Menjalankan kueri UDM

Didukung di:

Dokumen ini ditujukan bagi pengelola dan analis Security Operations Center (SOC) yang ingin memantau lanskap ancaman dan kondisi sistem menggunakan dasbor pilihan—dasbor yang telah ditentukan sebelumnya dan didesain untuk visibilitas di berbagai kasus penggunaan keamanan di Google Security Operations. Dokumen ini menyediakan kumpulan dasbor yang dikurasi dan kueri yang mendasarinya untuk jenis sumber UDM.

Tabel berikut memberikan daftar diagram dan contoh kuerinya untuk setiap dasbor pilihan. Anda dapat menggunakan kueri ini di editor kueri atau sebagai dasar untuk widget kustom. Untuk mengetahui informasi tentang cara membuat dan mengelola dasbor, lihat Mengelola dasbor.

Kontrol Aplikasi

Dasbor ini memberikan insight tentang keamanan aplikasi, sehingga membantu tim keamanan mendeteksi software yang tidak sah dan menerapkan kebijakan penggunaan. Fitur ini mendukung visibilitas terhadap perilaku berisiko, upaya yang diblokir, dan pola aktivitas yang tidak biasa.

Nama diagram Contoh kueri
Eksekusi Aplikasi dari Waktu ke Waktu
metadata.product_event_type = /(execution|application) (allow|block)/ nocase
or security_result.threat_name = /application control/ nocase

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F")

match:
  $Date

outcome:
  $Count = count(metadata.id)
10 Eksekusi Aplikasi yang Tidak Disetujui Teratas (Mode Audit/Izinkan)
metadata.product_event_type != /(execution|application) block/ nocase
metadata.product_event_type = /unapproved/ nocase

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])

match:
  $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Aplikasi Teratas yang Dieksekusi dari Media yang Dapat Dihapus
metadata.product_event_type = /(execution|application) (allow|block)/ nocase
or security_result.threat_name = /application control/ nocase
strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"]) = /(^(D|E|F|G):)|\/\/removable|usb/ nocase

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])

match:
  $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Eksekusi Aplikasi yang Diblokir Teratas Berdasarkan Alasan
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])
$Reason = strings.coalesce(target.resource.attribute.labels["categoryTupleDescription"], security_result.action_details, metadata.product_event_type)

match:
  $Application, $Reason

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Status Eksekusi Aplikasi dari Waktu ke Waktu
metadata.product_event_type = /(execution|application) (allow|block)/ nocase
or security_result.threat_name = /application control/ nocase

$Action = strings.coalesce(if(security_result.action = "BLOCK", "BLOCK", "ALLOW"), if(metadata.product_event_type = /(execution|application) block/ nocase, "BLOCK", "ALLOW"))
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds,"%F")

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
10 Eksekusi Aplikasi yang Diblokir Teratas
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])

match:
  $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Aplikasi yang Dieksekusi dari Lokasi yang Tidak Biasa
strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"]) = /C\:\\(?:Users|Temp|Windows)\\(?:.*\\(?:AppData|Downloads)?|Temp)?/ nocase

$File_Path = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])

match:
  $File_Path
10 Host Teratas menurut Eksekusi yang Diblokir
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$Host = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname)

match:
  $Host

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas berdasarkan Eksekusi yang Diblokir
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$User = strings.coalesce(target.user.userid, target.user.user_display_name, principal.user.userid, principal.user.user_display_name)

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Eksekusi yang Diblokir - Per Jam
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$Hours = timestamp.get_timestamp(metadata.event_timestamp.seconds,"%F %H:00")

match:
  $Hours

outcome:
  $Count = count(metadata.id)

order:
  $Hours desc 

Cloud Access Security Broker

Dasbor ini memberikan ringkasan tentang penggunaan aplikasi cloud, peristiwa keamanan, ancaman, dan akses tidak sah. Alat ini memantau pemberitahuan teratas, aktivitas dan tindakan pengguna, serta alamat IP sumber dan tujuan untuk meningkatkan penegakan kebijakan dan respons risiko.

Nama diagram Contoh kueri
10 Agen Pengguna Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$User_Agent = network.http.user_agent
$Log_Type = metadata.log_type

match:
  $User_Agent, $Log_Type

outcome:
  $Count = count(network.http.user_agent)

order:
  $Count desc

limit:
    10
10 Aplikasi Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Application = target.application
$Log_Type = metadata.log_type
$Application != ""
match:
  $Application, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Aktivitas CASB Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Activity = strings.coalesce(security_result.summary, metadata.description)
$Log_Type = metadata.log_type
$Activity != ""
match:
  $Activity, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Tujuan Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$IP_Address = target.ip
$Log_Type = metadata.log_type
$IP_Address != ""
match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Host Tujuan Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Hostname = target.hostname
$Log_Type = metadata.log_type

match:
  $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa menurut Tindakan: Izinkan vs. Blokir
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/
security_result.action = "ALLOW"
or security_result.action = "BLOCK"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(security_result.action)
Distribusi Jenis Autentikasi
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Log_Type = metadata.log_type
$Product_Event = metadata.product_event_type
$Authentication = extensions.auth.type

match:
  $Log_Type, $Product_Event, $Authentication

outcome:
  $Count = count(metadata.id)
10 Pemberitahuan Vendor Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Rule_Name = security_result.rule_name
$Log_Type = metadata.log_type
$Rule_Name != ""
match:
  $Rule_Name, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Aktivitas CASB Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Activity = strings.coalesce(security_result.summary, metadata.description)
$Log_Type = metadata.log_type

match:
  $Activity, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pemberitahuan Vendor Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Rule_Name = security_result.rule_name
$Log_Type = metadata.log_type

match:
  $Rule_Name, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Host Sumber Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Hostname = principal.hostname
$Log_Type = metadata.log_type
$Hostname != ""
match:
  $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi OS
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Platform = principal.platform

match:
  $Platform

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Pengguna Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$User = principal.user.userid
$Log_Type = metadata.log_type

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Host Tujuan Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Hostname = target.hostname
$Log_Type = metadata.log_type
$Hostname != ""
match:
  $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna yang Paling Banyak Diblokir
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase
security_result.action = "BLOCK"

$User = principal.user.userid
$Log_Type = metadata.log_type

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu menurut Jenis Log
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Agen Pengguna Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$User_Agent = network.http.user_agent
$Log_Type = metadata.log_type

match:
  $User_Agent, $Log_Type

outcome:
  $Count = count(network.http.user_agent)

order:
  $Count desc

limit:
    10
Peristiwa menurut Tindakan: Izinkan vs. Blokir
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase
security_result.action = "ALLOW"
or security_result.action = "BLOCK"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(security_result.action)
10 Aplikasi Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Application = target.application
$Log_Type = metadata.log_type

match:
  $Application, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$IP_Address = principal.ip
$Log_Type = metadata.log_type

match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$IP_Address = principal.ip
$Log_Type = metadata.log_type
$IP_Address != ""
match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Jenis Peristiwa Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Event_Type = metadata.event_type
$Log_Type = metadata.log_type

match:
  $Event_Type, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi OS
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Platform = principal.platform

match:
  $Platform

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Jenis Peristiwa Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Event_Type = metadata.event_type
$Log_Type = metadata.log_type

match:
  $Event_Type, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 URL teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$URL = target.url
$Log_Type = metadata.log_type
$URL != ""
match:
  $URL, $Log_Type

outcome:
  $Count = count(target.url)

order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu menurut Jenis Log
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Lokasi Sumber Peristiwa CASB Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Country = principal.location.country_or_region
$Latitude = principal.location.region_latitude
$Latitude != 0
$Longitude = principal.location.region_longitude
$Longitude != 0

match:
  $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Lokasi Sumber Peristiwa CASB Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$Country = principal.location.country_or_region
$Latitude = principal.location.region_latitude
$Latitude != 0
$Longitude = principal.location.region_longitude
$Longitude != 0

match:
  $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna yang Paling Banyak Diblokir
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/
security_result.action = "BLOCK"

$User = principal.user.userid
$Log_Type = metadata.log_type
$User != ""
match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 URL teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$URL = target.url
$Log_Type = metadata.log_type

match:
  $URL, $Log_Type

outcome:
  $Count = count(target.url)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/

$User = principal.user.userid
$Log_Type = metadata.log_type
$User != ""
match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi Jenis Autentikasi
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Log_Type = metadata.log_type
$Product_Event = metadata.product_event_type
$Authentication = extensions.auth.type

match:
  $Log_Type, $Product_Event, $Authentication

outcome:
  $Count = count(metadata.id)
10 Nama Host Sumber Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$Hostname = principal.hostname
$Log_Type = metadata.log_type

match:
  $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Tujuan Teratas
metadata.log_type = /_CASB|SMARTSHEET|CISCO_SDWAN|NETSKOPE_CLIENT|ORACLE_NETSUITE|TAILSCALE/ nocase

$IP_Address = target.ip
$Log_Type = metadata.log_type

match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Operasi Chrome Enterprise Premium

Dasbor ini memberikan ringkasan tentang integrasi Chrome Enterprise Premium dengan Google SecOps. Hal ini mencakup informasi tentang browser dan profil yang dikelola.

Nama diagram Contoh kueri
Ekstensi Browser yang Di-sideload
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "browserExtensionInstallEvent"
target.resource.attribute.labels["extension_source"] != "CHROME_WEBSTORE"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Source_Store = target.resource.attribute.labels["extension_source"]
$Browser_Extension = target.resource.name
$Browser_Extension_ID = target.resource.product_object_id

match:
  $Date, $Source_Store, $Browser_Extension, $Browser_Extension_ID
Ekstensi Browser yang Paling Banyak Diinstal
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "browserExtensionInstallEvent"
target.resource.attribute.labels["extension_action"] = "INSTALL"

$Browser_Extension = target.resource.name
$Browser_Extension_ID = target.resource.product_object_id
$Extension_Version = target.resource.attribute.labels["extension_version"]
$Extension_Source = target.resource.attribute.labels["extension_source"]

match:
  $Browser_Extension, $Browser_Extension_ID, $Extension_Version, $Extension_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc 
Acara Chrome
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type != ""

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Event_Type = metadata.product_event_type

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)
Kesehatan Telemetri Chrome
metadata.log_type = "CHROME_MANAGEMENT"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Browser Terkelola Teratas menurut Versi Chrome
metadata.log_type = "CHROME_MANAGEMENT"
network.http.parsed_user_agent.browser_version != ""
principal.application != ""

$Browser_Version = network.http.parsed_user_agent.browser_version
$Application = principal.application

match:
  $Browser_Version, $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Browser Terkelola Teratas menurut Sistem Operasi
metadata.log_type = "CHROME_MANAGEMENT"
network.http.parsed_user_agent.os != ""
principal.application != ""

$OS = network.http.parsed_user_agent.os
$Application = principal.application

match:
  $OS, $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Organisasi Pengelolaan
metadata.log_type = "CHROME_MANAGEMENT"
target.domain.name != ""

$Organization = target.domain.name

match:
  $Organization

outcome:
  $Count = count(principal.user.email_addresses)

order:
  $Count desc 
Ekstensi Browser yang Paling Banyak Digunakan
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "browserExtensionInstallEvent"
target.resource.attribute.labels["extension_action"] = "INSTALL"
or target.resource.attribute.labels["extension_action"] = "UPDATE"

$Browser_Extension = target.resource.name
$Browser_Extension_ID = target.resource.product_object_id
$Extension_Version = target.resource.attribute.labels["extension_version"]
$Extension_Source = target.resource.attribute.labels["extension_source"]

match:
  $Browser_Extension, $Browser_Extension_ID, $Extension_Version, $Extension_Source

outcome:
  $Total_Unique_Instances = count(metadata.id)

order:
  $Total_Unique_Instances desc 
10 Pengguna Teratas dengan Ekstensi Browser yang Paling Banyak Diinstal
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "browserExtensionInstallEvent"

$User = principal.user.email_addresses

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Ekstensi Browser menurut Izin
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "extensionTelemetryEvent"
target.resource.name = "COOKIES_GET_ALL_INFO"
or target.resource.name = "COOKIES_GET_INFO"
or target.resource.name = "TABS_API_INFO"

$Browser_Extension = target.resource_ancestors.name
$Browser_Extension_ID = target.resource_ancestors.product_object_id
$Extension_Version = target.resource_ancestors.attribute.labels["extension_version"]
$Extension_Source = target.resource_ancestors.attribute.labels["extension_source"]
$Severity = security_result.severity

match:
  $Browser_Extension, $Browser_Extension_ID, $Extension_Version, $Extension_Source, $Severity

outcome:
  $Permissions = array_distinct(target.resource.name)
  $Count = count(metadata.id)

order:
  $Browser_Extension asc 
Ekstensi Browser yang Paling Sedikit Diinstal
metadata.log_type = "CHROME_MANAGEMENT"
metadata.product_event_type = "browserExtensionInstallEvent"
target.resource.attribute.labels["extension_action"] = "INSTALL"

$Browser_Extension = target.resource.name
$Browser_Extension_ID = target.resource.product_object_id
$Extension_Version = target.resource.attribute.labels["extension_version"]
$Extension_Source = target.resource.attribute.labels["extension_source"]

match:
  $Browser_Extension, $Browser_Extension_ID, $Extension_Version, $Extension_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count asc

Keamanan Chrome Enterprise Premium

Dasbor ini memberikan insight real-time tentang peristiwa keamanan terkait Chrome seperti transfer data sensitif, akses ke domain berisiko tinggi, peristiwa perlindungan data, upaya malware dan phishing, serta masalah keamanan sandi. Fitur ini memungkinkan tim keamanan memantau, menyelidiki, dan merespons ancaman berbasis Chrome.

Nama diagram Contoh kueri
DLP Chrome : Insight Data
metadata.product_event_type = /sensitiveDataEvent|contentTransferEvent/ nocase
security_result.summary = /CONTENT_MATCHED_SENSITIVE_DATA_TYPES/ nocase or extracted.fields["reason"] = /CONTENT_MATCHED_SENSITIVE_DATA_TYPES/ nocase

$Sensitive_Data_Type = extracted.fields["matched_detectors[0].detector_id"]
$Trigger_Type = security_result.about.labels.value

match:
  $Sensitive_Data_Type, $Trigger_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
DLP Chrome : Total Transfer Web Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase
security_result.about.labels.value = /web_content_upload/ nocase

outcome:
  $Sensitive_Web_Transfer = count(metadata.id)
DLP Chrome : Total Cetakan File Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase
security_result.about.labels.value = /print/ nocase

outcome:
  $Sensitive_File_Print = count(metadata.id)
DLP Chrome : Total Upload File Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase
security_result.about.labels.value = /file_upload/ nocase

outcome:
  $Sensitive_File_Upload = count(metadata.id)
Peristiwa Penggunaan Ulang Sandi
metadata.product_event_type = /PASSWORD_REUSE|passwordReuseEvent/ nocase

$Action = security_result.action_details
$Severity = security_result.severity
$User = strings.coalesce(principal.user.userid , principal.user.user_display_name, principal.user.email_addresses)
$Summary = strings.coalesce(security_result.summary, security_result.description, metadata.product_event_type, security_result.category_details)
$URL = target.url

match:
  $User, $Summary, $Severity, $Action, $URL

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Domain Berisiko Tinggi Chrome
extracted.fields["url_info.risk_infos[0].risk_level"] = "HIGH"
target.url != ""

$URL = target.url
$Category = security_result.category
$Action = security_result.action_details
$Severity = principal.security_result.severity
$Risk_Level = extracted.fields["url_info.risk_infos[0].risk_level"]
$Threat_Type = extracted.fields["url_info.risk_infos[0].threat_type"]
$Domain = re.capture(target.url, `^(?:https?:\/\/)?(?:www\.)?([^\/:]+)`)

match:
  $URL, $Domain, $Category, $Severity, $Risk_Level, $Threat_Type, $Action

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Kebocoran Sandi
metadata.product_event_type = /passwordBreachEvent/ nocase

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Summary = strings.coalesce(security_result.summary, security_result.description, metadata.product_event_type, security_result.category_details)
$URL = target.url
$Action = security_result.action_details
$Severity = security_result.severity

match:
  $User, $Summary, $URL, $Severity, $Action

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa Malware
metadata.product_event_type = /dangerousDownloadEvent|contentTransferEvent/ nocase
(extracted.fields["content_risk[0].risk_level"] = "HIGH" or extracted.fields["content_risk_level"] = "HIGH")
(extracted.fields["content_risk[0].threat_type"] = "MALWARE")

$File_Hash = target.file.sha256
$File_Path = target.file.full_path
$Category = security_result.category
$Severity = security_result.severity
$Risk_Level = strings.coalesce(extracted.fields["content_risk[0].risk_level"],extracted.fields["content_risk_level"])

match:
  $File_Path, $File_Hash, $Category, $Severity, $Risk_Level

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Summary = array_distinct(security_result.summary)
  $Action = array_distinct(security_result.action_details)
  $Count = count(metadata.id)

order:
  $Count desc
Kunjungan Situs yang Tidak Aman
metadata.product_event_type = /badNavigationEvent/ nocase
(extracted.fields["url_info.risk_infos[0].risk_level"] = "HIGH" OR extracted.fields["url_info.risk_level"] = "HIGH")
//(extracted.fields["content_risk[0].threat_type"] = "MALWARE" or extracted.fields["tab_url_info.threat_type"] = "MALWARE")

$URL = target.url
$Category = security_result.category
$Threat_Type = extracted.fields["url_info.risk_infos[0].threat_type"]
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Risk_Level = strings.coalesce(extracted.fields["url_info.risk_infos[0].risk_level"], extracted.fields["url_info.risk_level"])

match:
  $User, $URL, $Category, $Threat_Type, $Risk_Level

outcome:
  $Action = array_distinct(security_result.action_details)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Phishing
extracted.fields["url_info.risk_infos[0].threat_type"] = "SOCIAL_ENGINEERING"

$URL = target.url
$Category = security_result.category
$Action = security_result.action_details
$Severity = principal.security_result.severity
$Risk_Level = extracted.fields["url_info.risk_infos[0].risk_level"]
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $User, $URL, $Category, $Severity, $Risk_Level, $Action

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
DLP Chrome : Total Transfer Konten Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase

outcome:
  $Total_Sensitive_Content_Transfer = count(metadata.id)
DLP Chrome : Total Download File Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase
security_result.about.labels.value = /file_download/ nocase

outcome:
  $Sensitive_File_Download = count(metadata.id)
DLP Chrome: Pengguna dengan Deteksi Konten Sensitif
metadata.product_event_type = /sensitiveDataEvent/ nocase or security_result.summary = /CONTENT_MATCHED_SENSITIVE_DATA_TYPES/ nocase

$Device_IP = extracted.fields["remote_ip"]
$Device_ID = extracted.fields["device_id"]
$Action = security_result.action_details
$Severity = principal.security_result.severity
$Trigger_Type = security_result.about.labels.value
$Sensitive_Data_Type = extracted.fields["matched_detectors[0].display_name"]
$Device_User = strings.coalesce(extracted.fields["device_user"], extracted.fields["profile_user"])

match:
  $Device_User, $Device_IP, $Device_ID, $Trigger_Type, $Sensitive_Data_Type, $Action, $Severity

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
DLP Chrome : Domain Konten Sensitif
metadata.product_event_type = /Sensitive data transfer|SENSITIVE_DATA_TRANSFER|sensitiveDataEvent|sensitiveDataTransferEvent/ nocase
or security_result.summary = /CONTENT_MATCHED_SENSITIVE_DATA_TYPES/ nocase
target.url != ""

$Domain = target.url
$Action = security_result.action_details
$Severity = security_result.severity
$Sensitive_Data_Type = extracted.fields["matched_detectors[0].display_name"]

match:
  $Domain, $Action, $Severity, $Sensitive_Data_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc

Ringkasan Kepatuhan CIS Controls

Dasbor ini memperkuat tata kelola keamanan dengan menawarkan visibilitas yang jelas terhadap kepatuhan terhadap CIS Critical Security Controls. Layanan ini melacak metrik kepatuhan penting seperti akurasi inventaris aset, progres perbaikan kerentanan, keandalan pencadangan, penegakan kontrol akses, dan kesiapan respons insiden.

