RawEventData.InputParameters),
APIsCalled=tostring(RawEventData.APIsCalled),
TablesRead=tostring(RawEventData.TablesRead),
DatabasesRead=tostring(RawEventData.DatabasesRead)
| where isnotempty(InputParameters)
| where array_length(SuspiciousPromptTerms) == 0
or InputParameters has_any (SuspiciousPromptTerms)
| project
AIToolRunTimestamp=TimeGenerated,
ReportId,
AccountObjectId,
AccountDisplayName,
AccountId,
Application,
ApplicationId,
IPAddress,
ToolName,
InputParameters,
APIsCalled,
TablesRead,
DatabasesRead;
AlertEvidence
| where TimeGenerated > ago(1h)
| where isnotempty(AlertId) and isnotempty(AccountObjectId)
| where array_length(RequiredAlertCategories) == 0
or Categories has_any (RequiredAlertCategories)
| project
AlertTimestamp=TimeGenerated,
AlertId,
AlertTitle=Title,
AlertCategories=Categories,
AttackTechniques,
ServiceSource,
DetectionSource,
EvidenceEntityType=EntityType,
EvidenceRole,
EvidenceSeverity=Severity,
AccountObjectId,
AccountUpn,
EvidenceApplication=Application,
EvidenceApplicationId=ApplicationId
| join kind=inner (AIToolRuns) on AccountObjectId
| where AlertTimestamp between (AIToolRunTimestamp .. AIToolRunTimestamp + CorrelationWindow)
| summarize
AIToolRunCount=dcount(ReportId),
AIToolRunReportIds=make_set(ReportId, 5),
AIToolRunTools=make_set(ToolName, 5),
AlertCount=dcount(AlertId),
AlertIds=make_set(AlertId, 5),
Alerts=make_set(AlertTitle, 5),
AlertCategorySet=make_set(AlertCategories, 5),
EvidenceSources=make_set(ServiceSource, 5),
arg_max(AlertTimestamp, *)
by AlertId, AccountObjectId
| project
TimeGenerated=AlertTimestamp,
AlertId,
AccountObjectId,
AccountUpn,
AccountDisplayName,
AccountId,
Application,
ApplicationId,
IPAddress,
AIToolRunTimestamp,
AIToolRunCount,
AIToolRunReportIds,
AIToolRunTools,
InputParameters,
APIsCalled,
TablesRead,
DatabasesRead,
AlertCount,
AlertIds,
Alerts,
AlertCategorySet,
EvidenceSources,
AttackTechniques,
DetectionSource,
EvidenceEntityType,
EvidenceRole,
EvidenceSeverityExplanation
This query is designed to identify and correlate suspicious activities involving AI tool usage and security alerts within a Microsoft Sentinel or Log Analytics environment. Here's a simplified breakdown of what the query does:
-
Set Parameters:
CorrelationWindow: A time window of 4 hours is set for correlating events.SuspiciousPromptTerms: A list of terms that, if found in AI tool inputs, are considered suspicious. Currently empty, meaning all non-empty inputs are considered.RequiredAlertCategories: A list of alert categories to filter on. Currently empty, meaning all categories are considered.
-
Extract AI Tool Runs:
- From the
CloudAppEventstable, it selects events from the last 5 hours where an AI tool run was completed. - Filters for events with non-empty account IDs and input parameters.
- Further filters based on suspicious terms if provided.
- Projects relevant details like tool name, input parameters, APIs called, etc.
- From the
-
Extract Alerts:
- From the
AlertEvidencetable, it selects alerts from the last hour with non-empty alert and account IDs. - Filters based on required alert categories if provided.
- Projects relevant alert details like alert title, categories, techniques, etc.
- From the
-
Correlate AI Tool Runs with Alerts:
- Joins the AI tool runs with alerts based on the account ID.
- Ensures the alert timestamp falls within the correlation window of the AI tool run timestamp.
-
Summarize Results:
- Counts distinct AI tool runs and alerts per account.
- Collects sets of report IDs, tool names, alert IDs, alert titles, and categories.
- Identifies the most recent alert per account and projects the final set of details.
The result is a summarized view of accounts that have both AI tool usage and security alerts within a specified time window, providing insights into potentially suspicious activities.