Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This detection identifies high-severity alerts across various Microsoft security products, including Microsoft Defender XDR and Microsoft Entra ID, and correlates them with instances of Google Cloud VM creation. It focuses on instances where VMs were created within a short timeframe of high-severity alerts, potentially indicating suspicious activity.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | GitHub Only |
| ID | 1cc0ba27-c5ca-411a-a779-fbc89e26be83 |
| Severity | Medium |
| Kind | Scheduled |
| Tactics | InitialAccess, Execution, Discovery |
| Techniques | T1078, T1106, T1526 |
| Required Connectors | GCPAuditLogsDefinition, AzureActiveDirectoryIdentityProtection, MicrosoftThreatProtection, MicrosoftDefenderAdvancedThreatProtection, MicrosoftCloudAppSecurity, BehaviorAnalytics |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
GCPAuditLogs |
MethodName endswith "instances.insert"ServiceName == "compute.googleapis.com" |
✓ | ✓ | ✓ |
IdentityInfo |
✓ | ✗ | ✓ | |
SecurityAlert |
AlertSeverity has_any "Medium"ProductName in "Azure Active Directory,Azure Active Directory Identity Protection,Microsoft 365 Defender,Microsoft Cloud App Security,Microsoft Defender ATP,Microsoft Defender Advanced Threat Protection" |
✓ | ✗ | ✓ |
The following connectors provide data for this content item:
| Connector | Solution |
|---|---|
| AzureActiveDirectoryIdentityProtection | Microsoft Entra ID Protection |
| GCPAuditLogsDefinition | Google Cloud Platform Audit Logs |
| GCPPub/SubAuditLogs | Google Cloud Platform Audit Logs |
Solutions: Google Cloud Platform Audit Logs, Microsoft Entra ID Protection
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