Nama diagram Contoh kueri
Pengguna Tidak Aktif (Lebih dari 7 Hari)
stage inactive_users {
    (metadata.event_type = "USER_UNCATEGORIZED"
    or metadata.event_type = "USER_LOGIN"
    or metadata.event_type = "USER_LOGOUT"
    or metadata.event_type = "USER_CREATION"
    or metadata.event_type = "USER_CHANGE_PASSWORD"
    or metadata.event_type = "USER_CHANGE_PERMISSIONS"
    or metadata.event_type = "USER_BADGE_IN"
    or metadata.event_type = "USER_DELETION"
    or metadata.event_type = "USER_RESOURCE_CREATION"
    or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
    or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
    or metadata.event_type = "USER_COMMUNICATION"
    or metadata.event_type = "USER_RESOURCE_ACCESS"
    or metadata.event_type = "USER_RESOURCE_DELETION")
    principal.user.last_login_time.seconds > 0

  $Event_Type = metadata.event_type
  $User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
  $User != ""
  $Log_Type = metadata.log_type

    match:
      $User, $Event_Type, $Log_Type

        outcome:
           $Logtime = max(metadata.event_timestamp.seconds)
           $Lastime = max(principal.user.last_login_time.seconds)
          $Time_Difference = cast.as_int(max(metadata.event_timestamp.seconds - principal.user.last_login_time.seconds)/86400)

             condition:
              $Time_Difference > 7

}
$User = $inactive_users.User
$Event_Type = $inactive_users.Event_Type
$Log_Type = $inactive_users.Log_Type

match:
  $User, $Event_Type, $Log_Type

outcome:
  $Last_Login = timestamp.get_timestamp(max($inactive_users.Lastime))
  $Latest_Login = timestamp.get_timestamp(max($inactive_users.Logtime))
  $Time_Difference = max($inactive_users.Time_Difference)

order:
  $Time_Difference desc
Eksekusi Aplikasi yang Diblokir Terbaru
(metadata.product_event_type = /(execution|application) block/ nocase or security_result.summary = /(execution|application) block/ or metadata.description = /(execution|application) block/ nocase or security_result.threat_name = /application control/ nocase)
(security_result.action = "BLOCK" or security_result.action_details = /block/ nocase or (target.resource.attribute.labels.key = "categoryBehavior" and target.resource.attribute.labels.value = /blocked/ nocase))

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"], principal.application, target.application)
$Description = strings.coalesce(target.resource.attribute.labels["categoryTupleDescription"], security_result.summary, metadata.product_event_type, security_result.description, metadata.description, security_result.action_details)
$Log_Type = metadata.log_type
$Severity = security_result.severity

match:
  $Application, $Description, $Severity, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Ringkasan Autentikasi SSO
extensions.auth.type = "SSO"
(metadata.event_type = "USER_LOGIN" or metadata.event_type = "USER_LOGOUT")

$Description = strings.coalesce(security_result.summary, metadata.description, security_result.description, metadata.product_event_type)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Action = security_result.action
$Severity = security_result.severity

match:
  $User, $Description, $Source_Hostname, $Source_IP, $Action, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Severity desc, $Date desc
Distribusi Peristiwa IDS / IPS
metadata.log_type = /_IDS|_IPS|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
(metadata.event_type = "SCAN_UNCATEGORIZED"
or metadata.event_type = "SCAN_NETWORK"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP")

$Category = security_result.category

match:
  $Category

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa MFA Akun dengan Hak Istimewa dari Waktu ke Waktu
(re.regex(metadata.product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex(additional.fields["AuthenticationRequirement"], `multiFactorAuthentication`) nocase or re.regex(security_result.detection_fields.value, `MFA`) nocase or re.regex(metadata.product_event_type, `mfa(?:\S)?auth|auth(?:.*)?mfa`) nocase)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name,target.user.email_addresses)
$User = /admin|root|administrator|security|support|default/ nocase //It will be updated as per the client's environment.
$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Sistem Teratas dengan Kerentanan Kritis/Tinggi
metadata.log_type = /ARMIS_VULNERABILITIES|FINGERPRINT_JS|NUCLEUS_VULNERABILITY|QUALYS_ASSET_CONTEXT|QUALYS_SCAN|QUALYS_VIRTUAL_SCANNER|QUALYS_VM|RAPID7_INSIGHT|RAPID7_NEXPOSE|SNYK_SDLC|SPUR_FEEDS|STACKHAWK|SUBLIMESECURITY|SYMANTEC_SA|TENABLE_IO|TENABLE_OT|TENABLE_SC|UPGUARD|URLSCAN_IO/ nocase

(principal.asset.vulnerabilities.severity = "HIGH" or  extensions.vulns.vulnerabilities.severity = "HIGH" or security_result.severity = "HIGH"
or target.asset.vulnerabilities.severity = "HIGH") or (principal.asset.vulnerabilities.severity = "CRITICAL" or  extensions.vulns.vulnerabilities.severity = "CRITICAL"
or security_result.severity = "CRITICAL" or target.asset.vulnerabilities.severity = "CRITICAL")

$Severity =
    if (principal.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        principal.asset.vulnerabilities.severity,
    if (target.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        target.asset.vulnerabilities.severity,
    if (extensions.vulns.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        extensions.vulns.vulnerabilities.severity,
    "UNKNOWN_SEVERITY")))

$Vulnerability = strings.coalesce(
  if(principal.asset.vulnerabilities.name != "" and principal.asset.vulnerabilities.description != "",
    strings.concat(principal.asset.vulnerabilities.name, " : ", principal.asset.vulnerabilities.description),
    strings.coalesce(principal.asset.vulnerabilities.name, principal.asset.vulnerabilities.description)),
  if(additional.fields["ScanReference"] != "" and metadata.description != "",
    strings.concat(additional.fields["ScanReference"], " : ", metadata.description),
    strings.coalesce(additional.fields["ScanReference"], metadata.description)),
  if(extensions.vulns.vulnerabilities.vendor_vulnerability_id != "" and extensions.vulns.vulnerabilities.description != "",
    strings.concat(extensions.vulns.vulnerabilities.vendor_vulnerability_id, " : ", extensions.vulns.vulnerabilities.description),
    strings.coalesce(extensions.vulns.vulnerabilities.vendor_vulnerability_id, extensions.vulns.vulnerabilities.description)
  )
)
($Vulnerability != " : " and $Vulnerability != "")
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname, target.hostname, target.asset.hostname)
$Log_Type = metadata.log_type

match:
  $Hostname, $Vulnerability, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(strings.coalesce(extensions.vulns.vulnerabilities.name, extensions.vulns.vulnerabilities.description, extensions.vulns.vulnerabilities.vendor_vulnerability_id,
                                    principal.asset.vulnerabilities.name, target.asset.vulnerabilities.name, additional.fields["ScanReference"]))

order:
  $Count desc

limit:
    10
Peristiwa Phishing Terbaru
metadata.log_type = /MAIL|ABNORMAL_SECURITY|AREA1|COFENSE_TRIAGE|FIREEYE|FORCEPOINT|FORTINET|KNOWBE4_PHISHER|MICROSOFT_GRAPH_ALERT|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|PHISHLABS|PROOFPOINT|SYMANTEC_VIP|VOLTAGE|WORKSPACE_ALERTS/ nocase
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"

$Security_Event_Type = metadata.product_event_type
$Summary = strings.coalesce(security_result.summary, metadata.description, security_result.description)
$Sender = strings.coalesce(network.email.from, principal.user.email_addresses)
$Subject = network.email.subject
$File_Path = strings.coalesce(target.file.full_path, about.file.full_path, target.file.names)
$File_Type = strings.coalesce(about.file.mime_type, target.file.mime_type)

match:
  $Security_Event_Type, $Sender, $Subject, $File_Path, $File_Type, $Summary

outcome:
  $Count = count(metadata.id)
  $Receiver_Count = count_distinct(strings.coalesce(network.email.to, network.email.reply_to, target.user.email_addresses))
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Algoritma Enkripsi Lemah dari Waktu ke Waktu
(((target.resource.attribute.labels.key  = "keyProperties_type" or target.resource.attribute.labels.key  = "requestParameters.keySpec" or target.resource.attribute.labels.key = /key/ nocase) and target.resource.attribute.labels.value  = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/) or network.tls.cipher = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/)

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Perubahan Izin dari Waktu ke Waktu
(metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" or metadata.event_type = "USER_CHANGE_PERMISSIONS" or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS")
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Pembuatan Akun Pengguna Terbaru
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, principal.mac, principal.asset.mac, extracted.fields["access_device.hostname"],
if(target.resource.attribute.labels.key = "Private DnsName",target.resource.attribute.labels.value, ""),
principal.resource.product_object_id, target.resource.product_object_id,
if(security_result.detection_fields.key = "actor_2",security_result.detection_fields.value, "")
)
$Initiator = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$User_Created = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Log_Type, $Source_IP, $Source_Hostname, $Initiator, $User_Created

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")

order:
  $Date desc
Pembuatan Akun Pengguna dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Tren Keberhasilan v/s Kegagalan Koneksi VPN dari Waktu ke Waktu
metadata.log_type = /VPN|ZSCALER_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/ nocase

$Action = if ((strings.coalesce(security_result.summary, metadata.product_event_type, extracted.fields["connection-attempt-status"]) = /Success|Authenticated/ nocase), "SUCCESS", "FAIL")
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
    
Deteksi Malware dari Waktu ke Waktu
(metadata.product_event_type = /malware/ nocase or security_result.summary = /malware/ nocase or security_result.category_details = /malware/ nocase or metadata.description = /malware/ nocase or security_result.threat_name = /malware/ nocase or security_result.rule_name = /malware/ nocase or security_result.category = "SOFTWARE_MALICIOUS")

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Action = security_result.action

match :
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc

Kerentanan Tinggi/Kritis menurut Usia
(principal.asset.vulnerabilities.severity = "CRITICAL" or  extensions.vulns.vulnerabilities.severity = "CRITICAL"
or security_result.severity = "CRITICAL" or target.asset.vulnerabilities.severity = "CRITICAL") OR
(principal.asset.vulnerabilities.severity = "HIGH" or  extensions.vulns.vulnerabilities.severity = "HIGH"
or security_result.severity = "HIGH" or target.asset.vulnerabilities.severity = "HIGH")

(timestamp.as_unix_seconds(additional.fields["first_found"]) > 0 or extensions.vulns.vulnerabilities.first_found.seconds > 0)

$Severity =
    if (principal.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        principal.asset.vulnerabilities.severity,
    if (target.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        target.asset.vulnerabilities.severity,
    if (extensions.vulns.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        extensions.vulns.vulnerabilities.severity,
    "UNKNOWN_SEVERITY")))

$Vulnerability = strings.coalesce(
  if(principal.asset.vulnerabilities.name != "" and principal.asset.vulnerabilities.description != "",
    strings.concat(principal.asset.vulnerabilities.name, " : ", principal.asset.vulnerabilities.description),
    strings.coalesce(principal.asset.vulnerabilities.name, principal.asset.vulnerabilities.description)),
  if(additional.fields["ScanReference"] != "" and metadata.description != "",
    strings.concat(additional.fields["ScanReference"], " : ", metadata.description),
    strings.coalesce(additional.fields["ScanReference"], metadata.description)),
  if(extensions.vulns.vulnerabilities.vendor_vulnerability_id != "" and extensions.vulns.vulnerabilities.description != "",
    strings.concat(extensions.vulns.vulnerabilities.vendor_vulnerability_id, " : ", extensions.vulns.vulnerabilities.description),
    strings.coalesce(extensions.vulns.vulnerabilities.vendor_vulnerability_id, extensions.vulns.vulnerabilities.description)
  )
)
($Vulnerability != " : " and $Vulnerability != "")
$Log_Type = metadata.log_type

match:
  $Vulnerability, $Log_Type, $Severity

outcome:
  $Age_Max = max(cast.as_int((metadata.event_timestamp.seconds - if(timestamp.as_unix_seconds(additional.fields["first_found"]) > 0,
                  timestamp.as_unix_seconds(additional.fields["first_found"]), if(extensions.vulns.vulnerabilities.first_found.seconds > 0,
                  extensions.vulns.vulnerabilities.first_found.seconds, metadata.event_timestamp.seconds))) / 86400))
  $Count = count(strings.coalesce(extensions.vulns.vulnerabilities.name, extensions.vulns.vulnerabilities.description, extensions.vulns.vulnerabilities.vendor_vulnerability_id,
                                          principal.asset.vulnerabilities.name, target.asset.vulnerabilities.name, additional.fields["ScanReference"]))

order:
  $Age_Max desc
10 Akun Layanan Teratas berdasarkan Login
metadata.event_type = "USER_LOGIN"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid, target.user.user_display_name, target.user.email_addresses) =  /(?i)service.*(?:account|^principal$)/  nocase

$Service_Account = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Service_Account != ""
$Action = security_result.action

match:
  $Service_Account, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Detail File Malware
(metadata.product_event_type = /malware/ nocase or security_result.summary = /malware/ nocase or security_result.category_details = /malware/ nocase or metadata.description = /malware/ nocase or security_result.threat_name = /malware/ nocase or security_result.rule_name = /malware/ nocase or security_result.category = "SOFTWARE_MALICIOUS")

$Source_User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses)
$File_Name = strings.coalesce(target.file.full_path, about.file.full_path)
$File_Name != ""
$File_Type = strings.coalesce(target.file.mime_type, about.file.mime_type)
$Severity = security_result.severity
$Action = security_result.action

match :
  $File_Name, $File_Type, $Source_User, $Severity, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Aktivitas Berbahaya Berbasis Jaringan
(metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP")
(security_result.category = "NETWORK_DENIAL_OF_SERVICE" or security_result.category = "NETWORK_MALICIOUS" or security_result.category = "NETWORK_SUSPICIOUS" or
security_result.category = "SOFTWARE_MALICIOUS" or security_result.category = "SOFTWARE_SUSPICIOUS" or security_result.category = "NETWORK_RECON")

$Log_Type = metadata.log_type
$Category = security_result.category
$Summary = strings.coalesce(security_result.description, security_result.summary, metadata.description, security_result.rule_name, metadata.product_event_type)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, principal.mac, principal.asset.mac, target.hostname, target.asset.hostname, target.mac, target.asset.mac,
target.resource.product_object_id, principal.group.product_object_id, principal.ip, principal.asset.ip, target.ip, target.asset.ip)
$Action = security_result.action

match:
  $Summary, $Category, $Hostname, $Log_Type, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Aktivitas & Modifikasi Akun Istimewa
metadata.event_type = "GROUP_CREATION" or metadata.event_type = "GROUP_MODIFICATION" or metadata.event_type = "GROUP_DELETION" or metadata.event_type = "USER_LOGIN" or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid,target.user.user_display_name,target.user.email_addresses)
($User = /admin|root|svc|adm|privilege/ nocase or principal.user.attribute.roles.type = "SERVICE_ACCOUNT" or principal.user.attribute.roles.type = "ADMINISTRATOR" or principal.user.account_type = "DOMAIN_ACCOUNT_TYPE" or principal.user.account_type = "SERVICE_ACCOUNT_TYPE")
$Event_Type = metadata.event_type
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip, principal.hostname, principal.asset.hostname, principal.mac)
$Target_Resource = strings.coalesce(target.resource.name, target.file.full_path, target.resource.product_object_id, target.group.product_object_id, target.user.group_identifiers, target.group.group_display_name)
$Target_Resourcetype = target.resource.resource_type
$Action = security_result.action
$Security_Event_Type = metadata.product_event_type
$Summary = strings.coalesce(additional.fields["Message"], security_result.summary, security_result.description, metadata.description)

match:
   $Event_Type, $User,$Source_IP, $Target_Resource, $Action, $Security_Event_Type, $Summary

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %H:%M:%S")

order:
   $Count desc

Peristiwa Login dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "USER_LOGIN"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Distribusi Peristiwa Keamanan Data
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|METABASE|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
 
Peristiwa Penghapusan dan Penghapusan Permanen Data
(metadata.event_type = "FILE_DELETION"
or metadata.event_type = "RESOURCE_DELETION"
or metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE"
or metadata.event_type = "REGISTRY_DELETION"
or metadata.event_type = "SETTING_DELETION"
or metadata.event_type = "USER_RESOURCE_DELETION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "SERVICE_DELETION"
or metadata.event_type = "SCHEDULED_TASK_DELETION"
or strings.coalesce(metadata.product_event_type, security_result.summary, security_result.description, security_result.action_details) = /delet(?:e|ed|ion|ing)|purge/ nocase)
security_result.action = "ALLOW"

$Description = strings.coalesce(security_result.summary, security_result.description, metadata.description, security_result.action_details)
$Product_Event_Type = metadata.product_event_type
$Event_Type = metadata.event_type
$Log_Type = metadata.log_type
$Target_Resource = strings.coalesce(target.resource.name, target.file.full_path, target.resource.product_object_id, target.group.product_object_id, target.user.group_identifiers)
$User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses, target.user.userid,target.user.user_display_name,target.user.email_addresses)

match:
  $User, $Log_Type, $Description, $Product_Event_Type, $Event_Type, $Target_Resource

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Date desc, $Count desc
Pemindaian Kerentanan dari Waktu ke Waktu
metadata.log_type = /ARMIS_VULNERABILITIES|FINGERPRINT_JS|NUCLEUS_VULNERABILITY|QUALYS_ASSET_CONTEXT|QUALYS_SCAN|QUALYS_VIRTUAL_SCANNER|QUALYS_VM|RAPID7_INSIGHT|RAPID7_NEXPOSE|SNYK_SDLC|SPUR_FEEDS|STACKHAWK|SUBLIMESECURITY|SYMANTEC_SA|TENABLE_IO|TENABLE_OT|TENABLE_SC|UPGUARD|URLSCAN_IO/ nocase

(metadata.event_type = "SCAN_VULN_HOST" or additional.fields["Type"] = "Scan" or security_result.detection_fields.key = /scan/ nocase or security_result.detection_fields.value = /scan/ nocase)

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Phishing dari Waktu ke Waktu
metadata.log_type = /MAIL|ABNORMAL_SECURITY|AREA1|COFENSE_TRIAGE|FIREEYE|FORCEPOINT|FORTINET|KNOWBE4_PHISHER|MICROSOFT_GRAPH_ALERT|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|PHISHLABS|PROOFPOINT|SYMANTEC_VIP|VOLTAGE|WORKSPACE_ALERTS/ nocase
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Severity = security_result.severity

match:
  $Date, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Pencadangan Terbaru
(metadata.log_type = /COHESITY|DRUVA_BACKUP|VEEAM|VERITAS_NETBACKUP/ nocase or metadata.log_type = "RUBRIK")

$Description = strings.coalesce(metadata.description, security_result.description, security_result.summary)

$Log_Type = metadata.log_type
$Event_Type = metadata.event_type
$Security_Event_Type = metadata.product_event_type
$Action = security_result.action

match:
  $Description, $Security_Event_Type, $Event_Type, $Action, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")

order:
  $Count desc
10 Ancaman Email Teratas menurut Tingkat Keparahan
metadata.log_type = /MAIL|ABNORMAL_SECURITY|AREA1|COFENSE_TRIAGE|FIREEYE|FORCEPOINT|FORTINET|KNOWBE4_PHISHER|MICROSOFT_GRAPH_ALERT|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|PHISHLABS|PROOFPOINT|SYMANTEC_VIP|VOLTAGE|WORKSPACE_ALERTS/ nocase
security_result.category = "MAIL_SPAM"
or security_result.category = "MAIL_SPOOFING"
or security_result.category = "SOFTWARE_MALICIOUS"
or (security_result.category = "MAIL_PHISHING" and security_result.threat_name!= "NOT_PHISHING")
or strings.coalesce(security_result.threat_name, security_result.category_details) = /Phish|Mail/ nocase

$Severity = security_result.severity
$Threat_Name = strings.coalesce(security_result.threat_name, security_result.category_details)
$Threat_Name != ""

match:
  $Threat_Name, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pencadangan dari Waktu ke Waktu
(metadata.log_type = /COHESITY|DRUVA_BACKUP|VEEAM|VERITAS_NETBACKUP/ nocase or metadata.log_type = "RUBRIK")

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Total Perangkat dari Waktu ke Waktu

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count_distinct(strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname))

order:
  $Date asc

 
10 Eksekusi Aplikasi yang Diblokir Teratas
(metadata.product_event_type = /(execution|application) block/ nocase or security_result.summary = /(execution|application) block/ or metadata.description = /(execution|application) block/ nocase or security_result.threat_name = /application control/ nocase)
(security_result.action = "BLOCK" or security_result.action_details = /block/ nocase or (target.resource.attribute.labels.key = "categoryBehavior" and target.resource.attribute.labels.value = /blocked/ nocase))

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"], principal.application, target.application)
$Description = strings.coalesce(target.resource.attribute.labels["categoryTupleDescription"], security_result.summary, metadata.product_event_type, security_result.description, metadata.description, security_result.action_details)

match:
  $Application, $Description, metadata.log_type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Upaya MFA yang Diblokir untuk Akun Istimewa
(re.regex(metadata.product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex(additional.fields["AuthenticationRequirement"], `multiFactorAuthentication`) nocase or re.regex(security_result.detection_fields.value, `MFA`) nocase or re.regex(metadata.product_event_type, `mfa(?:\S)?auth|auth(?:.*)?mfa`) nocase)
security_result.action = "BLOCK"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name,target.user.email_addresses)
$User = /admin|root|administrator|security|support|default/ nocase //It will be updated as per the client's environment.
$Reason = strings.coalesce(security_result.summary, metadata.product_event_type)
$Location = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = metadata.log_type
$Severity = security_result.severity

match:
  $Reason, $User, $Source_IP, $Location, $Severity, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Ringkasan Cloud Key Management

Dasbor ini menawarkan tampilan mendetail tentang aktivitas pengelolaan kunci dalam infrastruktur cloud organisasi Anda. Dasbor memantau status Kunci, Sertifikat, dan Secret di seluruh siklus prosesnya-dibuat, dihapus, diaktifkan, dirotasi, dan dinonaktifkan-sehingga memungkinkan deteksi anomali atau aktivitas yang tidak sah.

