Query Details

Vulnerability Statistics Sentinel Workbook

Vulnerability Statistics Logic App Sentinel Workbook

Query

No standalone KQL detected in this source

View source on GitHub

About this query

Explanation

This query is part of a Logic App and Sentinel Workbook designed to provide a weekly overview of vulnerabilities in your organization's IT environment. Here's a simplified breakdown of what it does:

  1. Data Collection: The Logic App runs a query every week to gather data from Microsoft Defender. It categorizes devices into groups like Windows servers, Windows clients, Linux, macOS, and network components.

  2. Vulnerability Analysis: For each device category, it calculates key security metrics such as:

    • Total number of vulnerabilities
    • Number of unique CVEs (Common Vulnerabilities and Exposures)
    • Number of exploitable CVEs
    • Number of affected devices
    • Average CVSS (Common Vulnerability Scoring System) score
  3. Data Storage: The results are sent to Azure Monitor using the Log Ingestion API and stored for further analysis.

  4. Error Handling: The Logic App checks if the data was successfully ingested. If successful, it logs a success message; if not, it logs an error and stops the process.

  5. Authentication: The process uses Managed Identity for secure authentication, eliminating the need for embedded credentials.

  6. Visualization: The Sentinel Workbook provides a visual representation of the data:

    • KPI Tiles and Detail Table: Show the latest vulnerability statistics for each device category.
    • Trend Analysis: Visualizes trends over time for vulnerability volume, average severity, and exploitable CVEs, helping to identify risk areas and prioritize remediation efforts.

Overall, this setup automates the collection, analysis, and visualization of vulnerability data, helping organizations maintain a high-level overview of their security posture and identify areas that need attention.