Multiple Email Entity Audit Logs
Query
// This query assumes a feed of threat indicators is ingested/synchronized periodically, and each synchronization ingests new indicators and only old indicators that have been modified.
// Active threat indicators in Sentinel are renovated as ThreatIntelligenceIndicator events every ~12 days.
let query_frequency = 1h;
let query_period = 14d;
let query_wait = 0h;
let table_query_lookback = 14d;
let _TIBenignProperty =
_GetWatchlist('ID-TIBenignProperty')
| where Notes has_any ("[SourceEmailAddress]", "[DestinationEmailAddress]")
| project IndicatorId, BenignProperty
;
let _TIExcludedSources = toscalar(
_GetWatchlist('Activity-ExpectedSignificantActivity')
| where Activity == "ThreatIndicatorSource"
| summarize make_list(Auxiliar)
);
let _EmailAddressRegex = toscalar(
_GetWatchlist('RegEx-SingleRegularExpressions')
| where UseCase == "EmailAddress"
| project RegEx
);
let _ExternalEmailAddressRegex = toscalar(
_GetWatchlist('RegEx-SingleRegularExpressions')
| where UseCase == "ExternalEmailAddress"
| project RegEx
);
let _TITableMatch = (table_start: datetime, table_end: datetime, only_new_ti: boolean, ti_start: datetime = datetime(null)) {
// Scheduled Analytics rules have a query period limit of 14d
let _Indicators =// materialize(
ThreatIntelligenceIndicator
| where TimeGenerated > ago(query_period)
// Take the earliest TimeGenerated and the latest column info
| summarize hint.strategy=shuffle
minTimeGenerated = min(TimeGenerated),
arg_max(TimeGenerated, Active, Description, ActivityGroupNames, IndicatorId, ThreatType, DomainName, Url, ExpirationDateTime, ConfidenceScore, AdditionalInformation, ExternalIndicatorId, EmailSenderAddress)
by IndicatorId
// Remove inactive or expired indicators
| where not(not(Active) or ExpirationDateTime < now())
// Pick indicators that contain the desired entity type
| where isnotempty(EmailSenderAddress)
| extend EmailAddress = tolower(EmailSenderAddress)
// Remove indicators from specific sources
| where not(AdditionalInformation has_any (_TIExcludedSources) or Description has_any (_TIExcludedSources))
// Remove excluded indicators with benign properties
| join kind=leftanti _TIBenignProperty on IndicatorId, $left.EmailAddress == $right.BenignProperty
// Deduplicate indicators by EmailAddress column, equivalent to using join kind=innerunique afterwards
| summarize hint.strategy=shuffle
minTimeGenerated = min(minTimeGenerated),
take_any(*)
by EmailAddress
// If we want only new indicators, remove indicators received previously
| where not(only_new_ti and minTimeGenerated < ti_start)
//)
;
//let _IndicatorsLength = toscalar(_Indicators | summarize count());
//let _IndicatorsPrefilter = toscalar(
// _Indicators
// | extend AuxiliarField = tostring(split(EmailAddress, ".")[-1])
// | summarize make_set_if(AuxiliarField, isnotempty(AuxiliarField))
//);
//let _IndicatorsPrefilterLength = array_length(_IndicatorsPrefilter);
let _TableEvents =
AuditLogs
| where TimeGenerated between (table_start .. table_end)
| extend UserPrincipalName = tostring(InitiatedBy.user.userPrincipalName)
| extend IPAddress = tostring(InitiatedBy[tostring(bag_keys(InitiatedBy)[0])].ipAddress)
// Filter events that may contain indicators
| where not(array_length(TargetResources) == 0)
//| where not(_IndicatorsPrefilterLength < 10000 and not(TargetResources has_any (_IndicatorsPrefilter))) // valid TLD ~1500 , "has_any" limit 10000
| extend TargetResourcesEmails = todynamic(dynamic_to_json(extract_all(_EmailAddressRegex, dynamic([1]), tostring(TargetResources))))
| mv-expand EmailAddress = TargetResourcesEmails to typeof(string)
| where isnotempty(EmailAddress)
| summarize take_any(*) by EmailAddress
// Parse original address
| extend EmailAddress = case(
EmailAddress has "#EXT#", replace_regex(EmailAddress, _ExternalEmailAddressRegex, @"\2@\3"),
EmailAddress startswith "live.com#" or EmailAddress startswith "guest#", replace_regex(EmailAddress, strcat(@"(?:live\.com#|guest#)", _EmailAddressRegex), @"\2@\3"),
EmailAddress
)
//| where not(_IndicatorsLength < 1000000 and not(EmailAddress in (toscalar(_Indicators | summarize make_list(EmailAddress))))) // "in" limit 1.000.000
| project-rename AuditLogs_TimeGenerated = TimeGenerated
;
_Indicators
| join kind=inner hint.strategy=shuffle _TableEvents on EmailAddress
// Take only a single event by key columns
//| summarize hint.strategy=shuffle take_any(*) by EmailAddress, InitiatedBy
| project
AuditLogs_TimeGenerated,
Description, ActivityGroupNames, IndicatorId, ThreatType, DomainName, Url, ExpirationDateTime, ConfidenceScore, AdditionalInformation, EmailSenderAddress,
Category, OperationName, Result, ResultDescription, Identity, UserPrincipalName, IPAddress, InitiatedBy = tostring(InitiatedBy), LoggedByService, AdditionalDetails, TargetResources, CorrelationId
};
union// isfuzzy=true
// Match current table events all indicators available
_TITableMatch(ago(query_frequency + query_wait), ago(query_wait), false),
// Match past table events new indicators since last query execution
_TITableMatch(ago(table_query_lookback + query_wait), ago(query_frequency + query_wait), true, ago(query_frequency))
| summarize arg_max(AuditLogs_TimeGenerated, *) by IndicatorId, InitiatedBy
| extend
timestamp = AuditLogs_TimeGenerated,
IPCustomEntity = IPAddress,
AccountCustomEntity = EmailSenderAddressExplanation
This KQL query is designed to identify and correlate threat indicators with audit log events in Microsoft Sentinel. Here's a simplified breakdown of what the query does:
-
Setup and Definitions:
- The query defines several parameters and helper functions to manage time periods and filter criteria.
- It retrieves specific watchlists to exclude benign properties and certain sources from the analysis.
- It sets up regular expressions to identify email addresses in the data.
-
Threat Indicator Processing:
- The query fetches threat indicators from the
ThreatIntelligenceIndicatortable, focusing on those generated in the last 14 days. - It filters out inactive or expired indicators and those from excluded sources.
- It further refines the list by excluding indicators with benign properties and deduplicating based on email addresses.
- The query fetches threat indicators from the
-
Audit Log Event Processing:
- The query retrieves events from the
AuditLogstable within specified time frames. - It extracts and processes email addresses from these events, focusing on those that may contain threat indicators.
- The query retrieves events from the
-
Correlation:
- The query joins the processed threat indicators with the audit log events based on email addresses.
- It ensures that only unique events are considered for each email address and initiator.
-
Output:
- The final result is a union of two sets of matches:
- Current audit log events with all available indicators.
- Past audit log events with new indicators since the last query execution.
- The query summarizes the results, providing details such as timestamps, descriptions, and associated entities like IP addresses and email addresses.
- The final result is a union of two sets of matches:
In essence, this query is designed to continuously monitor and correlate threat intelligence with audit logs to identify potential security incidents involving email addresses, helping security teams to quickly respond to threats.