Nama diagram Contoh kueri
Objek yang Dinonaktifkan dari Waktu ke Waktu
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Disable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Disable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase  and
target.resource.attribute.labels.value = /DISABLED/ nocase and security_result.action = "ALLOW"))

$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
   $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Total Jumlah Peristiwa menurut Jenis Log
(metadata.log_type = /AZURE_KEYVAULT_AUDIT|GCP_CLOUDAUDIT/ nocase or target.application = "kms.amazonaws.com")

$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Pengguna Teratas yang Membuat Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Create/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Create/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
metadata.product_event_type != /version/ nocase  and security_result.action = "ALLOW"))

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
Objek yang Dihapus dari Waktu ke Waktu
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Delete/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Delete|Destroy/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase
and security_result.action = "ALLOW"))

$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
   $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Objek yang Dibuat dari Waktu ke Waktu
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and ((additional.fields["resultType"] = /Allow|Success/ nocase) or (security_result.action = "ALLOW"))) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Create/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Create/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
metadata.product_event_type != /version/ nocase  and security_result.action = "ALLOW"))

$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 IP Sumber Teratas yang Mengaktifkan Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Enable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Enable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
target.resource.attribute.labels.value = /ENABLED/ nocase and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 Pengguna Teratas yang Memutar Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Rotate|KeyRotation/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /CreateCryptoKeyVersion|updateCryptoKeyPrimaryVersion|Rotate/ nocase and  metadata.product_event_type = /key|secret|certificate/ nocase  and security_result.action = "ALLOW"))

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
Objek yang Diputar Seiring Waktu
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Rotate|KeyRotation/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /CreateCryptoKeyVersion|updateCryptoKeyPrimaryVersion|Rotate/ nocase and  metadata.product_event_type = /key|secret|certificate/ nocase  and security_result.action = "ALLOW"))

$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 IP Sumber Teratas yang Memutar Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Rotate|KeyRotation/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /CreateCryptoKeyVersion|updateCryptoKeyPrimaryVersion|Rotate/ nocase and  metadata.product_event_type = /key|secret|certificate/ nocase  and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Menghapus objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Delete/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Delete|Destroy/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase
and security_result.action = "ALLOW"))

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 Objek Teratas yang Diputar
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Rotate|KeyRotation/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /CreateCryptoKeyVersion|updateCryptoKeyPrimaryVersion|Rotate/ nocase and  metadata.product_event_type = /key|secret|certificate/ nocase  and security_result.action = "ALLOW"))

$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Object_ID, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 Objek Teratas yang Dinonaktifkan
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Disable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Disable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase  and
target.resource.attribute.labels.value = /DISABLED/ nocase and security_result.action = "ALLOW"))

$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
   $Object_ID, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 Pengguna yang Paling Banyak Diblokir
((metadata.log_type = /AZURE_KEYVAULT_AUDIT|GCP_CLOUDAUDIT/ nocase and (additional.fields["resultType"] = /Fail/ nocase or security_result.action = "BLOCK")) or
(target.application = "kms.amazonaws.com" and security_result.action = "BLOCK"))

$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)

match:
  $User, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengaktifkan Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Enable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Enable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
target.resource.attribute.labels.value = /ENABLED/ nocase and security_result.action = "ALLOW"))

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
Objek yang Baru Dibuat (24 Jam Terakhir)
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Create/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Create/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
metadata.product_event_type != /version/ nocase  and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Location = principal.location.country_or_region
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
   $Date , $Log_Type, $Object_ID, $Security_Event_Type, $User, $Source_IP, $Location

order:
  $Date desc
    
10 Objek Teratas yang Diaktifkan
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Enable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Enable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
target.resource.attribute.labels.value = /ENABLED/ nocase and security_result.action = "ALLOW"))

$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Object_ID, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 Agen Pengguna Teratas
(metadata.log_type = /AZURE_KEYVAULT_AUDIT|GCP_CLOUDAUDIT/ nocase or target.application = "kms.amazonaws.com")

$User_Agent = network.http.user_agent
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User_Agent, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas yang Membuat Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Create/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Create/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
metadata.product_event_type != /version/ nocase  and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Lokasi Objek Teratas
(metadata.log_type = /AZURE_KEYVAULT_AUDIT|GCP_CLOUDAUDIT/ nocase or target.application = "kms.amazonaws.com")

$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Location = target.location.name

match:
  $Location, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
Objek yang Diaktifkan dari Waktu ke Waktu
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Enable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Enable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
target.resource.attribute.labels.value = /ENABLED/ nocase and security_result.action = "ALLOW"))

$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 IP Sumber yang Diblokir Teratas
((metadata.log_type = /AZURE_KEYVAULT_AUDIT|GCP_CLOUDAUDIT/ nocase and (additional.fields["resultType"] = /Fail/ nocase or security_result.action = "BLOCK")) or
(target.application = "kms.amazonaws.com" and security_result.action = "BLOCK"))

$Event_Type = metadata.event_type
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Source_IP, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
Objek yang Dibuat oleh Geolokasi
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Create/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Create/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase and
metadata.product_event_type != /version/ nocase  and security_result.action = "ALLOW"))

$Country = principal.ip_geo_artifact.location.country_or_region
$Country != ""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

order:
  $Count desc
10 Pengguna Teratas yang Menonaktifkan Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Disable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Disable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase  and
target.resource.attribute.labels.value = /DISABLED/ nocase and security_result.action = "ALLOW"))

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
    
10 IP Sumber Teratas yang Menonaktifkan Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Disable/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /UpdateCryptoKeyVersion|Disable/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase  and
target.resource.attribute.labels.value = /DISABLED/ nocase and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Objek yang Baru Dihapus(24 Jam Terakhir)
((metadata.log_type = "AZURE_KEYVAULT_AUDIT" and additional.fields["resultType"] = /Allow|Success/ nocase) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW"))
metadata.product_event_type = /Delete/ nocase

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, principal.user.group_identifiers)
$Object_ID = strings.coalesce(target.resource.product_object_id, principal.user.product_object_id, principal.resource.product_object_id)
$Location = principal.location.country_or_region
$Log_Type = strings.coalesce(metadata.log_type, target.application)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
   $Date, $Log_Type, $Object_ID, $Security_Event_Type, $User, $Source_IP, $Location

order:
  $Date desc

limit:
    10
    
10 IP Sumber Teratas Menghapus Objek
((((metadata.log_type = /AZURE_KEYVAULT_AUDIT/ nocase and (additional.fields["resultType"] = /Allow|Success/ nocase or security_result.action = "ALLOW")) or
(target.application = "kms.amazonaws.com" and security_result.action = "ALLOW")) and metadata.product_event_type = /Delete/ nocase) or
(metadata.log_type = /GCP_CLOUDAUDIT/ nocase and metadata.product_event_type = /Delete|Destroy/ nocase and metadata.product_event_type = /key|secret|certificate/ nocase
and security_result.action = "ALLOW"))

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Ringkasan Postur Keamanan Cloud

Dasbor ini memberikan insight postur Keamanan Cloud dengan melacak metrik utama di Google Cloud Google Cloud, AWS, dan Azure.

Nama diagram Contoh kueri
10 Aturan Pemicu Teratas
$log_type = metadata.log_type
$log_type = /AWS|AZURE/
$rule_name = security_result.rule_name
$rule_name != ""
match:
$rule_name
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10

Ringkasan Layanan Cloud Storage

Dasbor ini memberikan insight berharga tentang aktivitas penyimpanan cloud seperti resource yang dibuat, dihapus, diakses, diperbarui, dan izin yang diubah. Dasbor ini mencakup visualisasi tren peristiwa dan pemberitahuan dari waktu ke waktu serta menyoroti pengguna, alamat IP, agen pengguna, dan lokasi resource teratas. Informasi ini membantu mengidentifikasi pola yang tidak biasa, memantau pemberitahuan, dan menjaga integritas data sekaligus melindungi lingkungan cloud.

Nama diagram Contoh kueri
10 IP Sumber Teratas yang Mengakses Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_READ"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/read/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Resource yang Diakses berdasarkan Geolokasi
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_READ"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/read/ nocase)
)
security_result.action = "ALLOW"

$Country = principal.location.country_or_region
$Country != ""
$Latitude = principal.location.region_coordinates.latitude
$Longitude = principal.location.region_coordinates.longitude

match:
  $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Agen Pengguna Teratas
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.product_event_type = /storage|bucket/ nocase
 and (metadata.event_type = "RESOURCE_CREATION"
 or metadata.event_type = "RESOURCE_DELETION"
 or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
 or metadata.event_type = "RESOURCE_READ"
 or metadata.event_type = "RESOURCE_WRITTEN"))
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|delete|read)/ nocase)
network.http.user_agent != ""

$Log_Type = metadata.log_type
$User_Agent = network.http.user_agent

match:
  $Log_Type, $User_Agent

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas yang Memperbarui Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_WRITTEN"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|.*\/write)?/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Resource yang Paling Sering Diakses
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_READ"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|.*\/write)?/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Resource_Name = target.resource.name

match:
  $Log_Type, $Resource_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Sumber Daya yang Dihapus dari Waktu ke Waktu
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_DELETION"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/delete/ nocase)
)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 Pengguna yang Paling Banyak Diblokir
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.product_event_type = /storage|bucket/ nocase
 and (metadata.event_type = "RESOURCE_CREATION"
 or metadata.event_type = "RESOURCE_DELETION"
 or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
 or metadata.event_type = "RESOURCE_READ"
 or metadata.event_type = "RESOURCE_WRITTEN"))
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|delete|read)/ nocase)
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$User = principal.user.userid

match:
  $Event_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Resource yang Baru Dibuat (24 Jam Terakhir)
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_CREATION"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/write/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip
$User = principal.user.userid
$Resource_Name = target.resource.name
$Location = principal.location.country_or_region
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $IP_Address, $User, $Location, $Resource_Name

order:
  $Date desc
Resource yang Diakses dari Waktu ke Waktu
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_READ"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/read/ nocase)
)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 IP Sumber Teratas yang Mengubah Izin Resource
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.authorization\/(?:policyassignments|roledefinitions)?\/write/ nocase
and target.resource.resource_type = "STORAGE_BUCKET")
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Sumber Daya yang Baru-Baru Ini Dihapus (24 Jam Terakhir)
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_DELETION"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/delete/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip
$User = principal.user.userid
$Resource_Name = target.resource.name
$Location = principal.location.country_or_region
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $IP_Address, $User, $Location, $Resource_Name

order:
  $Date desc
10 IP Sumber yang Diblokir Teratas
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.product_event_type = /storage|bucket/ nocase
 and (metadata.event_type = "RESOURCE_CREATION"
 or metadata.event_type = "RESOURCE_DELETION"
 or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
 or metadata.event_type = "RESOURCE_READ"
 or metadata.event_type = "RESOURCE_WRITTEN"))
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|delete|read)/ nocase)
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$IP_Address = principal.ip

match:
  $Event_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Acara dari Waktu ke Waktu
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.product_event_type = /storage|bucket/ nocase
 and (metadata.event_type = "RESOURCE_CREATION"
 or metadata.event_type = "RESOURCE_DELETION"
 or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
 or metadata.event_type = "RESOURCE_READ"
 or metadata.event_type = "RESOURCE_WRITTEN"))
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|delete|read)/ nocase)

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)
10 Lokasi Sumber Daya Teratas
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.product_event_type = /storage|bucket/ nocase
 and (metadata.event_type = "RESOURCE_CREATION"
 or metadata.event_type = "RESOURCE_DELETION"
 or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
 or metadata.event_type = "RESOURCE_READ"
 or metadata.event_type = "RESOURCE_WRITTEN"))
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage[\/\.]storageaccounts[\/\.](?:write|delete|read)/ nocase)
target.location.name != ""
security_result.action = "ALLOW"

$Location = target.location.name
$Log_Type = metadata.log_type

match:
  $Location, $Log_Type

outcome:
  $Count = count_distinct(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas yang Menghapus Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_DELETION"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/delete/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Izin Resource Berubah dari Waktu ke Waktu
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.authorization\/(?:policyassignments|roledefinitions)?\/write/ nocase
and target.resource.resource_type = "STORAGE_BUCKET")
)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 IP Sumber Teratas yang Membuat Resource
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_CREATION"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/write/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengakses Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_READ"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/read/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Sumber Daya Teratas dengan Izin yang Diubah
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.authorization\/(?:policyassignments|roledefinitions)?\/write/ nocase
and target.resource.resource_type = "STORAGE_BUCKET")
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Resource_Name = target.resource.name

match:
  $Log_Type, $Resource_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Memperbarui Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_WRITTEN"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|.*\/write)?/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Izin Resource
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.authorization\/(?:policyassignments|roledefinitions)?\/write/ nocase
and target.resource.resource_type = "STORAGE_BUCKET")
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Referensi yang Dibuat dari Waktu ke Waktu
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_CREATION"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/write/ nocase)
)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 Resource Teratas yang Diperbarui
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_WRITTEN"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|.*\/write)?/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Resource_Name = target.resource.name

match:
  $Log_Type, $Resource_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Menghapus Resource
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_DELETION"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/delete/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Membuat Aset
(
(metadata.log_type = /AWS_CLOUDTRAIL|GCP_CLOUDAUDIT/ nocase
and metadata.event_type = "RESOURCE_CREATION"
and metadata.product_event_type = /storage|bucket/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/write/ nocase)
)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Resource yang Diperbarui dari Waktu ke Waktu
(
(metadata.log_type = /(AWS_CLOUDTRAIL|GCP_CLOUDAUDIT)/ nocase
and metadata.event_type = "RESOURCE_WRITTEN"
and metadata.product_event_type = /(storage|bucket)/ nocase)
or
(metadata.log_type = /AZURE/ nocase
and metadata.product_event_type = /microsoft\.storage\/storageaccounts\/(?:write|.*\/write)?/ nocase)
)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
Bucket yang Dibagikan kepada Publik
(metadata.log_type = "AZURE_ACTIVITY"
and metadata.product_event_type = "Microsoft.Storage/storageAccounts/write" nocase
and security_result.detection_fields["allowBlobPublicAccess"] = "true")
or
(metadata.log_type = "GCP_CLOUDAUDIT"
and metadata.product_event_type = "storage.setIamPermissions"
and target.application = "storage.googleapis.com"
and security_result.action = "ALLOW"
and target.resource.attribute.labels["ser_binding_deltas_action"] = "ADD"
and target.resource.attribute.labels["ser_binding_deltas_role"] = /roles\/storage.*/
and target.resource.attribute.labels["ser_binding_deltas_member"] = /allUsers|allAuthenticatedUsers/
and target.resource.resource_type = "STORAGE_BUCKET"
)
or
(metadata.log_type = "AWS_CLOUDTRAIL"
and metadata.ingestion_labels["EventSource"] = "s3.amazonaws.com" nocase
and metadata.product_event_type = /PutBucketPublicAccessBlock/ nocase
and (target.resource.attribute.labels["BlockPublicAcls"] = "false"
or target.resource.attribute.labels["BlockPublicPolicy"] = "false"
or target.resource.attribute.labels["IgnorePublicAcls"] = "false"
or target.resource.attribute.labels["RestrictPublicBuckets"] = "false")
)

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Type = metadata.log_type
$User = principal.user.userid
$Resource_Name = target.resource.name

match:
  $Date, $Log_Type, $User, $Resource_Name

Ringkasan DDOS

Dasbor ini memberikan analisis komprehensif tentang aktivitas Distributed Denial-of-Service (DDoS), yang menawarkan insight tentang tren, pola, dan perilaku serangan. Solusi ini membantu mengidentifikasi vektor ancaman dan area berisiko tinggi dalam jaringan, sehingga memungkinkan tim keamanan mendeteksi, merespons, dan memitigasi serangan DDoS secara efektif.

Nama diagram Contoh kueri
10 Pemberitahuan Vendor Teratas
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Rule_Name = security_result.rule_name
$Rule_Name != ""
$Log_Type = metadata.log_type
$Action = security_result.action

match:
  $Rule_Name, $Log_Type, $Action

outcome:

  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas menurut Tindakan
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Source_Ip = strings.coalesce(principal.ip, principal.asset.ip)
$Action = security_result.action

match:
  $Source_Ip, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa menurut Jenis Peristiwa
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Pemberitahuan Vendor dari Waktu ke Waktu menurut Jenis Log
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))
security_result.rule_name != ""

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:

  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa dari Waktu ke Waktu menurut Jenis Log
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Acara menurut Deskripsi
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Description = strings.coalesce(metadata.description,security_result.summary,security_result.description)
$Log_Type = metadata.log_type
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Destination_IP = strings.coalesce(target.ip, target.asset.ip)
$Action = security_result.action
$Destination_Hostname = strings.coalesce(target.hostname, target.asset.hostname)
$File = principal.process.file.full_path

match:
   $Description, $Source_IP, $Destination_IP, $Destination_Hostname, $Action, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Ringkasan Geolocation Sumber
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase))

$Country = principal.ip_geo_artifact.location.country_or_region
$Country !=""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_longitude)

order:
  $Count desc

Pemantauan DNS

Dasbor ini memberikan ringkasan mendetail tentang aktivitas DNS dan kondisi jaringan, yang menampilkan insight tentang peristiwa DNS, tren kueri, dan distribusi kueri yang diizinkan dan diblokir. Layanan ini memungkinkan pemantauan, deteksi ancaman, dan pemecahan masalah yang efisien melalui visualisasi anomali, lokasi, dan kegagalan DNS.

Nama diagram Contoh kueri
10 Kueri DNS yang Diizinkan Teratas
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$DNS_Questions_Name = network.dns.questions.name

match:
  $DNS_Questions_Name, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Kategori yang Diizinkan DNS Teratas
metadata.event_type = "NETWORK_DNS"
security_result.action = "ALLOW"
security_result.category_details != ""

$Log_Type = metadata.log_type
$Category = security_result.category_details

match:
  $Category, $Log_Type

outcome:
  $Count = count($Category)

order:
  $Count desc

limit:
    10
Total Peristiwa DNS
metadata.event_type = "NETWORK_DNS"

outcome:
  $Count = count(metadata.id)
Melaporkan Host
metadata.event_type = "NETWORK_DNS"

$Hostname = principal.hostname

match:
  $Hostname
10 Pertanyaan Teratas tentang DNS
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Questions_Name = $event.network.dns.questions.name

match:
  $Questions_Name
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Total Peristiwa DNS
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

outcome:
  $Count = count($event.metadata.id)
Total Peristiwa DNS menurut Jenis Log
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type

match:
  $Log_Type, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
10 Kategori yang Paling Sering Diblokir DNS
metadata.event_type = "NETWORK_DNS"
security_result.action = "BLOCK"
security_result.category_details != ""

$Log_Type = metadata.log_type
$Category = security_result.category_details

match:
  $Category, $Log_Type

outcome:
  $Count = count($Category)

order:
  $Count desc

limit:
    10
Respons DNS yang Berhasil dari Waktu ke Waktu
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"
$event.network.dns.response = true
$event.network.application_protocol = "DNS"

$Answered = $event.network.dns.response
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Answered
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc 
Aktivitas DNS Umum
metadata.event_type = "NETWORK_DNS"

$Log_Type = metadata.log_type
$Source_IP = principal.ip
$Description = strings.coalesce(metadata.description, security_result.summary)
$DNS_Questions_Name = network.dns.questions.name

match:
  $Source_IP, $Log_Type, $Description, $DNS_Questions_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Kueri DNS Teratas yang Diblokir
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""
security_result.action = "BLOCK"

$Log_Type = metadata.log_type
$DNS_Questions_Name = network.dns.questions.name

match:
  $DNS_Questions_Name, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Kueri DNS menurut Tindakan: Izinkan vs. Blokir
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""
security_result.action = "ALLOW"
or security_result.action = "BLOCK"

$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc 
Peristiwa DNS menurut Jenis Log dari Waktu ke Waktu
metadata.event_type = "NETWORK_DNS"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
Pembagian Jenis Data DNS
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$DNS_Record_Type = $event.additional.fields["dns_record_type"]
$DNS_Record_Type != ""
$Return_Message = $event.additional.fields["dns_return_message"]
$Date = timestamp.get_timestamp($event.metadata.event_timestamp.seconds)
$Description = $event.metadata.description

match:
  $Date, $Log_Type, $DNS_Record_Type, $Description, $Return_Message
order:
  $Date desc
limit:
    50
Respons DNS Gagal dari Waktu ke Waktu
metadata.event_type = "NETWORK_DNS"
network.dns.response_code = 3
or network.dns.response_code = 5

$Denied = strings.concat(network.dns.response_code, " ")
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Denied, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 IP Sumber Teratas
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$Source_IP = $event.principal.ip
$Source_IP != ""

match:
  $Source_IP, $Event_Type, $Log_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Jenis Data DNS dari Waktu ke Waktu
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Record_Types = $event.additional.fields["dns_record_type"]
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Record_Types, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Total Peristiwa DNS menurut Jenis Log
metadata.event_type = "NETWORK_DNS"

