Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate host attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query creates a M

Attribute Value
Type Analytic Rule
Solution Vectra XDR
ID 231904f5-b670-4223-9bec-2e9aeca9cf5b
Severity High
Status Available
Kind Scheduled
Tactics Discovery, LateralMovement, CredentialAccess, Exfiltration, CommandAndControl, Persistence
Techniques T1046, T1021, T1003, T1041, T1071
Required Connectors VectraRUXConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Detections_Data_CCF_CL ? ✓ ?
Detections_Data_CL ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Vectra XDR