Detection rules › Kusto

ClientDeniedAccess

Status
available
Severity
medium
Time window
1h
Group by
ClientIP, User
Source
github.com/Azure/Azure-Sentinel

'Creates an incident in the event a Client has an excessive amounts of denied access requests.'

MITRE ATT&CK coverage

TacticTechniques
Credential Access

Rule body

id: a9956d3a-07a9-44a6-a279-081a85020cae
name: ClientDeniedAccess
description: |
  'Creates an incident in the event a Client has an excessive amounts of denied access requests.'
severity: Medium
requiredDataConnectors:
  - connectorId: SyslogAma
    datatypes:
      - Syslog
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
triggerThreshold: 0
tactics:
  - CredentialAccess
relevantTechniques:
  - T1110
query: |
  let threshold = 15;
  let rejectedAccess = SymantecVIP
  | where isnotempty(RADIUSAuth)
  | where RADIUSAuth =~ "Reject"
  | summarize Total = count() by ClientIP, bin(TimeGenerated, 15m)
  | where Total > threshold
  | project ClientIP;
  SymantecVIP
  | where isnotempty(RADIUSAuth)
  | where RADIUSAuth =~ "Reject"
  | join kind=inner rejectedAccess on ClientIP
  | summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated), count() by ClientIP, User
entityMappings:
  - entityType: Account
    fieldMappings:
      - identifier: FullName
        columnName: User
  - entityType: IP
    fieldMappings:
      - identifier: Address
        columnName: ClientIP
version: 1.0.4
status: Available
kind: Scheduled

Stages and Predicates

Stage 0: let

let threshold = 15;
let rejectedAccess = SymantecVIP
| where isnotempty(RADIUSAuth)
| where RADIUSAuth =~ "Reject"
| summarize Total = count() by ClientIP, bin(TimeGenerated, 15m)
| where Total > threshold
| project ClientIP;

Stage 1: source

SymantecVIP

Stage 2: where

| where isnotempty(RADIUSAuth)

Stage 3: where

| where RADIUSAuth =~ "Reject"

Stage 4: join

| join kind=inner rejectedAccess on ClientIP

Stage 5: summarize

summarize EndTime, StartTime by ClientIP, User

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
ClientIPsummarize
EndTimesummarize
StartTimesummarize
Usersummarize