Detection rules › Kusto
Semperis DSP Operations Critical Notifications
Alerts when there are critical notifications fired in the DSP system.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Resource Development | |
| Initial Access | |
| Credential Access |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Semperis-DSP-Notifications | Event ID 30001: DSP critical notification |
Rule body
id: "8f471e21-3bb2-466f-9bc2-0a0326a60788"
name: Semperis DSP Operations Critical Notifications
description: |
'Alerts when there are critical notifications fired in the DSP system.'
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: SemperisDSP
dataTypes:
- dsp_parser
queryFrequency: 30m
queryPeriod: 30m
triggerOperator: gt
triggerThreshold: 0
tactics:
- InitialAccess
- CredentialAccess
- ResourceDevelopment
relevantTechniques:
- T1133
- T1110
- T1584
query: |
SecurityEvent
| where EventSourceName == 'Semperis-DSP-Notifications' and EventID == 30001
| extend p1Xml = parse_xml(EventData).EventData.Data
| mv-expand bagexpansion=array p1Xml
| evaluate bag_unpack(p1Xml)
| extend Name=column_ifexists('@Name', ''), Value=column_ifexists('#text', '')
| evaluate pivot(Name, any(Value), TimeGenerated, EventSourceName, Channel, Computer, Level, EventLevelName, EventID, Task, Type, _ResourceId)
| parse column_ifexists('objectDN', '') with * "CN=" cnName "," *
| where "Critical" == column_ifexists('severity', "")
| extend changedBy = column_ifexists('changedBy', "")
| extend NTDomain = tostring(split(changedBy, '\\', 0)[0]), LoginUser = tostring(split(changedBy, '\\', 1)[0])
| extend HostName = tostring(split(Computer, '.', 0)[0]), DnsDomain = tostring(strcat_array(array_slice(split(Computer, '.'), 1, -1), '.'))
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: LoginUser
- identifier: NTDomain
columnName: NTDomain
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: HostName
- identifier: DnsDomain
columnName: DnsDomain
eventGroupingSettings:
aggregationKind: SingleAlert
alertDetailsOverride:
alertDisplayNameFormat: Critical Notification -- Alert from Semperis Directory Services Protector
alertDescriptionFormat: A critical notification was created in the DSP system.
version: 2.0.7
kind: Scheduled
Stages and Predicates
Stage 1: source
SecurityEvent
Stage 2: where
| where EventSourceName == 'Semperis-DSP-Notifications' and EventID == 30001
Stage 3: extend
| extend p1Xml = parse_xml(EventData).EventData.Data
Stage 4: mv-expand
| mv-expand bagexpansion=array p1Xml
Stage 5: evaluate
| evaluate bag_unpack(p1Xml)
Stage 6: extend
| extend Name=column_ifexists('@Name', ''), Value=column_ifexists('#text', '')
Stage 7: evaluate
| evaluate pivot(Name, any(Value), TimeGenerated, EventSourceName, Channel, Computer, Level, EventLevelName, EventID, Task, Type, _ResourceId)
Stage 8: parse
| parse column_ifexists('objectDN', '') with * "CN=" cnName "," *
Stage 9: where
| where "Critical" == column_ifexists('severity', "")
Stage 10: extend (3 consecutive steps)
| extend changedBy = column_ifexists('changedBy', "")
| extend NTDomain = tostring(split(changedBy, '\\', 0)[0]), LoginUser = tostring(split(changedBy, '\\', 1)[0])
| extend HostName = tostring(split(Computer, '.', 0)[0]), DnsDomain = tostring(strcat_array(array_slice(split(Computer, '.'), 1, -1), '.'))
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventID | eq |
| field:"EventID" kind:eq value:"30001" |
EventSourceName | eq |
| field:"Category" kind:eq value:"Semperis-DSP-Notifications" |
Output fields
These fields are emitted when the rule matches.
| Field | Source |
|---|---|
p1Xml | extend |
Name | extend |
Value | extend |
changedBy | extend |
LoginUser | extend |
NTDomain | extend |
DnsDomain | extend |
HostName | extend |