Vectra RUX - Create Incident for Escalated Account Detection or Unresolved Priority Account

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This query creates a Microsoft Sentinel incident when a detection on an account entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate customer attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query cre

Attribute Value
Type Analytic Rule
Solution Vectra XDR
ID 231904f5-b670-4223-9bec-2e9aeca9cf5a
Severity High
Status Available
Kind Scheduled
Tactics Discovery, LateralMovement, CredentialAccess, Exfiltration, CommandAndControl, Persistence
Techniques T1078, T1110, T1003, T1041, T1071
Required Connectors VectraRUXConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Detections_Data_CCF_CL ? ✓ ?
Detections_Data_CL ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Vectra XDR