Detection rules › Splunk

Microsoft Defender Incident Alerts

Status
production
Severity
medium
Group by
description, id
Author
Bryan Pluta, Bhavin Patel, Splunk, lyonheart14, Github Community
Source
github.com/splunk/security_content

The following analytic is to leverage alerts from Microsoft Defender O365 Incidents. This query aggregates and summarizes all alerts from Microsoft Defender O365 Incidents, providing details such as the destination, file name, severity, process command line, ip address, registry key, signature, description, unique id, and timestamps. This detection is not intended to detect new activity from raw data, but leverages Microsoft provided alerts to be correlated with other data as part of risk based alerting. The data contained in the alert is mapped not only to the risk object, but also the threat object. This detection filters out evidence that has a verdict of clean from Microsoft. It dynamically maps the MITRE technique at search time to auto populate the annotation field with the value provided in the alert. It also uses a static mapping to set the risk score based on the severity of the alert.

Known false positives

  • False positives may vary based on Microsoft Defender configuration; monitor and filter out the alerts that are not relevant to your environment.

Rule body

name: Microsoft Defender Incident Alerts
id: 13435b55-afd8-46d4-9045-7d5457f430a5
version: 9
creation_date: '2024-10-30'
modification_date: '2026-05-13'
author: Bryan Pluta, Bhavin Patel, Splunk, lyonheart14, Github Community
status: production
type: TTP
description: The following analytic is to leverage alerts from Microsoft Defender O365 Incidents. This query aggregates and summarizes all alerts from Microsoft Defender O365 Incidents, providing details such as the destination, file name, severity, process command line, ip address, registry key, signature, description, unique id, and timestamps. This detection is not intended to detect new activity from raw data, but leverages Microsoft provided alerts to be correlated with other data as part of risk based alerting. The data contained in the alert is mapped not only to the risk object, but also the threat object. This detection filters out evidence that has a verdict of clean from Microsoft. It dynamically maps the MITRE technique at search time to auto populate the annotation field with the value provided in the alert. It also uses a static mapping to set the risk score based on the severity of the alert.
data_source:
    - MS365 Defender Incident Alerts
search: "`ms365_defender_incident_alerts`  (dest=* OR user=*)\n  | eval tmp_entities=json_extract(_raw, \"entities\"), tmp_entitymv=json_array_to_mv(tmp_entities), tmp_filtered_mv=mvfilter(json_extract(tmp_entitymv, \"verdict\") != \"Clean\"), entityType = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"entityType\")), filePath = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"filePath\")), processCommandLine = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"processCommandLine\")), ipAddress = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"ipAddress\")), registryKey = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"registryKey\")), url = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"url\"))\n  | eval tmp_filtered_mv=mvfilter(json_extract(tmp_filtered_mv, \"entityType\") = \"File\"), fileName = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, \"fileName\"))\n  | eval risk_score=case(severity=\"informational\", 5, severity=\"low\", 15, severity=\"medium\", 25, severity=\"high\", 50, true(), 2)\n  | stats count  min(_time) as firstTime max(_time) as lastTime values(fileName) as file_name values(severity) as severity values(processCommandLine) as process values(ipAddress) as ip_address values(registryKey) as registry_key values(url) as url values(mitreTechniques{}) as annotations.mitre_attack.mitre_technique_id values(signature) as signature values(dest) as dest values(user) as user values(risk_score) as risk_score\n    BY id description\n  | `security_content_ctime(firstTime)`\n  | `security_content_ctime(lastTime)`\n  | `microsoft_defender_incident_alerts_filter`"
how_to_implement: In order to properly run this search, you need to ingest alerts data from Microsoft Defender, specifcally using the Splunk add-on for Microsoft Security. This add-on will collect alerts using the ms365:defender:incident:alerts sourcetype. You will need to define the `ms365_defender_incident_alerts` macro to point to the proper index that contains the ms365:defender:incident:alerts sourcetype.
known_false_positives: False positives may vary based on Microsoft Defender configuration; monitor and filter out the alerts that are not relevant to your environment.
references:
    - https://learn.microsoft.com/en-us/defender-xdr/api-list-incidents?view=o365-worldwide
    - https://learn.microsoft.com/en-us/graph/api/resources/security-alert?view=graph-rest-1.0
    - https://splunkbase.splunk.com/app/6207
    - https://jasonconger.com/splunk-azure-gdi/
finding:
    title: $severity$ alert for $dest$ - $signature$
    entity:
        field: user
        type: user
        score: 50
intermediate_findings:
    entities:
        - field: dest
          type: system
          score: 50
          message: $severity$ alert for $dest$ - $signature$
threat_objects:
    - field: file_name
      type: file_name
    - field: ip_address
      type: ip_address
    - field: process
      type: process_name
    - field: registry_key
      type: registry_path
    - field: url
      type: url
analytic_story:
    - Critical Alerts
asset_type: Endpoint
mitre_attack_id: []
product:
    - Splunk Enterprise
    - Splunk Enterprise Security
    - Splunk Cloud
category: endpoint
security_domain: endpoint

Stages and Predicates

Stage 1: search

`ms365_defender_incident_alerts`  (dest=* OR user=*)

Stage 2: eval

| eval tmp_entities=json_extract(_raw, "entities"), tmp_entitymv=json_array_to_mv(tmp_entities), tmp_filtered_mv=mvfilter(json_extract(tmp_entitymv, "verdict") != "Clean"), entityType = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "entityType")), filePath = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "filePath")), processCommandLine = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "processCommandLine")), ipAddress = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "ipAddress")), registryKey = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "registryKey")), url = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "url"))

Stage 3: eval

| eval tmp_filtered_mv=mvfilter(json_extract(tmp_filtered_mv, "entityType") = "File"), fileName = mvmap(tmp_filtered_mv, spath(tmp_filtered_mv, "fileName"))

Stage 4: eval

| eval risk_score=case(severity="informational", 5, severity="low", 15, severity="medium", 25, severity="high", 50, true(), 2)
risk_score =
ifseverity = "informational"5
elifseverity = "low"15
elifseverity = "medium"25
elifseverity = "high"50
else2

Stage 5: stats

| stats count  min(_time) as firstTime max(_time) as lastTime values(fileName) as file_name values(severity) as severity values(processCommandLine) as process values(ipAddress) as ip_address values(registryKey) as registry_key values(url) as url values(mitreTechniques{}) as annotations.mitre_attack.mitre_technique_id values(signature) as signature values(dest) as dest values(user) as user values(risk_score) as risk_score
    BY id description

Stage 6: search

| `security_content_ctime(firstTime)`

Stage 7: search

| `security_content_ctime(lastTime)`

Stage 8: search

| `microsoft_defender_incident_alerts_filter`

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
desteq
  • * corpus 2 (splunk 2)
field:"dest" kind:eq value:"*"
sourcetypeeq
  • ms365:defender:incident:alerts
field:"sourcetype" kind:eq value:"ms365:defender:incident:alerts"
usereq
  • * corpus 2 (splunk 2)
field:"user" kind:eq value:"*"