Detection rules › Kusto

Multi-Factor Authentication User Locked

Status
available
Severity
high
Time window
5m
Source
github.com/Azure/Azure-Sentinel

Detects when the allowed number of multi-factor authentication attempts is exceeded for a user.

Rule body

id: ebdd9cf8-c41c-460e-95d8-e5bc3cd9763e
name: Multi-Factor Authentication User Locked
description: Detects when the allowed number of multi-factor authentication attempts
  is exceeded for a user.
severity: High
status: Available
requiredDataConnectors:
- connectorId: Syslog
  dataTypes:
  - Syslog
- connectorId: SyslogAma
  dataTypes:
  - Syslog
queryFrequency: 5m
queryPeriod: 5m
triggerOperator: gt
triggerThreshold: 0
eventGroupingSettings:
  aggregationKind: AlertPerResult
tactics: []
relevantTechniques: []
query: "Veeam_GetSecurityEvents\n| where instanceId == 40206\n| project\n  Date =\
  \ format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n    DataSource = original_host,\n\
  \    EventId = instanceId,\n    UserName = user,\n   MessageDetails = Description,\n\
  \   Severity = SeverityDescription\n| project Date, DataSource, EventId, UserName,MessageDetails,Severity"
version: 1.0.1
kind: Scheduled
customDetails:
  Date: Date
  VbrHostName: DataSource
  EventId: EventId
  MessageDetails: MessageDetails
  Severity: Severity

Stages and Predicates

Stage 1: source

Veeam_GetSecurityEvents

Stage 2: where

| where instanceId == 40206

Stage 3: project

| project
  Date = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),
    DataSource = original_host,
    EventId = instanceId,
    UserName = user,
   MessageDetails = Description,
   Severity = SeverityDescription

Stage 4: project

| project Date, DataSource, EventId, UserName,MessageDetails,Severity

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
DataSourceproject
Dateproject
EventIdproject
MessageDetailsproject
Severityproject
UserNameproject