Vectra

Telemetry Evidence

These values show how indexed rules identify Vectra telemetry.

Kusto

  • Queried source table CommonSecurityLog (7 rules)
  • Queried source table Entities_Data_CL (4 rules)
  • Queried source table VectraDetections (2 rules)
  • Queried source table VectraDetectionsCombined (2 rules)
  • Query discriminator DeviceVendor = Vectra Networks (7 rules)
  • Source collection Vectra AI Detect (7 rules)

Detection Rules

Kusto #

  • Vectra Create Detection Alert for Accounts source medium: This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra PlatformT1546
  • Vectra Create Detection Alert for Hosts source medium: This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra PlatformT1546
  • Vectra Create Incident Based on Priority for Accounts source medium: Create an incident when an identity is suspected to be compromised. Vectra is using AI to prioritize an entity based on multiple factors (attack rating, velocity, breadth, importance.etc.). This layer of aggregation at the entity level provides a greater signal-to-noise ratio and help analyst focus on what matters.T1546
  • Vectra Create Incident Based on Priority for Hosts source medium: Create an incident when an identity is suspected to be compromised. Vectra is using AI to prioritize an entity based on multiple factors (attack rating, velocity, breadth, importance.etc.). This layer of aggregation at the entity level provides a greater signal-to-noise ratio and help analyst focus on what matters.T1546
  • Vectra Create Incident Based on Tag for Accounts source high: Create an incident when the account entity presents a specific tag. If the tag is present, an incident should be created and marked with highest priority.T1546
  • Vectra Create Incident Based on Tag for Hosts source high: Create an incident when the host entity presents a specific tag. If the tag is present, an incident should be created and marked with highest priority.T1546
  • Vectra RUX - Create Incident for Escalated Account Detection or Unresolved Priority Account source high: This query creates a Microsoft Sentinel incident when a detection on an account entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate customer attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query creates a Microsoft Sentinel incident when Vectra AI identifies an account entity with one or more detections marked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns priority based on attack rating, velocity, breadth, and identity privilege level. This rule surfaces account-based threats that require analyst attention. Incidents are grouped per account entity and remain open while the threat persists. Once all associated detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.T1003, T1041, T1071, T1078, T1110
  • Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host source high: This query creates a Microsoft Sentinel incident when a detection on a host entity has been escalated in Vectra (investigation_status = escalated). Escalation indicates that a human analyst or MDR service has reviewed the detection and determined it requires immediate host attention or notification. One incident is created per detection - grouping is based on alert display name so that repeated rule evaluations against the same detection do not create duplicate incidents. This query creates a Microsoft Sentinel incident when Vectra AI identifies a host entity with one or more detections marked as unresolved and prioritized (unresolved_priority = true). Vectra's AI engine assigns priority based on attack rating, velocity, breadth, and host privilege level. This rule surfaces host-based threats that require analyst attention. Incidents are grouped per host entity and remain open while the threat persists. Once all associated detections are resolved in Vectra, the incident can be closed in Microsoft Sentinel.T1003, T1021, T1041, T1046, T1071

Product-Filtered Rules

These rules use generic transport telemetry with a product-specific filter for Vectra.

Kusto #

Compatible Rules

These rules declare Vectra connector or schema compatibility without a product-specific query filter.

Kusto #

Package-Only Rules

These rules appear in the Vectra Sentinel solution, but their queries do not identify Vectra telemetry. They do not count toward Rules.

Kusto #

  • Defender Alert Evidence source high: This analytic rule is looking for new alert evidence from Microsoft Defender for Endpoint. The intent is to create entries in the SecurityAlert table for every new alert evidence attached to an entity of type Device or User monitored by Defender for Endpoint.T1546