$Log_Type = metadata.log_type

match:
  $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Total Volume Log Peristiwa DNS dari Waktu ke Waktu
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc 
Respons DNS Gagal dari Waktu ke Waktu
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.network.dns.response_code = 3
or $event.network.dns.response_code = 5
$event.metadata.event_type = "NETWORK_DNS"

$Denied = $event.network.dns.response_code
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Denied, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Pembagian Jenis Data DNS
metadata.event_type = "NETWORK_DNS"

$Log_Type = metadata.log_type
$Event_Type = metadata.event_type
$Source_IP = principal.ip
$Hostname = principal.hostname
$DNS_Record_Type = strings.coalesce(additional.fields["dns_record_type"], extracted.fields["query_type"], extracted.fields["qtype_name"])
$Return_Message = additional.fields["dns_return_message"]
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$Description = strings.coalesce(metadata.description, security_result.summary)

match:
  $Date, $Log_Type, $Source_IP, $Hostname, $DNS_Record_Type, $Description, $Return_Message

order:
  $Date desc
10 IP Sumber Teratas
metadata.event_type = "NETWORK_DNS"

$Log_Type = metadata.log_type
$Source_IP = principal.ip

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Kueri DNS menurut Jenis Data
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""

$Record_Types = strings.coalesce(additional.fields["dns_record_type"], extracted.fields["query_type"], extracted.fields["qtype_name"])
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Record_Types

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Total Host Pelaporan
metadata.event_type = "NETWORK_DNS"

outcome:
  $Count = count_distinct(principal.hostname)
Kueri DNS dari Waktu ke Waktu
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(network.dns.questions.name)

order:
  $Date desc
Respons DNS yang Berhasil dari Waktu ke Waktu
metadata.event_type = "NETWORK_DNS"
network.dns.response = true

$Answered = network.dns.response
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Answered

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
Aktivitas DNS Umum
$event.metadata.log_type = /EXTRAHOP_DNS|UMBRELLA_DNS/ nocase
$event.metadata.event_type = "NETWORK_DNS"

$Log_Type = $event.metadata.log_type
$Source_IP = $event.principal.ip
$Description = $event.metadata.description
$DQ_Name = $event.network.dns.questions.name

match:
  $Source_IP, $Description, $DQ_Name
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50
10 Kueri DNS Teratas menurut Lokasi
metadata.event_type = "NETWORK_DNS"
network.dns.questions.name != ""

$Questions_Name = network.dns.questions.name
$Country = principal.ip_geo_artifact.location.country_or_region
$Latitude = principal.ip_geo_artifact.location.region_latitude
$Longitude = principal.ip_geo_artifact.location.region_longitude

match:
  $Questions_Name, $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

limit:
    10

Penyerapan dan Kesehatan Data

Dasbor ini memberikan insight penting tentang alur data, menampilkan peristiwa yang diserap dan jumlah error untuk memberikan visibilitas yang jelas terhadap potensi masalah. Dasbor ini mencakup visualisasi untuk distribusi jenis log dan status peristiwa yang di-ingest, beserta aktivitas penyerapan terbaru dan informasi log harian. Dengan melacak throughput penyerapan selama berbagai jangka waktu, dasbor ini membantu mengidentifikasi tren dan masalah, sehingga meningkatkan kemampuan organisasi Anda untuk mengelola penyerapan data dan menjaga kelancaran operasi.

Nama diagram Contoh kueri
Logging Agen Bindplane - Log menurut Tingkat Keparahan dari Waktu ke Waktu
metadata.log_type = "BINDPLANE_AGENT"
metadata.ingestion_labels.key = "ingestion_source"
metadata.ingestion_labels.value = $agent
metadata.description = $message
security_result.severity = $severity
timestamp.get_timestamp(metadata.event_timestamp.seconds) = $timestamp
match:
  $severity, $timestamp
outcome:
  $total = count(metadata.id)
order :
  $severity
Jumlah Hari Sejak Host Melaporkan Acara (7 Hari Terakhir)
$host = principal.hostname
$event_time = metadata.event_timestamp.seconds
match:
  $host
outcome:
  $last_seen_timestamp = timestamp.get_timestamp(max($event_time))
  $days_since_last_seen = math.round((timestamp.current_seconds() - max($event_time)) / 86400, 0)
order:
  $days_since_last_seen desc
Logging Agen BindPlane - Pesan menurut Jumlah
metadata.log_type = "BINDPLANE_AGENT"
metadata.ingestion_labels.key = "ingestion_source"
metadata.ingestion_labels.value = $agent
metadata.description = $message
security_result.severity = $severity
match:
  $severity, $message
outcome:
  $total = count(metadata.id)
  $first_seen = timestamp.get_timestamp(min(metadata.event_timestamp.seconds))
  $last_seen = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))

Pencegahan Kebocoran Data (DLP)

Dasbor ini memberikan metrik utama terkait peristiwa DLP.

Nama diagram Contoh kueri
10 Pengguna Teratas
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$user= strings.coalesce(principal.user.user_display_name,principal.user.userid)
$user != ""
match:
$user
outcome:
$user_count = count(metadata.id)
order:
$user_count desc
limit: 10
Upaya Akses Data Sensitif
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$event_type = metadata.event_type
$security_event_type = metadata.product_event_type
$security_event_type = /Sensitive/
$user = strings.coalesce(principal.user.user_display_name,principal.user.userid)
$action = security_result.action_details
$hostname = principal.hostname
$src_ip = principal.ip
$file_path = target.file.full_path

match:
  $user,$action,$src_ip,$hostname,$file_path
outcome:
   $event_count = count(metadata.id)

order:
$event_count desc
Tren Peristiwa DLP dari Waktu ke Waktu
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$log_type = metadata.log_type
$log_type = /DLP/ nocase
match:
$date
outcome:
$event_count = count(metadata.id)
Peristiwa Menurut Tindakan
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$action = security_result.action_details
$action != ""
match:
$action
outcome:
$event_count = count(metadata.id)
order:
$action asc
Pelanggaran DLP menurut Tingkat Keparahan
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$log_type=metadata.log_type
$log_type = /DLP/ nocase
$severity =security_result.severity
$security_event_type=metadata.product_event_type
$security_event_type = /Violation/ nocase
match:
  $severity
outcome:
   $count = count(metadata.id)
order:
$severity desc
10 Jenis Peristiwa Pelanggaran Kebijakan DLP Teratas
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$event_type = metadata.product_event_type
$user = principal.user.user_display_name
$reason = strings.coalesce(security_result.summary,metadata.description,metadata.product_event_type)
$reason = /violation/ nocase
match:
$event_type
outcome:
$event_count = count(metadata.id)
$Count_user = count_distinct($user)
order:
$event_count desc
limit:
10
Pelanggaran DLP dari Waktu ke Waktu
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$log_type=metadata.log_type
$log_type = /DLP/ nocase
$security_event_type=metadata.product_event_type
$security_event_type = /Violation/ nocase

match:
$date

outcome:
$count = count(metadata.id)

order:
$date  asc
10 Penyelenggara Teratas
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$hostname= strings.coalesce(principal.hostname, principal.asset.hostname)
$hostname != ""

match:
$hostname
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit: 10
10 Aturan DLP Teratas
$log_type = metadata.log_type
$log_type = /DLP/
$rule_name = security_result.rule_name
$rule_name != ""
match:
$rule_name
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit: 10
10 Pengguna Teratas berdasarkan Upaya Pemindahan Data yang Tidak Sah
$log_type = metadata.log_type
$log_type = /DLP/ nocase
$user = strings.coalesce(principal.user.user_display_name,principal.user.userid)
$user !=""
$reason = strings.coalesce(metadata.product_event_type,security_result.summary,metadata.description)
$reason = /exfiltration/ nocase
$action = security_result.action_details
match:
  $user
outcome:
   $Action = array_distinct($action)
   $Reason = array_distinct($reason)
   $event_count = count(metadata.id)
order:
 $event_count desc
 limit:
 10 
10 File Teratas
$log_type = metadata.log_type
$log_type = /DLP/
$file_name = strings.coalesce(target.file.full_path, additional.fields["fname"])
match:
$file_name
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit: 10

Pemantauan Keamanan Data

Dasbor ini memberikan tampilan komprehensif tentang peristiwa keamanan yang disediakan oleh alat keamanan data, yang berfokus pada metrik seperti tingkat keparahan peristiwa, tindakan yang diambil, dan aturan pemicu. Layanan ini melacak host, pengguna, dan pola geografis teratas untuk mengidentifikasi ancaman dan tren yang muncul.

Nama diagram Contoh kueri
Peristiwa menurut Tingkat Keparahan
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa dari Waktu ke Waktu menurut Jenis Log
$Log_Type = metadata.log_type
$Log_Type =  /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Acara menurut Tindakan
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peta Panas Geolocation Sumber
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Country = principal.ip_geo_artifact.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_longitude)

order:
  $Count desc
Distribusi Jenis Peristiwa
metadata.log_type =  /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Total Peristiwa
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/

outcome:
   $Count = count(metadata.id)
10 Peristiwa Teratas menurut Deskripsi
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Summary = strings.coalesce(metadata.description,security_result.description,security_result.summary)
$Summary != ""
match:
  $Summary

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Host Sumber Teratas
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Hostname= strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname!=""
match:
  $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Pengguna Sumber Teratas
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses)
$User != ""
match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Aturan Produk Keamanan Data Teratas yang Dipicu
metadata.log_type = /ARUBA_CENTRAL|CLOUDFLARE_WARP|DELL_CYBERSENSE|FORGEROCK_OPENIDM|IMPERVA_DRA|IMPERVA_SECURESPHERE|IBM_OPENPAGES|INTEL471_WATCHER_ALERTS|OKERA_DAP|OPENCANARY|RUBRIK_POLARIS|SENTRY|TINES|TINTRI|VARONIS/ nocase

$Rule_Name = security_result.rule_name
$Rule_Name !=""
match:
  $Rule_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Pemantauan Database

Dasbor ini memberikan visibilitas mendalam terhadap operasi, keamanan, performa, dan kondisi database dengan melacak aktivitas pengguna, pernyataan SQL yang dijalankan, tren login, dan tingkat keparahan peristiwa. Hal ini membantu Anda mengidentifikasi perilaku yang tidak biasa, memastikan efisiensi operasional, dan mengelola risiko secara proaktif di seluruh lingkungan database.

Nama diagram Contoh kueri
Acara menurut Tindakan
$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Objek menurut Tingkat Keparahan
$Object_id = strings.coalesce(target.resource.product_object_id, principal.resource.product_object_id)
$Object_id != ""
$Severity = security_result.severity
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Summary = strings.coalesce(target.process.command_line, security_result.action_details, security_result.description, extracted.fields["textPayload"], extracted.fields["cmd_line"])
$IP = strings.coalesce(principal.ip, principal.asset.ip, target.ip, target.asset.ip)
$Log_Type = metadata.log_type

match:
  $Object_id, $Summary, $User, $IP, $Severity, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Upaya Login yang Gagal dari Waktu ke Waktu
((metadata.event_type = "USER_LOGIN" and security_result.action = "BLOCK") or (metadata.event_type = "GENERIC_EVENT" and (extracted.fields["token_metadata.event_type"] = "DB_LOGIN_FAILED")))

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc

10 Pengguna Teratas berdasarkan Pernyataan CREATE
(target.process.command_line = /create/ nocase or extracted.fields["textPayload"] = /create/ nocase or additional.fields["statement"] = /create/ nocase or security_result.description = /create/ nocase or metadata.product_event_type = /create/ nocase)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Log_Type = metadata.log_type

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akses dengan Hak Istimewa Diberikan
$Summary = strings.coalesce(if (target.process.command_line = /grant|revoke|(alter|create|drop|delete)\s+(user|role|database|server\s+role|login|table|trigger|function)|set\s+(role|password)|rename|backup|restore|impersonate|superuser/ nocase,target.process.command_line, ""),
  if (extracted.fields["textPayload"] = /grant|revoke|(alter|create|drop|delete)\s+(user|role|database|server\s+role|login|table|trigger|function)|set\s+(role|password)|rename|backup|restore|impersonate|superuser/ nocase,extracted.fields["textPayload"], ""),
  if (additional.fields["statement"] = /grant|revoke|(alter|create|drop|delete)\s+(user|role|database|server\s+role|login|table|trigger|function)|set\s+(role|password)|rename|backup|restore|impersonate|superuser/ nocase,additional.fields["statement"], ""),
  if (security_result.description = /grant|revoke|(alter|create|drop|delete)\s+(user|role|database|server\s+role|login|table|trigger|function)|set\s+(role|password)|rename|backup|restore|impersonate|superuser/ nocase,security_result.description,  ""),
  if (metadata.product_event_type = /grant|revoke|(alter|create|drop|delete)\s+(user|role|database|server\s+role|login|table|trigger|function)|set\s+(role|password)|rename|backup|restore|impersonate|superuser/ nocase, strings.concat(metadata.product_event_type, " : ", extracted.fields["cmd_line"]),  ""))
$Summary != ""

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Log_Type = metadata.log_type

match:
  $User, $Hostname, $Summary, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

10 Pengguna Teratas menurut Pernyataan DROP
(target.process.command_line = /drop/ nocase or extracted.fields["textPayload"] = /drop/ nocase or additional.fields["statement"] = /drop/ nocase or security_result.description = /drop/ nocase or metadata.product_event_type = /drop/ nocase)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Log_Type = metadata.log_type

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Jalur File Terkait Database Teratas
$File_Path = target.file.full_path
$File_Path != ""
$Log_Type = metadata.log_type

match:
  $File_Path, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Operasi File Terbaru
$File = target.file.full_path
$File != ""
$Summary = strings.coalesce(target.process.command_line, security_result.description, security_result.action_details, extracted.fields["textPayload"], extracted.fields["cmd_line"])
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Log_Type = metadata.log_type

match:
  $User, $File, $Summary, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Pengguna Terbaru menurut Pernyataan CREATE
$Summary = strings.coalesce(if (target.process.command_line = /create/ nocase, target.process.command_line, ""),
                            if (extracted.fields["textPayload"] = /create/ nocase, extracted.fields["textPayload"], ""),
                            if (additional.fields["statement"] = /create/ nocase, additional.fields["statement"], ""),
                            if (security_result.description = /create/ nocase, security_result.description, "" ),
                            if (metadata.product_event_type = /create/ nocase, strings.concat(metadata.product_event_type, " : " ,extracted.fields["cmd_line"]), ""))
$Summary != ""

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Log_Type = metadata.log_type

match:
  $User, $Hostname, $Summary, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Upaya Login Gagal Baru-Baru Ini
((metadata.event_type = "USER_LOGIN" and security_result.action = "BLOCK") or (metadata.event_type = "GENERIC_EVENT" and (extracted.fields["token_metadata.event_type"] = "DB_LOGIN_FAILED")))

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Summary = strings.coalesce(extracted.fields["textPayload"], extracted.fields["cmd_line"], principal.user.attribute.permissions.name, security_result.action_details, security_result.description)

match:
  $User, $Hostname, $Summary, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Pernyataan DDL
$DDL_Statements = strings.coalesce(if (target.process.command_line = /alter|create|drop|rename|truncate|comment/ nocase, target.process.command_line, ""),
                                   if (extracted.fields["textPayload"] = /alter|create|drop|rename|truncate|comment/ nocase, extracted.fields["textPayload"], ""),
                                   if (additional.fields["statement"] = /alter|create|drop|rename|truncate|comment/ nocase, additional.fields["statement"], ""),
                                   if (security_result.description = /alter|create|drop|rename|truncate|comment/ nocase, security_result.description, "" ),
                                   if (metadata.product_event_type = /alter|create|drop|rename|truncate|comment/ nocase, strings.concat(metadata.product_event_type, " : " ,extracted.fields["cmd_line"]), ""))
$DDL_Statements != ""

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Log_Type = metadata.log_type

match:
  $DDL_Statements, $User, $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
10 Pernyataan Teratas yang Dieksekusi
$Command_Line = strings.coalesce(target.process.command_line, extracted.fields["textPayload"], additional.fields["statement"], extracted.fields["cmd_line"] security_result.description)
$Log_Type = metadata.log_type

match:
   $Command_Line ,$Log_Type

outcome:
   $Count = count(metadata.id)

order:
   $Count desc

limit:
    10
Upaya Login Berhasil Terbaru
((metadata.event_type = "USER_LOGIN" and security_result.action = "ALLOW") or (metadata.event_type = "GENERIC_EVENT" and (extracted.fields["token_metadata.event_type"] = "DB_LOGIN_SUCCESS")))

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Summary = strings.coalesce(extracted.fields["textPayload"], extracted.fields["cmd_line"], principal.user.attribute.permissions.name, security_result.action_details, security_result.description)

match:
  $User, $Hostname, $Summary, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Pengguna Terbaru menurut Koneksi Database
(metadata.product_event_type = /connection/ nocase or security_result.description = /Connection/ nocase or additional.fields["operation_name"]= /Connection/ nocase or extracted.fields["textPayload"] = /connection/ nocase or additional.fields["ctx"] = /conn/ nocase)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Summary  = strings.coalesce(extracted.fields["textPayload"], security_result.description, security_result.action_details, metadata.description)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Log_Type = metadata.log_type

match:
   $User, $Hostname, $Summary, $Log_Type

outcome:
   $Count = count(metadata.id)
   $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
   $Count desc
Upaya Login yang Berhasil dari Waktu ke Waktu
((metadata.event_type = "USER_LOGIN" and security_result.action = "ALLOW") or (metadata.event_type = "GENERIC_EVENT" and (extracted.fields["token_metadata.event_type"] = "DB_LOGIN_SUCCESS")))

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc

Peristiwa Hibah dari Waktu ke Waktu
(target.process.command_line = /grant/ nocase or extracted.fields["textPayload"] = /grant/ nocase or additional.fields["statement"] = /grant/ nocase or security_result.description = /grant/ nocase or metadata.product_event_type = /grant/ nocase)

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Traffic Aplikasi dari Waktu ke Waktu
$Application = target.application
$Application != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
   $Application, $Date

outcome:
   $Count = count(metadata.id)

order:
   $Date asc
Pengguna Terbaru menurut Pernyataan DROP
$Summary = strings.coalesce(if (target.process.command_line = /drop/ nocase, additional.fields["statement"], ""),
                            if (extracted.fields["textPayload"] = /drop/ nocase, extracted.fields["textPayload"], ""),
                            if (additional.fields["statement"] = /drop/ nocase, additional.fields["statement"], ""),
                            if (security_result.description = /drop/ nocase, security_result.description, "" ),
                            if (metadata.product_event_type = /drop/ nocase, strings.concat(metadata.product_event_type, " : " ,extracted.fields["cmd_line"]), ""))
$Summary != ""

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Log_Type = metadata.log_type

match:
   $User, $Hostname, $Summary, $Log_Type

outcome:
   $Count = count(metadata.id)
   $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
   $Count desc
Pernyataan DDL dari Waktu ke Waktu menurut Jenis Log
(target.process.command_line = /alter|create|drop|rename|truncate|comment/ nocase or extracted.fields["textPayload"] = /alter|create|drop|rename|truncate|comment/ nocase or additional.fields["statement"] = /alter|create|drop|rename|truncate|comment/ nocase or security_result.description = /alter|create|drop|rename|truncate|comment/ nocase or  metadata.product_event_type = /alter|create|drop|rename|truncate|comment/ nocase)

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Database menurut Aplikasi
$Application = target.application
$Application != ""
$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname, target.resource.name)
$Summary = strings.coalesce(extracted.fields["textPayload"], extracted.fields["cmd_line"],target.process.command_line, security_result.action_details, security_result.description)

match:
  $Application, $Summary, $User, $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Distribusi Tingkat Keparahan
$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

Pemantauan Penipuan

Dasbor ini memberikan ringkasan komprehensif tentang aktivitas terkait penipuan, yang menawarkan insight tentang tren, pola, dan perilaku peristiwa. Selain itu, alat ini juga menandai area berisiko tinggi dalam jaringan umpan, sehingga tim keamanan dapat menganalisis, memantau, dan merespons ancaman secara efektif.

