Query Details

CAND 002 Guardrail Enriched

Query

// CAND-002 (proposed) - Guardrail-enriched correlation for BC-1 (gatekeeper evasion, T1562).
//
// STATUS: draft / requires tenant validation. This is NOT part of the original
// PuzzleMask report. It is proposed because AgentsInfo.Guardrails and
// BehaviorInfo's MITRE-classified Categories are official telemetry that may
// close two gaps the report explicitly flagged in CAND-001:
//   1. "No explicit gatekeeper decision field was confirmed."
//   2. Raw AlertEvidence is a weaker downstream signal than pre-classified
//      MITRE ATT&CK behaviors.
//
// Before relying on this query:
//   - Run agent-observability-preflight.kql queries 1, 2, and 5 first.
//   - Confirm the AccountObjectId-to-EntraAgentId join key assumption in query 5
//     against real values from your tenant; do not assume it is correct.
//   - Populate every placeholder below with tenant-approved values.
//   - Replay in count-only mode before creating an analytics rule.

let CorrelationWindow = 4h;  // PLACEHOLDER - maximum allowed delay between a completed AI tool run and a corroborating BehaviorInfo record
let RequiredBehaviorCategories = dynamic([]);  // PLACEHOLDER - MITRE-mapped BehaviorInfo categories to require; empty matches all categories
let SuspiciousPromptTerms = dynamic([]);  // PLACEHOLDER - tenant-specific prompt-safety bypass or prohibited-instruction terms

// Agents with weak or absent declared guardrail coverage.
let WeaklyGuardedAgents =
    AgentsInfo
    | where Timestamp > ago(5h)
    | where isnotempty(EntraAgentId)
    | where array_length(Guardrails) == 0
    | project AgentId, AgentName, Platform, EntraAgentId, ObservabilityId;

// Completed AI tool runs from weakly-guarded agents with suspicious input.
let AIToolRuns =
    CloudAppEvents
    | where TimeGenerated > ago(5h)
    | where ActionType =~ "SentinelAIToolRunCompleted"
    | where isnotempty(AccountObjectId)
    | extend InputParameters = tostring(RawEventData.InputParameters)
    | where isnotempty(InputParameters)
    | where array_length(SuspiciousPromptTerms) == 0
        or InputParameters has_any (SuspiciousPromptTerms)
    | join kind=inner (WeaklyGuardedAgents) on $left.AccountObjectId == $right.EntraAgentId
    | project
        AIToolRunTimestamp = TimeGenerated,
        AccountObjectId,
        AccountDisplayName,
        Application,
        IPAddress,
        InputParameters,
        AgentId,
        AgentName,
        Platform;

// MITRE-classified downstream behaviors for the same account.
BehaviorInfo
| where Timestamp > ago(1h)
| where isnotempty(AccountObjectId)
| where array_length(RequiredBehaviorCategories) == 0
    or Categories has_any (RequiredBehaviorCategories)
| project
    BehaviorTimestamp = Timestamp,
    BehaviorId,
    BehaviorTitle = Title,
    BehaviorCategories = Categories,
    AttackTechniques,
    ServiceSource,
    DetectionSource,
    AccountObjectId
| join kind=inner (AIToolRuns) on AccountObjectId
| where BehaviorTimestamp between (AIToolRunTimestamp .. AIToolRunTimestamp + CorrelationWindow)
| summarize
    ToolRunCount = count(),
    BehaviorCount = dcount(BehaviorId),
    BehaviorIds = make_set(BehaviorId, 5),
    Behaviors = make_set(BehaviorTitle, 5),
    BehaviorCategorySet = make_set(BehaviorCategories, 5),
    arg_max(BehaviorTimestamp, *)
    by BehaviorId, AccountObjectId
| project
    TimeGenerated = BehaviorTimestamp,
    BehaviorId,
    AccountObjectId,
    AccountDisplayName,
    AgentId,
    AgentName,
    Platform,
    Application,
    IPAddress,
    AIToolRunTimestamp,
    ToolRunCount,
    InputParameters,
    BehaviorCount,
    BehaviorIds,
    Behaviors,
    BehaviorCategorySet,
    AttackTechniques,
    ServiceSource,
    DetectionSource

Explanation

This query is designed to identify suspicious activities related to AI tool usage within an organization. Here's a simplified breakdown of what it does:

  1. Setup and Preconditions:

    • The query is in draft status and requires validation within a specific tenant environment.
    • It addresses gaps identified in a previous report by using official telemetry data.
    • Before using this query, certain preliminary checks and validations are recommended.
  2. Define Parameters:

    • CorrelationWindow: A time frame of 4 hours is set to match AI tool runs with behavior records.
    • RequiredBehaviorCategories and SuspiciousPromptTerms: These are placeholders for specific categories and terms that need to be defined by the tenant.
  3. Identify Weakly Guarded Agents:

    • It filters agents that have no or weak guardrail coverage and have been active in the last 5 hours.
  4. Track AI Tool Runs:

    • It identifies completed AI tool runs from the weakly guarded agents, especially those with suspicious input terms.
    • It joins this data with the weakly guarded agents to get more details about these runs.
  5. Correlate with Behavior Information:

    • It looks for MITRE-classified behaviors associated with the same accounts within the last hour.
    • It correlates these behaviors with the AI tool runs if they fall within the defined correlation window.
  6. Summarize Findings:

    • The query summarizes the number of tool runs and behaviors, listing details like behavior IDs, titles, and categories.
    • It provides a comprehensive view of potentially suspicious activities, including timestamps, account details, and associated behaviors.

In essence, this query helps in detecting and analyzing potentially risky AI tool usage by correlating it with known behavior patterns, thereby enhancing security monitoring.