Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This query creates a Microsoft Sentinel incident when a detection on an account entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate customer attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query cre
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Vectra XDR |
| ID | 231904f5-b670-4223-9bec-2e9aeca9cf5a |
| Severity | High |
| Status | Available |
| Kind | Scheduled |
| Tactics | Discovery, LateralMovement, CredentialAccess, Exfiltration, CommandAndControl, Persistence |
| Techniques | T1078, T1110, T1003, T1041, T1071 |
| Required Connectors | VectraRUXConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
Detections_Data_CCF_CL |
? | ✓ | ? |
Detections_Data_CL |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