Nama diagram Contoh kueri
10 IP Tujuan Teratas
$Destination_IP = strings.coalesce(target.ip, target.asset.ip)
$Log_Type = metadata.log_type

match:
  $Destination_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

Order:
  $Count desc

limit:
    10
10 IP Sumber Teratas
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Log_Type = metadata.log_type

match:
  $Source_IP, $Log_Type

outcome:
  $Count = count(metadata.id)

Order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu menurut Jenis Log
$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 Port dan Protokol Teratas
$Port = target.port

match:
  $Port

outcome:
  $Protocol = array_distinct(network.application_protocol)
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Ringkasan Geolocation Sumber
$Country = principal.ip_geo_artifact.location.country_or_region
$Country != ""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_longitude)

order:
  $Count desc
10 Nama Host Tujuan Teratas
$Destination_Hostname = strings.coalesce(target.hostname,target.asset.hostname)
$Log_Type = metadata.log_type

match:
  $Destination_Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perincian Fase Rantai Kill Decoy (Zscaler Deception)
$Kill_Chain = strings.coalesce(additional.fields["kill_chain_phase"],extracted.fields["kill_chain_phase"])
$Decoy_Server = strings.coalesce(additional.fields["decoy_recon_server_type"],extracted.fields["decoy_recon_server_type"])
$Attack_Type = strings.coalesce(additional.fields["decoy_recon_dataset_type"],extracted.fields["decoy_recon_dataset_type"])
$Source_User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses)
$Destination_Hostname = strings.coalesce(target.hostname, target.asset.hostname)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Destination_IP = strings.coalesce(target.ip, target.asset.ip)
$Log_Type = metadata.log_type

match:
  $Kill_Chain ,$Decoy_Server ,$Attack_Type, $Destination_Hostname, $Source_User, $Source_IP, $Destination_IP, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
10 Pengguna Sumber Teratas
$Source_User = strings.coalesce(principal.user.userid, principal.user.email_addresses, principal.user.user_display_name)
$Log_Type = metadata.log_type

match:
  $Source_User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Jenis Peristiwa Teratas menurut Jenis Log
$Log_Type = metadata.log_type
$Event_Type = metadata.event_type

match:
  $Event_Type, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Jenis Resource Umpan yang Paling Sering Ditargetkan (Zscaler Deception)
$Resource_Type = target.resource.type
$Destination_Hostname = strings.coalesce(target.hostname, target.asset.hostname)

match:
  $Resource_Type, $Destination_Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Umpan Teratas dengan Skor Risiko Tinggi (Zscaler Deception)
$Decoy_Server = strings.coalesce(additional.fields["decoy_recon_server_type"], extracted.fields["decoy_recon_server_type"])
$Attack_Type = strings.coalesce(additional.fields["decoy_recon_dataset_type"], extracted.fields["decoy_recon_dataset_type"])
$Risk_Score = security_result.risk_score
$Log_Type = metadata.log_type

match:
  $Decoy_Server, $Attack_Type , $Risk_Score, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Risk_Score desc

limit :
    10
Perincian Aktivitas menurut Jaringan Umpan (Zscaler Deception)
$Decoy_Network = strings.coalesce(additional.fields["decoy_network_name"],extracted.fields["decoy_network_name"])
$Attack_Type = strings.coalesce(additional.fields["decoy_recon_dataset_type"],extracted.fields["decoy_recon_dataset_type"])
$Log_Type = metadata.log_type

match:
  $Decoy_Network, $Attack_Type, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Peristiwa menurut Tingkat Keparahan
$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

Ringkasan Pemberitahuan EDR

Dasbor ini memberikan tampilan komprehensif tentang aset, peristiwa, dan deteksi ancaman aktif yang menawarkan visibilitas dan kontrol yang lebih baik.

Nama diagram Contoh kueri
10 Pemberitahuan EDR Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Log_Type = $event.metadata.log_type
$Detection = $event.security_result.summary
$Detection != ""

match:
  $Detection, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Pemberitahuan EDR Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Log_Type = $event.metadata.log_type
$Detection = $event.security_result.summary
$Detection != ""

match:
  $Detection, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Total Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

outcome:
  $Count = count($event.security_result.summary)
Sensor EDR Aktif
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$EDR_Asset = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$EDR_Asset != ""

match:
  $EDR_Asset
limit:
    50
10 Host Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$Hostname != ""

match:
  $Hostname
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Jumlah Sensor EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

outcome:
  $Count = count_distinct(strings.coalesce($event.principal.asset.hostname, $event.principal.hostname))
10 Teknik Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Technique_ID = strings.coalesce($event.security_result.attack_details.techniques.id, $event.security_result.detection_fields["Technique ID"])
$Technique  = strings.coalesce($event.security_result.attack_details.techniques.name, $event.security_result.detection_fields["Technique"])
$Technique_ID != ""
$Technique  != ""

match:
  $Technique_ID, $Technique
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Tingkat keparahan berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase
$event.security_result.summary != ""

$Severity = $event.security_result.severity

match:
  $Severity
outcome:
  $Count = count($event.security_result.summary)
order:
  $Severity asc
limit:
    10
Tingkat keparahan berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase
$event.security_result.summary != ""

$Severity = $event.security_result.severity

match:
  $Severity
outcome:
  $Count = count($event.security_result.summary)
order:
  $Severity asc
limit:
    10
10 Taktik Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Tactic_ID = strings.coalesce($event.security_result.attack_details.tactics.id, $event.security_result.detection_fields["Tactic ID"])
$Tactic_Name = strings.coalesce($event.security_result.attack_details.tactics.name, $event.security_result.detection_fields["Tactic"])
$Tactic_ID != ""
$Tactic_Name != ""

match:
  $Tactic_ID, $Tactic_Name
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Total Pemberitahuan EDR dari Waktu ke Waktu
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Date asc
Sensor EDR Aktif
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$EDR_Asset = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$EDR_Asset != ""

match:
  $EDR_Asset
limit:
    50
Total Pemberitahuan EDR dari Waktu ke Waktu
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Date asc
10 Teknik Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Technique_ID = strings.coalesce($event.security_result.attack_details.techniques.id, $event.security_result.detection_fields["Technique ID"])
$Technique  = strings.coalesce($event.security_result.attack_details.techniques.name, $event.security_result.detection_fields["Technique"])
$Technique_ID != ""
$Technique  != ""

match:
  $Technique_ID, $Technique
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Pengguna Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$User = $event.principal.user.user_display_name
$User != ""

match:
  $User
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Pengguna Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$User = $event.principal.user.user_display_name
$User != ""

match:
  $User
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Taktik Teratas
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Tactic_ID = strings.coalesce($event.security_result.attack_details.tactics.id, $event.security_result.detection_fields["Tactic ID"])
$Tactic_Name = strings.coalesce($event.security_result.attack_details.tactics.name, $event.security_result.detection_fields["Tactic"])
$Tactic_ID != ""
$Tactic_Name != ""

match:
  $Tactic_ID, $Tactic_Name
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Total Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

outcome:
  $Count = count($event.security_result.summary)
Jumlah Sensor EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

outcome:
  $Count = count_distinct(strings.coalesce($event.principal.asset.hostname, $event.principal.hostname))
10 Host Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /LIMACHARLIE_EDR|CS_EDR|CS_DETECTS|ESET_EDR|CHECKPOINT_EDR|SOPHOS_EDR|OSQUERY_EDR|DIGITALGUARDIAN_EDR|SENTINEL_DV|MICROSOFT_DEFENDER_ENDPOINT|SENTINEL_EDR|UPTYCS_EDR|SYMANTEC_EDR|FORTINET_FORTIEDR|REDCANARY_EDR|CYBEREASON_EDR|MICROSOFT_DEFENDER_IDENTITY|DEEP_INSTINCT_EDR|CB_EDR|PAN_EDR|FIREEYE_HX|WATCHGUARD_EDR/ nocase

$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$Hostname != ""

match:
  $Hostname
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10

Ringkasan Aktivitas Email

Dasbor ini memberikan ringkasan mendetail tentang traffic email, termasuk total volume, email yang diizinkan versus yang diblokir, pengirim unik, penerima unik, dan statistik utama tentang pengirim dan penerima teratas. Alat ini memberikan insight berharga tentang pola komunikasi dan meningkatkan keamanan email, efektivitas pemfilteran, dan pengelolaan email secara keseluruhan.

Nama diagram Contoh kueri
Peristiwa Email Terbaru
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Sender = $event.network.email.from
$Recipient = $event.network.email.to
$Subject = $event.network.email.subject
$Subject != ""
$Date = timestamp.get_timestamp($event.metadata.event_timestamp.seconds)
$Action = $event.security_result.action

match:
  $Date, $Sender, $Recipient, $Subject, $Action
order:
  $Date desc
limit:
    50
Email yang Diblokir
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
$event.security_result.action = "BLOCK"

outcome:
  $Count = count($event.metadata.id)
5 Penerima Teratas menurut Jenis Log
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Log_Type = $event.metadata.log_type
$Recipients = $event.network.email.to
$Recipients != ""

match:
  $Log_Type, $Recipients
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    5 
Peristiwa Email yang Diizinkan
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
$event.security_result.action = "ALLOW"

outcome:
  $Count = count($event.metadata.id)
5 Penerima Teratas menurut Jenis Log
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Log_Type = $event.metadata.log_type
$Recipients = $event.network.email.to
$Recipients != ""

match:
  $Log_Type, $Recipients
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    5 
Total Peristiwa Email
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count($event.metadata.id)
10 Sumber Log Email Teratas menurut Jenis Peristiwa
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type

match:
  $Log_Type, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Peristiwa Email yang Diizinkan
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
$event.security_result.action = "ALLOW"

outcome:
  $Count = count($event.metadata.id)
5 Pengirim Teratas menurut Jenis Log
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Log_Type = $event.metadata.log_type
$Sender = $event.network.email.from
$Sender != ""

match:
  $Log_Type, $Sender
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    5
Pengirim Unik
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count_distinct($event.network.email.from)
Pengirim Unik
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count_distinct($event.network.email.from)
Total Peristiwa Email
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count($event.metadata.id)
5 Pengirim Teratas menurut Jenis Log
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Log_Type = $event.metadata.log_type
$Sender = $event.network.email.from
$Sender != ""

match:
  $Log_Type, $Sender
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    5
Peristiwa Email Terbaru
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Sender = $event.network.email.from
$Recipient = $event.network.email.to
$Subject = $event.network.email.subject
$Subject != ""
$Date = timestamp.get_timestamp($event.metadata.event_timestamp.seconds)
$Action = $event.security_result.action

match:
  $Date, $Sender, $Recipient, $Subject, $Action
order:
  $Date desc
limit:
    50
Penerima Unik
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count_distinct($event.network.email.to)
Email yang Diblokir
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
$event.security_result.action = "BLOCK"

outcome:
  $Count = count($event.metadata.id)
Penerima Unik
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

outcome:
  $Count = count_distinct($event.network.email.to)
10 Sumber Log Email Teratas menurut Jenis Peristiwa
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type

match:
  $Log_Type, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

Ringkasan Keamanan Email

Dasbor ini memberikan informasi tentang ancaman email seperti phishing, malware, ransomware, dan Business Email Compromise (BEC). Laporan ini memberikan ringkasan tentang peristiwa terkait keamanan, pengirim berbahaya, IP sumber, dan alamat email yang ditargetkan.

Nama diagram Contoh kueri
10 Domain Teratas yang Teridentifikasi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.principal.administrative_domain != ""

$Domain = $event.principal.administrative_domain

match:
  $Domain
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Total Phishing yang Terdeteksi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category = "MAIL_PHISHING"

outcome:
  $Count = count_distinct($event.principal.user.email_addresses)
Kategori Email dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Category = $event.security_result.category
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Category
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
10 URL Mencurigakan Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$event.security_result.category = "MAIL_PHISHING"
or $event.security_result.category = "MAIL_SPAM"
or $event.security_result.category = "MAIL_SPOOFING"
or $event.security_result.category = "SOFTWARE_MALICIOUS"
strings.coalesce($event.target.url, $event.security_result.about.url,$event.security_result.detection_fields["detectedUrls"]) != ""

$URL = strings.coalesce($event.target.url, $event.security_result.about.url,$event.security_result.detection_fields["detectedUrls"])

match:
  $URL
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
Phishing Terdeteksi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category = "MAIL_PHISHING"

$Email = $event.principal.user.email_addresses

match:
  $Email
10 IP Sumber Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.principal.ip != ""

$Source_IP = $event.principal.ip

match:
  $Source_IP
outcome:
  $Count = count($event.principal.ip)
order:
  $Count desc
limit:
    10
Ancaman Email menurut Kategori
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase

$Threat_Name = $event.security_result.category_details
$Category = $event.security_result.category

match:
  $Threat_Name, $Category
outcome:
  $Count = count($event.security_result.threat_name)
order:
  $Count desc
limit:
    50 
Tindakan yang Dilakukan dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Action = $event.security_result.action
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Action
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc

Ancaman Email yang Teridentifikasi dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Threat_Name = $event.security_result.threat_name
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Threat_Name
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc 
Ancaman Email yang Teridentifikasi dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Threat_Name = $event.security_result.threat_name
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Threat_Name
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc 
Ancaman Aktif Terbaru
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Threat_Name = $event.security_result.threat_name
$Status = $event.security_result.threat_status

match:
  $Threat_Name, $Status
outcome:
  $Count = count($event.metadata.id)
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50
URL yang Diblokir vs. URL yang Diizinkan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.action = "ALLOW"
or $event.security_result.action = "BLOCK"

$Action = $event.security_result.action
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Action
outcome:
  $Count = count($event.target.url)
order:
  $Count desc
Phishing Terdeteksi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category = "MAIL_PHISHING"

$Email = $event.principal.user.email_addresses

match:
  $Email
10 Pengirim Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.network.email.from != ""

$Sender = $event.network.email.from

match:
  $Sender
outcome:
  $Count = count($event.network.email.from)
order:
  $Count desc
limit:
    10
Lampiran Berbahaya Terbaru
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
strings.coalesce($event.about.file.full_path, $event.security_result.detection_fields["attachmentNames"]) != ""

$Attachment = strings.coalesce($event.about.file.full_path, $event.security_result.detection_fields["attachmentNames"])
$Category = $event.security_result.category
$Sender = $event.network.email.from
$Receiver = $event.network.email.to
$Status = $event.additional.fields["remediationStatus"]
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Sender, $Receiver, $Attachment, $Category, $Status
order:
  $Date desc
limit:
    50
Total Phishing yang Terdeteksi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category = "MAIL_PHISHING"

outcome:
  $Count = count_distinct($event.principal.user.email_addresses)
10 Email Bertarget Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.target.user.email_addresses != ""

$Target = $event.target.user.email_addresses

match:
  $Target
outcome:
  $Count = count($event.target.user.email_addresses)
order:
  $Count desc
limit:
    10
Kategori Email dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Category = $event.security_result.category
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Category
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
10 URL Mencurigakan Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$event.security_result.category = "MAIL_PHISHING"
or $event.security_result.category = "MAIL_SPAM"
or $event.security_result.category = "MAIL_SPOOFING"
or $event.security_result.category = "SOFTWARE_MALICIOUS"
strings.coalesce($event.target.url, $event.security_result.about.url,$event.security_result.detection_fields["detectedUrls"]) != ""

$URL = strings.coalesce($event.target.url, $event.security_result.about.url,$event.security_result.detection_fields["detectedUrls"])

match:
  $URL
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
Tindakan yang Dilakukan dari Waktu ke Waktu
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Action = $event.security_result.action
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Action
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc

10 Ancaman Tingkat Keparahan Tinggi Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category_details != ""
$event.security_result.severity = "HIGH"

$Category = $event.security_result.category_details
$Category != ""

match:
   $Category
outcome:
   $Count = count($event.metadata.id)
order:
   $Count desc
limit:
    10 
10 IP Sumber Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.principal.ip != ""

$Source_IP = $event.principal.ip

match:
  $Source_IP
outcome:
  $Count = count($event.principal.ip)
order:
  $Count desc
limit:
    10
10 Pengirim Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.network.email.from != ""

$Sender = $event.network.email.from

match:
  $Sender
outcome:
  $Count = count($event.network.email.from)
order:
  $Count desc
limit:
    10
URL yang Diblokir vs. URL yang Diizinkan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.action = "ALLOW"
or $event.security_result.action = "BLOCK"

$Action = $event.security_result.action
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Action
outcome:
  $Count = count($event.target.url)
order:
  $Count desc
Lampiran Berbahaya Terbaru
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
strings.coalesce($event.about.file.full_path, $event.security_result.detection_fields["attachmentNames"]) != ""

$Attachment = strings.coalesce($event.about.file.full_path, $event.security_result.detection_fields["attachmentNames"])
$Category = $event.security_result.category
$Sender = $event.network.email.from
$Receiver = $event.network.email.to
$Status = $event.additional.fields["remediationStatus"]
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Sender, $Receiver, $Attachment, $Category, $Status
order:
  $Date desc
limit:
    50
10 Lokasi Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.principal.location.country_or_region != ""

$Countries = $event.principal.location.country_or_region
$Latitude = $event.principal.location.region_coordinates.latitude
$Longitude = $event.principal.location.region_coordinates.longitude

match:
  $Countries, $Latitude, $Longitude
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Ancaman Email menurut Kategori
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase

$Threat_Name = $event.security_result.category_details
$Category = $event.security_result.category

match:
  $Threat_Name, $Category
outcome:
  $Count = count($event.security_result.threat_name)
order:
  $Count desc
limit:
    50 
10 Ancaman Email Teratas menurut Tingkat Keparahan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category_details != ""

$Severity = $event.security_result.severity
$Threat_Name = $event.security_result.category_details
$Threat_Name != ""

match:
  $Threat_Name, $Severity
outcome:
  $Count = count($event.security_result.severity)
order:
  $Count desc
limit:
    10
Ancaman Aktif Terbaru
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Threat_Name = $event.security_result.threat_name
$Status = $event.security_result.threat_status

match:
  $Threat_Name, $Status
outcome:
  $Count = count($event.metadata.id)
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50
Distribusi Status Ancaman
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Status = $event.security_result.threat_status

match:
  $Status
outcome:
  $Count = count($event.security_result.threat_name)
order:
  $Count desc 
Distribusi Tindakan Hasil Keamanan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Action = $event.security_result.action

match:
  $Action
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
Distribusi Tindakan Hasil Keamanan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Action = $event.security_result.action

match:
  $Action
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
10 Email Bertarget Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.target.user.email_addresses != ""

$Target = $event.target.user.email_addresses

match:
  $Target
outcome:
  $Count = count($event.target.user.email_addresses)
order:
  $Count desc
limit:
    10
10 Lokasi Berbahaya Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.detection_fields["judgement"] = /MALICIOUS/ nocase
$event.principal.location.country_or_region != ""

$Countries = $event.principal.location.country_or_region
$Latitude = $event.principal.location.region_coordinates.latitude
$Longitude = $event.principal.location.region_coordinates.longitude

match:
  $Countries, $Latitude, $Longitude
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Ancaman Tingkat Keparahan Tinggi Teratas
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category_details != ""
$event.security_result.severity = "HIGH"

$Category = $event.security_result.category_details

match:
   $Category
outcome:
   $Count = count($event.metadata.id)
order:
   $Count desc
limit:
    10 
Distribusi Status Ancaman
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"

$Status = $event.security_result.threat_status

match:
  $Status
outcome:
  $Count = count($event.security_result.threat_name)
order:
  $Count desc 
10 Ancaman Email Teratas menurut Tingkat Keparahan
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.category_details != ""

$Severity = $event.security_result.severity
$Threat_Name = $event.security_result.category_details

match:
  $Threat_Name, $Severity
outcome:
  $Count = count($event.security_result.severity)
order:
  $Count desc
limit:
    10
10 Domain Teratas yang Teridentifikasi
$event.metadata.log_type = /ABNORMAL_SECURITY|AREA1|AVANAN_EMAIL|BARRACUDA_EMAIL|CISCO_EMAIL_SECURITY|COFENSE_TRIAGE|EXCHANGE_MAIL|FIREEYE_EMPS|FIREEYE_ETP|FORCEPOINT_EMAILSECURITY|FORCEPOINT_MAIL_RELAY|FORTINET_FORTIMAIL|KNOWBE4_PHISHER|MAILMARSHAL|MICROSOFT_DEFENDER_MAIL|MIMECAST_MAIL|MIMECAST_URL_LOGS|OBSERVEIT|OFFICE_365|POSTFIX_MAIL|PROOFPOINT_MAIL|PROOFPOINT_MAIL_FILTER|PROOFPOINT_ON_DEMAND|PROOFPOINT_SENDMAIL_SENTRION|PROOFPOINT_SER|PROOFPOINT_TAP_FORENSICS|PROOFPOINT_TRAP|SENDMAIL|SEPPMAIL|SYMANTEC_VIP|VIRTRU_EMAIL_ENCRYPTION|VOLTAGE|WORKSPACE_ALERTS|ZIX_EMAIL_ENCRYPTION|PHISHLABS/ nocase
$event.metadata.event_type = "EMAIL_UNCATEGORIZED"
or $event.metadata.event_type = "EMAIL_TRANSACTION"
or $event.metadata.event_type = "NETWORK_HTTP"
$event.principal.administrative_domain != ""

$Domain = $event.principal.administrative_domain

match:
  $Domain
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

Pemantauan Berkelanjutan FEDRAMP

Dasbor ini memberikan tampilan yang jelas tentang kepatuhan sistem dan postur keamanan. Platform ini melacak kerentanan, dan efektivitas kontrol terhadap standar FedRAMP, sehingga membantu Anda tetap mematuhi standar dan memprioritaskan upaya perbaikan.

Nama diagram Contoh kueri
Total Koneksi Masuk
metadata.event_type = "NETWORK_CONNECTION"
network.direction = "INBOUND"

outcome:
  $Count = count_distinct(principal.ip)
Sistem dengan Update yang Tersedia
metadata.product_event_type = "40"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)

match:
  $Hostname, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Notifikasi Vendor Perlindungan Media Terbaru
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Vendor_Alert = strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary)
$User = strings.coalesce(principal.user.user_display_name, target.user.user_display_name)
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$File_Name = target.file.full_path
$Action = security_result.action
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Vendor_Alert, $Source_IP, $User, $File_Name, $Action

order:
  $Date desc
10 Domain Teratas yang Diblokir
security_result.action = "BLOCK"

$Destination_Domain = strings.coalesce(target.administrative_domain, about.administrative_domain, target.ip_geo_artifact.network.dns_domain)
$Destination_Domain != ""

match:
  $Destination_Domain

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Traffic Jaringan dari Waktu ke Waktu menurut Arah
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Direction = network.direction
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Direction, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Kerentanan menurut Tingkat Keparahan
$Severity =
    if (principal.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        principal.asset.vulnerabilities.severity,
    if (target.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        target.asset.vulnerabilities.severity,
    if (extensions.vulns.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        extensions.vulns.vulnerabilities.severity,
    "UNKNOWN_SEVERITY")))

match:
  $Severity

outcome:
  $Event_Count = count(strings.coalesce(extensions.vulns.vulnerabilities.name, extensions.vulns.vulnerabilities.description, extensions.vulns.vulnerabilities.vendor_vulnerability_id, principal.asset.vulnerabilities.name, target.asset.vulnerabilities.name, additional.fields["ScanReference"]))

order:
  $Severity desc
10 Eksekusi Aplikasi yang Diblokir Teratas Berdasarkan Alasan
metadata.product_event_type = /(execution|application) block/ nocase
or security_result.threat_name = /application control/ nocase
security_result.action = "BLOCK"

$Application = strings.coalesce(about.file.full_path, target.process.file.full_path, additional.fields["fname"])
$Reason = strings.coalesce(target.resource.attribute.labels["categoryTupleDescription"], security_result.action_details, metadata.product_event_type)

match:
  $Application, $Reason

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Penggunaan Versi TLS yang Lemah dari Waktu ke Waktu
network.tls.version != /1(\.|_)?(2|3)/ nocase

$Cipher_Version = network.tls.version
$Cipher_Version != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Cipher_Version, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Login menurut Status dari Waktu ke Waktu
metadata.event_type = "USER_LOGIN"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Status Pendaftaran MFA
metadata.product_name  = "MULTI-FACTOR_AUTHENTICATION"
or strings.coalesce(additional.fields["AuthenticationRequirement"], security_result.detection_fields.value) = /mfa|multi(?:\s|\S)?factor(?:\s|\S)?authentication|/ nocase

metadata.product_event_type = "enrollment"
or target.resource_ancestors.resource_subtype = "AuthenticatorEnrollment"

$Result = security_result.summary

match:
  $Result

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Endpoint Teratas menurut Peringatan Tingkat Keparahan Tinggi
principal.hostname != ""

$Hostname = principal.hostname
$Severity = security_result.severity
$Severity = "CRITICAL" or $Severity = "HIGH"

match:
  $Hostname, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Alamat IP Masuk Teratas
network.direction = "INBOUND"

$Log_Type = metadata.log_type
$Source_IP = principal.ip

match:
  $Log_Type, $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peringatan Vendor Perlindungan Media menurut Tindakan dari Waktu ke Waktu
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Check-In Pengguna Terbaru Teratas
(metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_UNCATEGORIZED")
strings.coalesce(metadata.description, security_result.action_details, security_result.description, security_result.summary, additional.fields["plasectrxEvtypename"]) = /(?:access\sgranted|badge\sin)/ nocase

$User = strings.coalesce(principal.user.user_display_name, principal.user.email_addresses, additional.fields["person"], principal.user.userid)
$Location = strings.coalesce(security_result.rule_labels["Place"], additional.fields["site"], target.location.name, principal.resource.name)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %H:%M:%S ")

match:
  $Date, $User, $Location

order:
  $Date desc

limit:
    10
Deteksi Endpoint dengan Tingkat Keparahan Tinggi dari Waktu ke Waktu
principal.hostname != ""

$Severity = security_result.severity
$Severity = "CRITICAL" or $Severity = "HIGH"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
   $Severity, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Total Koneksi Keluar
metadata.event_type = "NETWORK_CONNECTION"
network.direction = "OUTBOUND"

outcome:
  $Count = count_distinct(target.ip)
10 Pengguna Teratas yang Gagal Login
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"
target.user.userid != ""

$User = target.user.userid

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi Cipher TLS
network.tls.cipher != /1(\.|_)?(2|3)/ nocase

$TLS_Cipher = network.tls.cipher
$TLS_Cipher != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $TLS_Cipher, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Pelanggaran DLP menurut Tingkat Keparahan
metadata.log_type = /DLP/ nocase
metadata.product_event_type = /Violation/ nocase

$Severity = security_result.severity
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Severity desc
Kerentanan menurut Usia
(timestamp.as_unix_seconds(additional.fields["first_found"]) > 0
or extensions.vulns.vulnerabilities.first_found.seconds > 0
or principal.asset.vulnerabilities.first_found.seconds > 0)

$Vulnerability = strings.coalesce(
  if(principal.asset.vulnerabilities.name != "" and principal.asset.vulnerabilities.description != "",
    strings.concat(principal.asset.vulnerabilities.name, " : ", principal.asset.vulnerabilities.description),
    strings.coalesce(principal.asset.vulnerabilities.name, principal.asset.vulnerabilities.description)),
  if(additional.fields["ScanReference"] != "" and metadata.description != "",
    strings.concat(additional.fields["ScanReference"], " : ", metadata.description),
    strings.coalesce(additional.fields["ScanReference"], metadata.description)),
  if(extensions.vulns.vulnerabilities.vendor_vulnerability_id != "" and extensions.vulns.vulnerabilities.description != "",
    strings.concat(extensions.vulns.vulnerabilities.vendor_vulnerability_id, " : ", extensions.vulns.vulnerabilities.description),
    strings.coalesce(extensions.vulns.vulnerabilities.vendor_vulnerability_id, extensions.vulns.vulnerabilities.description)
  )
)

$Vulnerability != " : "
$Vulnerability != ""
$Log_Type = metadata.log_type

match:
  $Vulnerability, $Log_Type

outcome:
  $Age = max(cast.as_int((metadata.event_timestamp.seconds - if(timestamp.as_unix_seconds(additional.fields["first_found"]) > 0, timestamp.as_unix_seconds(additional.fields["first_found"]), if(extensions.vulns.vulnerabilities.first_found.seconds > 0, extensions.vulns.vulnerabilities.first_found.seconds, if(principal.asset.vulnerabilities.first_found.seconds > 0, principal.asset.vulnerabilities.first_found.seconds, metadata.event_timestamp.seconds)))) / 86400))
  $Days_Range = if($Age <= 30, "0-30 Days",
                 if($Age <= 60, "31-60 Days",
                 if($Age <= 90, "61-90 Days", "> 90 Days")))
  $Count = count(strings.coalesce(extensions.vulns.vulnerabilities.name, extensions.vulns.vulnerabilities.description, extensions.vulns.vulnerabilities.vendor_vulnerability_id, principal.asset.vulnerabilities.name, additional.fields["ScanReference"]))

order:
  $Age desc
Mengubah Izin Akun Pengguna
metadata.event_type = "USER_CHANGE_PERMISSIONS"
principal.user.userid != ""

outcome:
  $Count = count_distinct(metadata.id)
10 Alamat IP Keluar Teratas
network.direction = "OUTBOUND"

$Log_Type = metadata.log_type
$Destination_IP = target.ip

match:
  $Log_Type, $Destination_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas menurut Tindakan Istimewa
principal.user.attribute.roles.type = "ADMINISTRATOR"
or strings.coalesce(principal.user.attribute.roles.name, principal.user.userid) = /Admin|Root|Super/ nocase

$User = principal.user.userid
$Action = metadata.product_event_type

match:
  $User, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Pemantauan Aktivitas Firewall

Dasbor ini memberikan informasi tentang aktivitas firewall untuk meningkatkan keamanan dan pengelolaan performa. Layanan ini memberikan insight real-time tentang keamanan jaringan dengan melacak berbagai metrik dan peristiwa yang terkait dengan aktivitas firewall, sehingga membantu pengguna mengelola dan merespons potensi ancaman secara efektif.

Nama diagram Contoh kueri
Aturan Firewall yang Jarang Dipicu
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$rule_name
outcome:
$Count = count($rule_name)
order: $Count asc
limit: 10
10 Aturan Firewall Teratas yang Dipicu
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
match:
$rule_name
outcome:
$Count = count(metadata.id)
order: $Count desc
limit: 10
Koneksi menurut Lokasi Geografis
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
$country = principal.location.country_or_region
$country != ""
$direction = network.direction
match:
$country
outcome:
$event_count = count_distinct($country)
$latitude = max(principal.location.region_coordinates.latitude)
$longitude = max(principal.location.region_coordinates.longitude)
Tujuan Koneksi Teratas
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$Dest_IP = target.ip
$Dest_IP != ""
match:
$Dest_IP
outcome:
$event_count = count(metadata.id)
order: $event_count desc
limit: 10
Arus Masuk Data menurut IP
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$ruleN = security_result.rule_name
$IP = principal.ip
$byte = network.received_bytes
$byte != 0
$Vendor = metadata.vendor_name
$Vendor != ""
match:
$IP, $Vendor
outcome:
$byte_sum=sum($byte)
$Data_in_mb = math.round($byte_sum/1048576)
order: $Data_in_mb desc
limit: 10
Koneksi menurut Lokasi Geografis
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
$country = principal.location.country_or_region
$country != ""
$direction = network.direction
match:
$country
outcome:
$event_count = count_distinct($country)
$latitude = max(principal.location.region_coordinates.latitude)
$longitude = max(principal.location.region_coordinates.longitude)
Aliran Data menurut IP
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$IP = principal.ip
$byte = network.sent_bytes
$byte != 0
$Vendor = metadata.vendor_name
metadata.vendor_name != ""
match:
$IP, $Vendor
outcome:
$byte_sum=sum($byte)
$data_in_mb = math.round($byte_sum/1048576)
order: $data_in_mb desc
limit:10
Aturan Firewall yang Jarang Dipicu
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$rule_name
outcome:
$Count = count($rule_name)
order: $Count asc
limit: 10
Sumber Koneksi teratas
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$Src_IP = principal.ip
match:
$Src_IP
outcome:
$event_count = count(metadata.id)
order: $event_count desc
limit: 10
Traffic yang Diblokir vs. Traffic yang Diizinkan
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$action = security_result.action
$action = "BLOCK" OR $action = "ALLOW"
match:
$action
outcome:
$event_count = count(metadata.id)
order: $event_count desc
10 Aturan Firewall Teratas yang Dipicu
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$rule_name !=""
match:
$rule_name
outcome:
$Count = count(metadata.id)
order: $Count desc
limit: 10
Traffic yang Diblokir vs. Traffic yang Diizinkan
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$action = security_result.action
$action = "BLOCK" OR $action = "ALLOW"
match:
$action
outcome:
$event_count = count(metadata.id)
order: $event_count desc
Aliran Data menurut IP
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$IP = principal.ip
$byte = network.sent_bytes
$byte != 0
$Vendor = metadata.vendor_name
metadata.vendor_name != ""
match:
$IP, $Vendor
outcome:
$byte_sum=sum($byte)
$data_in_mb = math.round($byte_sum/1048576)
order: $data_in_mb desc
limit:10
Arus Masuk Data menurut IP
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$ruleN = security_result.rule_name
$IP = principal.ip
$byte = network.received_bytes
$byte != 0
$Vendor = metadata.vendor_name
$Vendor != ""
match:
$IP, $Vendor
outcome:
$byte_sum=sum($byte)
$Data_in_mb = math.round($byte_sum/1048576)
order: $Data_in_mb desc
limit: 10
Sumber Koneksi teratas
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$Src_IP = principal.ip
$Src_IP != ""
match:
$Src_IP
outcome:
$event_count = count(metadata.id)
order: $event_count desc
limit: 10
Tujuan Koneksi Teratas
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$Dest_IP = target.ip
$Dest_IP != "EMPTY"
match:
$Dest_IP
outcome:
$event_count = count(metadata.id)
order: $event_count desc
limit: 10
10 IP Teratas yang Diblokir
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$action = security_result.action
$action = "BLOCK"
$IP = principal.ip
match:
$IP, $action
outcome:
$event_count = count_distinct(metadata.id)
order: $event_count desc
limit: 10
10 IP Teratas yang Diblokir
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$log_type = metadata.log_type
$rule_name = security_result.rule_name
$action = security_result.action
$action = "BLOCK"
$IP = principal.ip
match:
$IP, $action
outcome:
$event_count = count_distinct(metadata.id)
order: $event_count desc
limit: 10

Tata Kelola Data GDPR

Dasbor ini memberikan visibilitas ke akses data di seluruh region Uni Eropa, termasuk tren akses, upaya akses non-Uni Eropa, dan geolokasi teratas. Fitur ini membantu memantau kepatuhan terhadap peraturan GDPR, mendeteksi akses data yang tidak sah, dan memastikan penanganan data Uni Eropa yang aman.

Nama diagram Contoh kueri
Akses Akun Istimewa ke Resource Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.log_type = "GENERIC_EVENT" OR metadata.event_type ="USER_LOGIN" or metadata.log_type = "USER_CHANGE_PERMISSIONS")

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid,target.user.user_display_name,target.user.email_addresses)
($User = /admin|root|svc|adm|privilege/ nocase or principal.user.attribute.roles.type = "SERVICE_ACCOUNT" or principal.user.attribute.roles.type = "ADMINISTRATOR" or principal.user.account_type = "DOMAIN_ACCOUNT_TYPE" or principal.user.account_type = "SERVICE_ACCOUNT_TYPE")
$Target_EU_Country =  strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)
$Event_Type = metadata.event_type
$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Target_Resource = strings.coalesce(target.resource.name, target.file.full_path, target.resource.product_object_id, target.group.product_object_id, target.user.group_identifiers)
$Target_Resourcetype = target.resource.resource_type
$Action = security_result.action

match:
   $Event_Type, $User,$Source_IP, $Target_EU_Country, $Target_Resource, $Target_Resourcetype, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))

order:
   $Count desc

Distribusi Versi TLS yang Lemah
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

network.tls.version != /1(\.|_)?(2|3)/ nocase

$TLS_Version = network.tls.version
$TLS_Version != ""

match:
  $TLS_Version

outcome:
  $Count = count(metadata.id)
 
10 IP Non-Uni Eropa Teratas yang Mengakses Resource Uni Eropa
(strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase
and strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name) != /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase)

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.log_type = "GENERIC_EVENT" OR metadata.event_type ="USER_LOGIN" or metadata.log_type = "USER_CHANGE_PERMISSIONS")

$Principal_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Principal_IP != ""
$Principal_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)

match:
  $Principal_IP, $Principal_Country

outcome:
  $Count = count(metadata.id)

order :
  $Count desc

limit:
   10
10 Pengguna Teratas yang Mengakses Resource Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$User = strings.coalesce(principal.user.user_display_name, principal.user.userid,  principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses)
$Source_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)
$User != ""

match:
  $User, $Source_Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akses Data Uni Eropa berdasarkan Geolokasi Sumber
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

principal.ip_geo_artifact.location.region_coordinates.latitude != 0
principal.ip_geo_artifact.location.region_coordinates.longitude != 0

$Source_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)

match:
  $Source_Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)
Peristiwa Penghapusan dan Pembersihan Data di Resource Uni Eropa dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "FILE_DELETION" or metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" or metadata.event_type = "USER_RESOURCE_DELETION"
 or metadata.product_event_type = /delete|purge/ nocase or security_result.summary = /delete|purge/ nocase or security_result.description = /delete|purge/ nocase)
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Enkripsi Lemah pada Resource Uni Eropa dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(((target.resource.attribute.labels.key  = "keyProperties_type" or target.resource.attribute.labels.key  = "requestParameters.keySpec" or target.resource.attribute.labels.key = /key/ nocase) and target.resource.attribute.labels.value  = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/) or network.tls.cipher = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/)

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Penghapusan dan Penghapusan Permanen Data di Resource Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "FILE_DELETION" or metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" or metadata.event_type = "USER_RESOURCE_DELETION"
 or metadata.product_event_type = /delete|purge/ nocase or security_result.summary = /delete|purge/ nocase or security_result.description = /delete|purge/ nocase)
security_result.action = "ALLOW"

$Description = strings.coalesce(security_result.summary, security_result.description, metadata.description, security_result.action_details)
$Product_Event_Type = metadata.product_event_type
$Event_Type = metadata.event_type
$Log_Type = metadata.log_type
$Target_Resource = strings.coalesce(target.resource.name, target.file.full_path, target.resource.product_object_id, target.group.product_object_id, target.user.group_identifiers)
$User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses, target.user.userid,target.user.user_display_name,target.user.email_addresses)

match:
  $User, $Log_Type, $Target_Resource, $Description, $Product_Event_Type, $Event_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))
  $Count = count(metadata.id)

order:
  $Date desc, $Count desc
10 Akun Istimewa Teratas yang Mengakses Resource Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT" OR metadata.event_type ="USER_LOGIN" or metadata.event_type = "USER_CHANGE_PERMISSIONS")

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid,target.user.user_display_name,target.user.email_addresses)
($User = /admin|root|svc|adm|privilege/ nocase or principal.user.attribute.roles.type = "SERVICE_ACCOUNT" or principal.user.attribute.roles.type = "ADMINISTRATOR" or principal.user.account_type = "DOMAIN_ACCOUNT_TYPE" or principal.user.account_type = "SERVICE_ACCOUNT_TYPE")
$Target_EU_Country =  strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)

match:
  $User, $Target_EU_Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa DLP Berbasis Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT" OR metadata.event_type = "NETWORK_UNCATEGORIZED" OR metadata.event_type = "NETWORK_FLOW" OR metadata.event_type = "NETWORK_CONNECTION" OR metadata.event_type = "NETWORK_FTP" OR metadata.event_type = "NETWORK_DHCP" OR metadata.event_type = "NETWORK_DNS" OR metadata.event_type = "NETWORK_HTTP" OR metadata.event_type = "NETWORK_SMTP")

(metadata.log_type = /DLP|ACCELLION|CODE42_INCYDR|GUARDIUM|TRIPWIRE_FIM/ nocase OR metadata.product_event_type = /dlp/  nocase OR security_result.outcomes.value = /dlp/  nocase OR security_result.rule_type = /dlp/  nocase OR security_result.rule_name = /dlp/  nocase OR security_result.category_details = /dlp|data loss prevention/ nocase OR security_result.category = "DATA_EXFILTRATION" or security_result.category = "DATA_DESTRUCTION")

outcome:
  $Count = count(metadata.id)
10 Domain Eksternal Teratas yang Menerima Data Uni Eropa
strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT" OR metadata.event_type = "NETWORK_UNCATEGORIZED" OR metadata.event_type = "NETWORK_FLOW" OR metadata.event_type = "NETWORK_CONNECTION" OR metadata.event_type = "NETWORK_FTP" OR metadata.event_type = "NETWORK_DHCP" OR metadata.event_type = "NETWORK_DNS" OR metadata.event_type = "NETWORK_HTTP"
OR metadata.event_type = "NETWORK_SMTP")
network.direction = "OUTBOUND"
network.sent_bytes > 0

$Target_Domain = re.capture(strings.coalesce(target.url, target.administrative_domain), `^(?:https?:\/\/)?(?:www\.)?([^\/:]+)`)
$Target_Domain != ""
$Target_EU_Country = strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)

match:
  $Target_Domain, $Target_EU_Country

outcome:
  $Size_in_MB = math.round((sum(network.sent_bytes)/1000000), 2)

order :
  $Size_in_MB desc

limit:
   10
Ringkasan File Malware
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

(metadata.product_event_type = /malware/ nocase or security_result.summary = /malware/ nocase or security_result.category_details = /malware/ nocase or metadata.description = /malware/ nocase or security_result.threat_name = /malware/ nocase or security_result.rule_name = /malware/ nocase or security_result.category = "SOFTWARE_MALICIOUS")

$Source_User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses)
$File_Name = strings.coalesce(target.file.full_path, about.file.full_path)
$File_Name != ""
$File_Type = target.file.file_type
$Severity = security_result.severity
$Action = security_result.action
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Threat_Name = security_result.threat_name

match :
  $Hostname,$File_Name, $File_Type, $Threat_Name, $Source_User, $Severity, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Peristiwa DLP Berbasis Uni Eropa dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT" OR metadata.event_type = "NETWORK_UNCATEGORIZED" OR metadata.event_type = "NETWORK_FLOW" OR metadata.event_type = "NETWORK_CONNECTION" OR metadata.event_type = "NETWORK_FTP" OR metadata.event_type = "NETWORK_DHCP" OR metadata.event_type = "NETWORK_DNS" OR metadata.event_type = "NETWORK_HTTP" OR metadata.event_type = "NETWORK_SMTP")

(metadata.log_type = /DLP|ACCELLION|CODE42_INCYDR|GUARDIUM|TRIPWIRE_FIM/ nocase OR metadata.product_event_type = /dlp/  nocase OR security_result.outcomes.value = /dlp/  nocase OR security_result.rule_type = /dlp/  nocase OR security_result.rule_name = /dlp/  nocase OR security_result.category_details = /dlp|data loss prevention/ nocase OR security_result.category = "DATA_EXFILTRATION" or security_result.category = "DATA_DESTRUCTION")

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Akses Data Uni Eropa dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Action = security_result.action

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Kebijakan Teratas yang Dilanggar
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")
security_result.rule_name = /Policy/ nocase

$Policy = security_result.rule_name
$Policy != ""
$Target_EU_Country = strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)

match:
  $Policy, $Target_EU_Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akses Tidak Sah ke Resource Uni Eropa
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Action = security_result.action
$Action != "ALLOW"
$Summary = strings.coalesce(security_result.summary, metadata.description, security_result.description)
$Severity = security_result.severity

match:
  $Summary, $User, $Source_IP ,$Action , $Severity, $Hostname

outcome :
  $Count  = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))

order:
   $Count desc
Akses ke Resource Uni Eropa dari Negara Non-Uni Eropa
(strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase
and strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name) != /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase)

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$Source_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)
$Target_EU_Country = strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)
$Target_EU_Resource = strings.coalesce(target.resource.name, target.file.full_path, target.resource.product_object_id, target.group.product_object_id, target.user.group_identifiers)
$Event_Type = metadata.event_type
$Description = strings.coalesce(metadata.description,security_result.description,security_result.summary,metadata.product_event_type)
$HTTP_Method = network.http.method
$Log_Type = metadata.log_type
$Action = security_result.action
$User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses)
$Source_Country != ""

match:
  $User, $Description, $Event_Type,  $Log_Type, $Source_Country, $Target_EU_Resource, $Target_EU_Country, $HTTP_Method, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))

order:
  $Count desc
10 Negara Non-Uni Eropa Teratas yang Mengakses Data Uni Eropa
(strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase
and strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name) != /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase)

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$Source_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)
$Log_Type = metadata.log_type
$Source_Country != ""

match:
  $Source_Country, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akses Istimewa ke Resource Uni Eropa dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT" OR metadata.event_type ="USER_LOGIN" or metadata.event_type = "USER_CHANGE_PERMISSIONS")

$User = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses)
($User = /admin|root|svc|adm|privilege/ nocase or principal.user.attribute.roles.type = "SERVICE_ACCOUNT" or principal.user.attribute.roles.type = "ADMINISTRATOR" or principal.user.account_type = "DOMAIN_ACCOUNT_TYPE" or principal.user.account_type = "SERVICE_ACCOUNT_TYPE")
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Target_EU_Country = strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name)

match:
   $Target_EU_Country, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Deteksi Ancaman dari Waktu ke Waktu
strings.coalesce(target.location.country_or_region, target.ip_geo_artifact.location.country_or_region, target.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.event_type = "GENERIC_EVENT")

$Threat_Name = security_result.threat_name
$Threat_Name != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Threat_Name, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Akses Data Sensitif
strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name) = /Austria|Belgium|Bulgaria|Croatia|Cyprus|Czechia|Denmark|Estonia|Finland|France|Germany|Greece|Hungary|Ireland|Italy|Latvia|Lithuania|Luxembourg|Malta|Netherlands|Poland|Portugal|Romania|Slovakia|Slovenia|Spain|Sweden|eu-(west-1|west-3|central-1|north-1|south-1|south-2)|europe-(west1|west3|west4|west8|west9|west10|west12|central2|north1|north2|southwest1)|austriaeast|denmarkeast|francecentral|germanywestcentral|greececentral|italynorth|northeurope|spaincentral|swedencentral|westeurope|polandcentral/ nocase

(metadata.event_type = "RESOURCE_READ" OR metadata.event_type = "RESOURCE_WRITTEN" OR metadata.event_type = "RESOURCE_CREATION" OR metadata.event_type = "RESOURCE_DELETION" OR metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" OR metadata.event_type = "FILE_UNCATEGORIZED" OR metadata.event_type = "FILE_CREATION" OR metadata.event_type = "FILE_DELETION" OR metadata.event_type = "FILE_MODIFICATION" OR metadata.event_type = "FILE_READ" OR metadata.event_type = "FILE_COPY" OR metadata.event_type = "FILE_OPEN" OR metadata.event_type = "FILE_MOVE" OR metadata.event_type = "FILE_SYNC" OR metadata.event_type = "EVENTTYPE_UNSPECIFIED" OR metadata.event_type = "SETTING_UNCATEGORIZED" OR metadata.event_type = "USER_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" OR metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE" OR metadata.event_type = "USER_RESOURCE_CREATION" OR metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT" OR metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" OR metadata.event_type = "USER_RESOURCE_ACCESS" OR metadata.event_type = "USER_RESOURCE_DELETION" OR metadata.log_type = "GENERIC_EVENT" OR metadata.event_type ="USER_LOGIN" or metadata.log_type = "USER_CHANGE_PERMISSIONS")

(metadata.product_event_type = /SENSITIVE/ nocase OR security_result.rule_name = /SENSITIVE/ nocase OR metadata.description = /SENSITIVE/ nocase OR security_result.summary = /SENSITIVE/ nocase OR                      security_result.description = /SENSITIVE/ nocase)

$Description = strings.coalesce(security_result.summary, security_result.description,metadata.description)
$Source_User = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$Target_User = strings.coalesce(target.user.userid,target.user.user_display_name,target.user.email_addresses)
$Source_Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region, principal.location.name)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Destination_IP = strings.coalesce(target.ip, target.asset.ip)
$Protocol = network.application_protocol
$Action = security_result.action
$Log_Type = metadata.log_type

match:
   $Description,$Source_User, $Target_User, $Source_IP,$Source_Country, $Destination_IP ,$Protocol , $Log_Type, $Action
outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))

order:
   $Count desc  

Pemberitahuan Google Workspace

Dasbor ini memberikan ringkasan peristiwa keamanan dan potensi ancaman, melacak tren dan notifikasi penting terkait aktivitas pengguna dari workspace.

Nama diagram Contoh kueri
10 Peringatan Tingkat Keparahan Tinggi Teratas
metadata.log_type = "WORKSPACE_ALERTS"
security_result.severity = "HIGH"
security_result.summary != ""

$Alert = security_result.summary
$Alert != ""

match:
  $Alert
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
limit:
    10 
10 Pemberitahuan Teratas
metadata.log_type = "WORKSPACE_ALERTS"
security_result.summary != ""

$Alert = security_result.summary
$Alert != ""

match:
  $Alert
outcome:
  $Count = count(security_result.summary)
order:
  $Count desc
limit:
    10 
Pemberitahuan dari Waktu ke Waktu
metadata.log_type = "WORKSPACE_ALERTS"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date
outcome:
  $Count = count(metadata.id)
order:
  $Date desc
Detail Pemberitahuan Terbaru
metadata.log_type = "WORKSPACE_ALERTS"

$Alert = security_result.summary
$Category_Details = security_result.category_details
$Category = security_result.category
$Severity = security_result.severity
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Alert, $Category, $Category_Details, $Severity
outcome:
  $Count = count(metadata.id)
order:
  $Date desc
limit:
    50 
Pemberitahuan menurut Tingkat Keparahan
metadata.log_type = "WORKSPACE_ALERTS"

$Severity = security_result.severity

match:
  $Severity
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
10 Pengguna Teratas menurut Jumlah Pemberitahuan
metadata.log_type = "WORKSPACE_ALERTS"
target.user.userid != ""
$User = target.user.userid

match:
  $User
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
limit:
    10 

Google Workspace Drive

Dasbor ini memberikan gambaran menyeluruh tentang aktivitas pengguna dan pengelolaan resource. Laporan ini menyoroti peristiwa keamanan, pengguna, dan pola akses utama di berbagai lokasi, sehingga tim keamanan dapat memastikan kepatuhan dan mengurangi potensi risiko.

Nama diagram Contoh kueri
Ringkasan DLP untuk Peristiwa Download
metadata.product_event_type = "download"
target.resource.attribute.labels.key = "dlp_info"

$DLP_Signature = target.resource.attribute.labels.value
$URL = target.url
$Source_IP = principal.ip
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $DLP_Signature,$User,$Source_IP, $URL

outcome:

  $Storage_Used_in_MB = max(math.round(cast.as_float(additional.fields["storage_usage_in_bytes"])/(1000*1000), 2))
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa yang Didownload dari Waktu ke Waktu
metadata.product_event_type = "download"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date,$User

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Pengguna Teratas dalam Peristiwa Download
metadata.product_event_type = "download"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $User

outcome:

  $Storage_Used_in_MB = sum(math.round(cast.as_float(additional.fields["storage_usage_in_bytes"])/(1000*1000), 2))

order:
  $Storage_Used_in_MB desc

limit:
    10
Peristiwa Penghapusan Resource dari Waktu ke Waktu
(metadata.event_type = "RESOURCE_DELETION" or metadata.event_type = "USER_RESOURCE_DELETION")
(metadata.product_event_type = "trash" or metadata.product_event_type = "delete")

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date,$User

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Acara Teratas
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Security_Event_Type,$User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pembuatan Resource dari Waktu ke Waktu
(metadata.event_type  = "RESOURCE_CREATION" or metadata.event_type  = "USER_RESOURCE_CREATION")
metadata.product_event_type = "create"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Date,$User

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Lokasi Teratas
$Location = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region)

match:
  $Location

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Ringkasan Geolocation Sumber
(metadata.event_type = "USER_RESOURCE_ACCESS" or metadata.event_type = "RESOURCE_READ" or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT")

$Country = principal.ip_geo_artifact.location.country_or_region
$Country !=""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

order:
  $Count desc
Ringkasan DLP untuk Peristiwa Upload
metadata.product_event_type = "upload"
target.resource.attribute.labels.key = "dlp_info"

$DLP_Signature = target.resource.attribute.labels.value
$URL = target.url
$Source_IP = principal.ip
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $DLP_Signature,$User,$Source_IP, $URL

outcome:

  $Storage_Used_in_MB = max(math.round(cast.as_float(additional.fields["storage_usage_in_bytes"])/(1000*1000), 2))
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa dari Waktu ke Waktu menurut Tindakan
$Security_Event_Type = metadata.product_event_type
$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date ,$Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc

10 Resource yang Paling Sering Diakses
(metadata.event_type  = "USER_RESOURCE_ACCESS" or  metadata.event_type  = "RESOURCE_READ" or  metadata.event_type  = "USER_RESOURCE_UPDATE_CONTENT")

$Security_Event_Type = metadata.product_event_type
$Resource_Id = target.resource.product_object_id
$Resource_Id != ""
$Source_User = strings.coalesce(principal.user.email_addresses, principal.user.userid, principal.user.user_display_name)
$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Action = security_result.action

match:
  $Resource_Id,$Source_User,$Source_IP ,$Security_Event_Type, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas dalam Peristiwa Upload
metadata.product_event_type = "upload"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $User

outcome:

  $Storage_Used_in_MB = sum(math.round(cast.as_float(additional.fields["storage_usage_in_bytes"])/(1000*1000), 2))

order:
  $Storage_Used_in_MB desc

limit:
    10
10 Pengguna Teratas
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Action = security_result.action

match:
  $User, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Pengelolaan Identitas Google Workspace

Dasbor ini memberikan ringkasan aktivitas pengguna dan grup, yang menawarkan insight tentang pola login, modifikasi, dan perubahan izin, sekaligus melacak tren dari waktu ke waktu.

Nama diagram Contoh kueri
Peristiwa Modifikasi Grup dari Waktu ke Waktu
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = /modify_group/ nocase

$Event = metadata.product_event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa Penghapusan Pengguna dari Waktu ke Waktu
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = /delete_user/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(target.user.email_addresses)

order:
  $Count desc
Peristiwa Perubahan Izin dari Waktu ke Waktu
metadata.log_type  = "WORKSPACE_ACTIVITY"
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"

$Permission = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Permission, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Login Berhasil vs. Gagal
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = "LOGIN_SUCCESS"
or metadata.product_event_type = "LOGIN_FAILURE"

$User_Login = metadata.product_event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $User_Login

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Admin Teratas yang Menangani Tugas Pengelolaan
metadata.log_type = "WORKSPACE_ACTIVITY"
target.application = /admin/ nocase

$Event = metadata.event_type
$Admin = principal.user.email_addresses

match:
  $Admin, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Tren 10 Teratas Login Pengguna yang Gagal
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = "LOGIN_FAILURE"
principal.user.email_addresses != ""

$User_Account = principal.user.email_addresses
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
  $User_Account, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pembuatan Pengguna dari Waktu ke Waktu
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = /create_user/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(target.user.email_addresses)

order:
  $Count desc
Tren 10 Login Pengguna Berhasil Teratas
metadata.log_type = "WORKSPACE_ACTIVITY"
metadata.product_event_type = "LOGIN_SUCCESS"
principal.user.email_addresses != ""

$User_Account = principal.user.email_addresses
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $User_Account, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Ringkasan Aktivitas Grup

Dasbor ini memberikan tampilan mendetail tentang interaksi pengguna dan grup, melacak pengguna, grup, dan perubahan keanggotaan yang berbeda. Fitur ini menyoroti pengguna dan grup yang paling aktif, perubahan grup, dan memantau tren aktivitas grup.

Nama diagram Contoh kueri
Grup yang Dibuat dari Waktu ke Waktu
metadata.event_type = "GROUP_CREATION"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Host Teratas menurut Peristiwa Pengelolaan Grup
metadata.event_type = "GROUP_UNCATEGORIZED"
or metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "GROUP_MODIFICATION"

$Hostname = principal.hostname
$Hostname != ""
$Event_Type = metadata.event_type

match:
  $Hostname, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Grup Dibuat
metadata.event_type = "GROUP_CREATION"

outcome:
  $Count = count_distinct(target.group.group_display_name)
Pengguna Dihapus dari Grup
$event.metadata.product_event_type = /4733|4729|4757/
or $event.metadata.product_event_type = /remove.*(?:user|member).*(?:from|to).*group/ nocase

$Initiator = strings.coalesce($event.principal.user.windows_sid, $event.principal.user.userid)
$AffectedUser = strings.coalesce($event.target.user.windows_sid, $event.target.user.userid)
$Group = $event.target.group.group_display_name
$Description = strings.coalesce($event.metadata.description, $event.security_result.summary)

match:
  $Initiator, $Group, $AffectedUser, $Description
outcome:
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50
Grup Terbaru Dihapus
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Group = target.group.group_display_name
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Group

order:
  $Date desc
Peristiwa Grup yang Diblokir dari Waktu ke Waktu
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "BLOCK"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
Pengguna Ditambahkan ke Grup Admin
metadata.product_event_type = /4732|4728|4756/
or metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

$Initiator = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.windows_sid, target.user.userid, re.capture(additional.fields["Message"], `Account Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Affected_User = strings.coalesce(re.capture(additional.fields["Message"], `Member Name:(?:\W?)([A-Za-z0-9._%+-]+)`), re.capture(security_result.description, `\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]+`), target.user.user_display_name, target.user.userid, target.user.windows_sid)
$Group = strings.coalesce(target.group.group_display_name, re.capture(security_result.description, `group\W([A-Za-z0-9._%+-]+\W+[A-Za-z0-9._%+-]+)`), re.capture(additional.fields["Message"], `Group Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Group = /admin/ nocase
$Description = strings.coalesce(metadata.description, security_result.summary)
$Date = timestamp.get_timestamp((metadata.event_timestamp.seconds))

match:
  $Date, $Initiator, $Group, $Affected_User, $Description

order:
  $Date desc
Pengguna yang Baru-Baru Ini Dihapus dari Grup
metadata.product_event_type = /4733|4729|4757/
or metadata.product_event_type = /remove.*(?:user|member).*(?:from|to).*group/ nocase

$Initiator = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.windows_sid, target.user.userid, re.capture(additional.fields["Message"], `Account Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Affected_User = strings.coalesce(re.capture(additional.fields["Message"], `Member Name:(?:\W?)([A-Za-z0-9._%+-]+)`), re.capture(security_result.description, `\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]+`), target.user.user_display_name, target.user.userid, target.user.windows_sid)
$Group = strings.coalesce(target.group.group_display_name, re.capture(security_result.description, `group\W([A-Za-z0-9._%+-]+\W+[A-Za-z0-9._%+-]+)`), re.capture(additional.fields["Message"], `Group Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Description = strings.coalesce(metadata.description, security_result.summary)
$Date = timestamp.get_timestamp((metadata.event_timestamp.seconds))

match:
  $Date, $Initiator, $Group, $Affected_User, $Description

order:
  $Date desc
Jumlah Aktivitas Perubahan Grup
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "GROUP_MODIFICATION"

outcome:
  $Count = count(metadata.id)
10 Pengguna Teratas yang Diblokir dalam Acara Grup
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Event_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Grup Dihapus
$event.metadata.event_type = "GROUP_DELETION"

outcome:
  $Count = count_distinct($event.target.group.group_display_name)
Grup yang Baru Dibuat
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Group = target.group.group_display_name
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Group

order:
  $Date desc 
10 Host Aktif Teratas
$event.metadata.event_type = "GROUP_UNCATEGORIZED"
or $event.metadata.event_type = "GROUP_CREATION"
or $event.metadata.event_type = "GROUP_DELETION"
or $event.metadata.event_type = "GROUP_MODIFICATION"

$Hostname = $event.principal.hostname
$Hostname != ""
$Event_Type = $event.metadata.event_type
$Log_type = $event.metadata.log_type

match:
  $Hostname, $Event_Type, $Log_type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
10 Pengguna Teratas yang Menghapus Grup
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Tindakan Grup Teratas
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "GROUP_MODIFICATION"

$Description = strings.coalesce(metadata.description, security_result.summary)
$Description != ""

match:
  $Description

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas menurut Peristiwa Login
metadata.event_type = "USER_LOGIN"

$User = strings.concat(target.user.userid, " ")
$User !=  " "

match:
  $User

outcome:
  $Count = count(target.user.userid)

order:
  $Count desc

limit:
    10
Jumlah Pengguna yang Ditambahkan ke Grup
$event.metadata.event_type = "GROUP_MODIFICATION"
$event.metadata.product_event_type = /4720|4728|4732|4746|4751|4756|4761|4785/
or $event.metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

outcome:
  $Count = count($event.metadata.id)
10 IP Sumber yang Diblokir Teratas dalam Peristiwa Grup
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$IP_Address = principal.ip

match:
  $Event_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pengguna Unik dalam Peristiwa Login
metadata.event_type = "USER_LOGIN"

outcome:
  $Count = count_distinct(principal.user.userid)
10 IP Sumber Teratas yang Mengubah Grup
metadata.event_type = "GROUP_MODIFICATION"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Total Pengguna yang Ditambahkan ke Grup Admin
metadata.product_event_type = /4732|4728|4756/
or metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

$Group = strings.coalesce(target.group.group_display_name, re.capture(security_result.description, `group\W([A-Za-z0-9._%+-]+\W+[A-Za-z0-9._%+-]+)`), re.capture(additional.fields["Message"], `Group Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Group = /admin/ nocase

outcome:
  $Count = count(metadata.id)
Aktivitas Grup dari Waktu ke Waktu
$event.metadata.event_type = "GROUP_CREATION"
or $event.metadata.event_type = "GROUP_DELETION"
or $event.metadata.event_type = "GROUP_MODIFICATION"
or $event.metadata.event_type = "GROUP_UNCATEGORIZED"

$User = $event.target.user.windows_sid
$Hostname = $event.principal.hostname
$Group = $event.target.group.group_display_name
$Event = $event.metadata.event_type
$Action = $event.metadata.description
$Action != "A security-enabled local group membership was enumerated"

match:
  $Event, $User, $Hostname, $Group, $Action
outcome:
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50
Grup Baru Ditambahkan
$event.metadata.event_type = "GROUP_CREATION"

outcome:
  $Count = count_distinct($event.target.group.group_display_name)
Grup Dihapus
metadata.event_type = "GROUP_DELETION"

outcome:
  $Count = count_distinct(target.group.group_display_name)
Pengguna yang Baru Ditambahkan ke Grup
metadata.product_event_type = /4732|4728|4756/
or metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

$Initiator = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.windows_sid, target.user.userid, re.capture(additional.fields["Message"], `Account Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Affected_User = strings.coalesce(re.capture(additional.fields["Message"], `Member Name:(?:\W?)([A-Za-z0-9._%+-]+)`), re.capture(security_result.description, `\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]+`), target.user.user_display_name, target.user.userid, target.user.windows_sid)
$Group = strings.coalesce(target.group.group_display_name, re.capture(security_result.description, `group\W([A-Za-z0-9._%+-]+\W+[A-Za-z0-9._%+-]+)`), re.capture(additional.fields["Message"], `Group Name:(?:\W?)([A-Za-z0-9._%+-]+)`))
$Description = strings.coalesce(metadata.description, security_result.summary)
$Date = timestamp.get_timestamp((metadata.event_timestamp.seconds))

match:
  $Date, $Initiator, $Group, $Affected_User, $Description

order:
  $Date desc
Grup yang Diubah dari Waktu ke Waktu
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Grup yang Baru Diubah
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Event = metadata.product_event_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$Group = target.group.group_display_name
$Description = strings.coalesce(metadata.description, security_result.summary)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User, $Group, $Event, $Description

order:
  $Date desc
Pengguna Dihapus dari Grup
metadata.event_type = "GROUP_MODIFICATION"
metadata.product_event_type = /4729|4733|4747|4752|4757|4762|4786/
or metadata.product_event_type = /remove.*(?:user|member).*to.*group/ nocase

outcome:
  $Count = count(metadata.id)
    
10 Pengguna Teratas yang Membuat Grup
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Grup
metadata.event_type = "GROUP_MODIFICATION"

$Log_Type = metadata.log_type
$User = principal.user.userid

match:
  $User, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pengguna Ditambahkan ke Grup Admin
$event.metadata.product_event_type = /4732|4728|4756/
or $event.metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

$Initiator = strings.coalesce($event.principal.user.windows_sid, $event.principal.user.userid)
$User = strings.coalesce($event.target.user.windows_sid, $event.target.user.userid)
$Group = $event.target.group.group_display_name
$Group = /admin/ nocase
$Description = strings.coalesce($event.metadata.description, $event.security_result.summary)

match:
  $Initiator, $User, $Group, $Description
outcome:
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50
Jumlah Aktivitas Perubahan Grup
$event.metadata.event_type = "GROUP_CREATION"
or $event.metadata.event_type = "GROUP_DELETION"
or $event.metadata.event_type = "GROUP_MODIFICATION"

outcome:
  $Count = count($event.metadata.id)
Pengguna yang Ditambahkan ke Grup
metadata.event_type = "GROUP_MODIFICATION"
metadata.product_event_type = /4720|4728|4732|4746|4751|4756|4761|4785/
or metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

outcome:
  $Count = count(metadata.id)
10 Tindakan Grup Teratas
$event.metadata.event_type = "GROUP_CREATION"
or $event.metadata.event_type = "GROUP_DELETION"
or $event.metadata.event_type = "GROUP_MODIFICATION"

$Description = strings.coalesce($event.metadata.description, $event.security_result.summary)
$Group_Name = $event.target.group.group_display_name

match:
  $Description, $Group_Name
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 IP Sumber Teratas yang Menghapus Grup
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Jumlah Login Pengguna Unik
$event.metadata.event_type = "USER_LOGIN"

outcome:
  $Count = count_distinct($event.principal.user.userid)
10 IP Sumber Teratas yang Membuat Grup
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Grup Aktif Teratas
$event.metadata.event_type = "GROUP_UNCATEGORIZED"
or $event.metadata.event_type = "GROUP_CREATION"
or $event.metadata.event_type = "GROUP_DELETION"
or $event.metadata.event_type = "GROUP_MODIFICATION"

$Log_Type = $event.metadata.log_type
$Event = $event.metadata.event_type
$Group_Name = $event.target.group.group_display_name
$Group_Name != ""

match:
  $Group_Name, $Event, $Log_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Jumlah Pengguna yang Dihapus dari Grup
$event.metadata.event_type = "GROUP_MODIFICATION"
$event.metadata.product_event_type = /4729|4733|4747|4752|4757|4762|4786/
or $event.metadata.product_event_type = /remove.*(?:user|member).*to.*group/ nocase

outcome:
  $Count = count($event.metadata.id)
    
Grup yang Dihapus dari Waktu ke Waktu
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Grup Teratas menurut Jumlah Peristiwa
metadata.event_type = "GROUP_UNCATEGORIZED"
or metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "GROUP_MODIFICATION"

$Event_Type = metadata.event_type
$Group_Name = target.group.group_display_name
$Group_Name != ""

match:
  $Group_Name, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Login Pengguna Aktif Teratas
$event.metadata.event_type = "USER_LOGIN"

$Event_Type = $event.metadata.event_type
$User = strings.concat($event.target.user.userid, " ")
$User != " "
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $User, $Event_Type, $Date over every day
outcome:
  $Count = count($event.target.user.userid)
order:
  $Date desc, $Count desc
limit:
    10
Pengguna yang Ditambahkan ke Grup
$event.metadata.product_event_type = /4732|4728|4756/
or $event.metadata.product_event_type = /add.*(?:user|member).*to.*group/ nocase

$Initiator = strings.coalesce($event.principal.user.windows_sid, $event.principal.user.userid)
$AffectedUser = strings.coalesce($event.target.user.windows_sid, $event.target.user.userid)
$Group = $event.target.group.group_display_name
$Description = strings.coalesce($event.metadata.description, $event.security_result.summary)

match:
  $Initiator, $Group, $AffectedUser, $Description
outcome:
  $Date = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Date desc
limit:
    50

Audit Pengelolaan Grup

Dasbor ini adalah dasbor khusus untuk mengaudit seluruh siklus proses grup pengguna. Hal ini membantu memastikan bahwa pembuatan, modifikasi, dan penghapusan grup dikelola dengan benar, sehingga mencegah hak akses yang tidak diinginkan dalam skala besar.

Nama diagram Contoh kueri
10 Pengguna Teratas yang Membuat Grup
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas yang Membuat Grup
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Grup
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Modifikasi Grup Terbaru
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Event = metadata.product_event_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$Group = target.group.group_display_name
$Description = strings.coalesce(metadata.description, security_result.summary)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User, $Group, $Event, $Description

order:
  $Date desc
Total Grup Unik yang Diubah
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(target.group.group_display_name)
Grup yang Dihapus dari Waktu ke Waktu
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Grup yang Dibuat dari Waktu ke Waktu
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Grup yang Diubah dari Waktu ke Waktu
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Acara Kelompok dari Waktu ke Waktu
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /(?:add|create|delete)(?:\s)?group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Event = metadata.event_type

match:
  $Date, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 IP Sumber Teratas yang Menghapus Grup
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Total Grup Unik yang Dibuat
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(target.group.group_display_name)
Penghapusan Grup Terbaru
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Group = target.group.group_display_name
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Group

order:
  $Date desc
10 IP Sumber Teratas yang Mengubah Grup
metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Diblokir dalam Acara Grup
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Event_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Menghapus Grup
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pembuatan Grup Terbaru
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /(?:add|create)(?:\s)?group/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Group = target.group.group_display_name
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Group

order:
  $Date desc 
10 IP Sumber yang Diblokir Teratas dalam Peristiwa Grup
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$IP_Address = principal.ip

match:
  $Event_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Total Grup Unik yang Dihapus
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete group/ nocase
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(target.group.group_display_name)

Dasbor HIPAA

Dasbor ini menyediakan pemantauan real-time terhadap metrik keamanan dan kepatuhan untuk memastikan kepatuhan terhadap peraturan HIPAA. Layanan ini memberikan visibilitas terhadap potensi risiko, pelanggaran, dan aktivitas akses data yang melibatkan Informasi Kesehatan Terlindungi (PHI). Hal ini memungkinkan pengelolaan risiko proaktif dan membantu menjaga kerahasiaan, integritas, dan ketersediaan data kesehatan sensitif. Dasbor ini menggunakan tabel data ePHI_assets.Hostname untuk mencakup data sesuai dengan standar HIPAA. Diagram di dasbor ini tidak dimuat hingga tabel data yang diperlukan dibuat.

Nama diagram Contoh kueri
Kerentanan menurut Tingkat Keparahan
metadata.log_type = /ARMIS_VULNERABILITIES|FINGERPRINT_JS|NUCLEUS_VULNERABILITY|QUALYS_ASSET_CONTEXT|QUALYS_SCAN|QUALYS_VIRTUAL_SCANNER|QUALYS_VM|RAPID7_INSIGHT|RAPID7_NEXPOSE|SNYK_SDLC|SPUR_FEEDS|STACKHAWK|SUBLIMESECURITY|SYMANTEC_SA|TENABLE_IO|TENABLE_OT|TENABLE_SC|TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES|UPGUARD|URLSCAN_IO/ nocase
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Severity =
    if (principal.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        principal.asset.vulnerabilities.severity,
    if (target.asset.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        target.asset.vulnerabilities.severity,
    if (extensions.vulns.vulnerabilities.severity != "UNKNOWN_SEVERITY",
        extensions.vulns.vulnerabilities.severity,
    "UNKNOWN_SEVERITY")))

match:
  $Severity

outcome:
  $Count = count(strings.coalesce(extensions.vulns.vulnerabilities.name, extensions.vulns.vulnerabilities.description, extensions.vulns.vulnerabilities.vendor_vulnerability_id,
                                          principal.asset.vulnerabilities.name, target.asset.vulnerabilities.name, additional.fields["ScanReference"]))

order:
  $Severity desc
Perubahan Izin dari Waktu ke Waktu menurut Jenis Log
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa MFA dari Waktu ke Waktu menurut Tindakan
(re.regex(metadata.product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex(additional.fields["AuthenticationRequirement"], `multiFactorAuthentication`) nocase or re.regex(security_result.detection_fields.value, `MFA`) nocase )
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname,target.asset.hostname) in %ePHI_assets.Hostname

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Login dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "USER_LOGIN"
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Host ePHI Teratas menurut Pelanggaran DLP
metadata.log_type = /DLP|ACCELLION|CODE42_INCYDR|GUARDIUM|TRIPWIRE_FIM/ nocase
metadata.product_event_type = /Violation/ nocase
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Severity = security_result.severity
$Hostname= strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)

match:
  $Hostname, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pemberitahuan EDR dari Waktu ke Waktu menurut Tingkat Keparahan
metadata.log_type = /EDR|CS_ALERTS|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce(security_result.rule_name, security_result.threat_name) != ""
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Severity = security_result.severity
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Pencadangan dari Waktu ke Waktu menurut Tindakan
(metadata.log_type = /COHESITY|DRUVA_BACKUP|VEEAM|VERITAS_NETBACKUP/ nocase or metadata.log_type = "RUBRIK")
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Action = security_result.action

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Perubahan Sandi dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "USER_CHANGE_PASSWORD"
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Log_Type = metadata.log_type
$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match :
  $Date, $Action

outcome :
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Pencadangan Terbaru (24 Jam Terakhir)
(metadata.log_type = /COHESITY|DRUVA_BACKUP|VEEAM|VERITAS_NETBACKUP/ nocase or metadata.log_type = "RUBRIK")
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Description = strings.coalesce(metadata.description, security_result.description, security_result.summary)
$Log_Type = metadata.log_type
$Event_Type = metadata.event_type
$Security_Event_Type = metadata.product_event_type
$Action = security_result.action

match:
  $Description, $Security_Event_Type, $Event_Type, $Action, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")

order:
  $Date desc
Pemberitahuan EDR Terbaru (24 Jam Terakhir)
metadata.log_type = /EDR|CS_ALERTS|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Log_Type = metadata.log_type
$EDR_Alerts = strings.coalesce(security_result.rule_name, security_result.threat_name)
$EDR_Alerts != ""
$Severity = security_result.severity
$User = strings.coalesce(principal.user.user_display_name, principal.user.email_addresses, principal.user.userid, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)

match:
  $EDR_Alerts, $Hostname, $User, $Severity, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Date desc
Pembuatan Akun Pengguna Terbaru (24 Jam Terakhir)
metadata.event_type = "USER_CREATION"
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Log_Type = metadata.log_type
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Initiator = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$User_Created = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Action = security_result.action

match:
  $Initiator, $User_Created, $Source_Hostname, $Source_IP, $Action, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")

order:
  $Date desc
Komunikasi Terenkripsi Lemah dari Waktu ke Waktu menurut Jenis Log
(((target.resource.attribute.labels.key  = "keyProperties_type" or target.resource.attribute.labels.key  = "requestParameters.keySpec" or target.resource.attribute.labels.key = /key/ nocase) and target.resource.attribute.labels.value  = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/) or network.tls.cipher = /^(RSA-)|DES|RC4|MD5|SHA1|SHA-1/)
strings.coalesce(principal.hostname, principal.asset.hostname,  target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Perubahan Sandi Pengguna Baru-Baru Ini (24 Jam Terakhir)
metadata.event_type = "USER_CHANGE_PASSWORD"
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Log_Type = metadata.log_type
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Action = security_result.action

match :
  $User, $Source_Hostname, $Source_IP, $Security_Event_Type, $Action, $Log_Type

outcome :
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")
  $Count = count(metadata.id)

order :
  $Date desc

10 Aplikasi SaaS Teratas
strings.coalesce(security_result.category_details, security_result.rule_name) = /saas/ nocase
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Application = target.application
$Log_Type = metadata.log_type

match:
   $Application, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Operasi Utama Teratas
(metadata.log_type  = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT|GCP_CLOUDAUDIT/ or target.application = "kms.amazonaws.com")
strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname) in %ePHI_assets.Hostname

$Security_Event_Type = metadata.product_event_type
$Log_Type = strings.coalesce(metadata.log_type, target.application)

match:
  $Security_Event_Type, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Investigasi Host

Dasbor ini memberikan ringkasan komprehensif tentang aktivitas host dan peristiwa keamanan. Widget utama melacak komunikasi jaringan, perubahan autentikasi, malware, peristiwa teratas, dan proses yang jarang terjadi. Layanan ini juga memantau pembuatan layanan dan tugas terjadwal, serta potensi ancaman keamanan.

Nama diagram Contoh kueri
10 Acara Teratas
$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Event_Type,$User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Tren Peristiwa dari Waktu ke Waktu
$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Malware dan Penyusupan
$Log_Type = metadata.log_type
$Category = security_result.category
($Category = "UNKNOWN_CATEGORY" or $Category = "SOFTWARE_MALICIOUS" or $Category = "SOFTWARE_SUSPICIOUS" or $Category = "SOFTWARE_PUA" or $Category = "NETWORK_MALICIOUS"or $Category = "NETWORK_SUSPICIOUS" or $Category = "NETWORK_CATEGORIZED_CONTENT" or $Category = "NETWORK_DENIAL_OF_SERVICE" or $Category = "NETWORK_RECON" or $Category = "NETWORK_COMMAND_AND_CONTROL" or $Category = "ACL_VIOLATION" or $Category = "AUTH_VIOLATION" or $Category = "EXPLOIT" or $Category = "DATA_EXFILTRATION" or $Category = "DATA_AT_REST" or $Category = "DATA_DESTRUCTION" or $Category = "TOR_EXIT_NODE" or $Category = "MAIL_SPAM" or $Category = "MAIL_PHISHING" or $Category = "MAIL_SPOOFING" or $Category = "POLICY_VIOLATION" or $Category = "SOCIAL_ENGINEERING" or $Category = "PHISHING")
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,intermediary.hostname,target.hostname,target.asset.hostname)
$Hostname !=""
$Description = strings.coalesce(metadata.description,security_result.summary)
$Action = security_result.action
$File_Path = target.file.full_path

match:
$Hostname, $Log_Type, $Category, $Description, $Action,$File_Path

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peta Keluar Komunikasi Jaringan
(metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP")
network.direction = "OUTBOUND"

$Hostname = strings.coalesce(principal.hostname, intermediary.hostname, observer.hostname, principal.asset.hostname, principal.asset.ip)
$Country = target.ip_geo_artifact.location.country_or_region

match:
  $Country

outcome:
  $Latitude = max(target.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(target.ip_geo_artifact.location.region_coordinates.longitude)
  $Count = count(metadata.id)
Proses Langka
(metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD")

$Process_Name = strings.coalesce(if(principal.application != "", principal.application, ""), if(re.capture(target.process.file.full_path, `.*\\(\S+\.\w+)`) != "", re.capture(target.process.file.full_path, `.*\\(\S+\.\w+)`), ""))
$Process_Name != ""
$Severity = security_result.severity
$Action = security_result.action
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Process_Name,$User,$Severity,$Action

outcome:
  $Count = count(metadata.id)

order:
  $Count asc
Pembuatan Layanan
(metadata.event_type = "SERVICE_CREATION" or metadata.event_type = "SERVICE_UNSPECIFIED")

$Username = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,intermediary.hostname,target.hostname,target.asset.hostname)
$Application = target.application
$Path = target.process.file.full_path

match:
  $Hostname, $Application, $Username, $Path

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Komunikasi Jaringan
(metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP")

$Source_Port = principal.port
$Destination_Port = target.port
$Source_IP = principal.ip
$Destination_IP = target.ip
$Direction = network.direction
$Direction != "UNKNOWN_DIRECTION"
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,intermediary.hostname,target.hostname,target.asset.hostname)
$Hostname != ""
$Bytes_Sent = network.sent_bytes
$Bytes_Received = network.received_bytes

match:
$Hostname, $Source_IP, $Source_Port, $Direction, $Destination_IP, $Destination_Port,$Bytes_Sent,$Bytes_Received

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Autentikasi dan Perubahan
$Event_Type = metadata.event_type
($Event_Type = "USER_LOGIN" or $Event_Type = "USER_LOGOUT" or $Event_Type = "USER_BADGE_IN" or $Event_Type= "USER_CHANGE_PASSWORD" or $Event_Type = "USER_CHANGE_PERMISSIONS" or $Event_Type = "USER_CREATION" or $Event_Type = "USER_DELETION" or $Event_Type = "USER_RESOURCE_CREATION" or $Event_Type = "USER_RESOURCE_DELETION" or $Event_Type= "USER_RESOURCE_UPDATE_CONTENT" or $Event_Type = "USER_RESOURCE_UPDATE_PERMISSIONS" or $Event_Type = "SERVICE_CREATION" or $Event_Type = "SERVICE_DELETION" or $Event_Type = "SERVICE_MODIFICATION" or $Event_Type = "SETTING_CREATION" or $Event_Type = "SETTING_DELETION" or $Event_Type = "SETTING_MODIFICATION" or $Event_Type = "DEVICE_CONFIG_UPDATE")
$Log_Type = metadata.log_type
$Security_Event_Type = metadata.product_event_type
$Description = strings.coalesce(metadata.description,security_result.description)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,intermediary.hostname,target.hostname,target.asset.hostname)
$Hostname !=""
$Action = security_result.action

match:
  $Hostname, $Log_Type, $Event_Type,$Security_Event_Type, $Description, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Peta Masuk Komunikasi Jaringan
(metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP")
network.direction = "INBOUND"

$Country = principal.ip_geo_artifact.location.country_or_region

match:
  $Country

outcome:
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)
  $Count = count(metadata.id)
Pembuatan Tugas Terjadwal
metadata.event_type = "SCHEDULED_TASK_CREATION"

$Username = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,intermediary.hostname,target.hostname,target.asset.hostname)
$Task_Name = target.resource.name

match:
$Hostname, $Task_Name, $Username

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

Operasi Keamanan IAM

Dasbor ini adalah ringkasan umum untuk pemantauan harian. Solusi ini berfokus pada anomali real-time, ancaman aktif, dan peristiwa berisiko tinggi untuk memungkinkan deteksi dan respons insiden yang cepat.

Nama diagram Contoh kueri
Akun Pengguna Baru Dihapus
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$IP_Address = principal.ip

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
Kegagalan & Keberhasilan Login Akun Istimewa
metadata.event_type = "USER_LOGIN"
strings.coalesce(principal.user.attribute.roles.name, principal.resource.name, target.user.attribute.roles.name, target.resource.name) = /admin/ nocase
if(security_result.action = "ALLOW", "Success", if(security_result.action = "BLOCK", "Failed", "Unknown")) != ""

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$User = if(strings.coalesce(principal.user.attribute.roles.name, principal.resource.name) = /admin/ nocase, strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses),
        if(strings.coalesce(target.user.attribute.roles.name, target.resource.name) = /admin/ nocase, strings.coalesce(target.user.windows_sid, target.user.userid, target.user.email_addresses), ""))
$Login_Status = if(security_result.action = "ALLOW", "Success", if(security_result.action = "BLOCK", "Failed", "Unknown"))
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Privilege_Type = principal.user.attribute.roles.name
$Privilege_Type != ""
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)

match:
  $Date, $User, $Login_Status, $Privilege_Type,  $Hostname, $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Total Akun Pengguna Unik yang Diubah
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.userid, target.user.email_addresses))
10 Login Akun Pengguna Teratas
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = target.user.userid

match:
  $Log_Type, $User

outcome:
  $Count = count(target.user.userid)

order:
  $Count desc

limit:
    10  
Peran yang Baru Dihapus
metadata.product_event_type = /\bDelete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$IP_Address = principal.ip
$Role = strings.coalesce(target.user.attribute.roles.name, target.resource.name)

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Role

order:
  $Date desc  
10 IP Sumber yang Diblokir Teratas dalam Peristiwa Pengguna
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$IP_Address = principal.ip

match:
  $Event_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akses Pertama Kali dari Sumber Baru
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$Source_IP = principal.ip
$User = target.user.userid
$Country = principal.location.country_or_region
$City = principal.location.city
$City != ""
$ASN = principal.ip_geo_artifact.network.asn
$ASN != ""

match:
   $Source_IP, $User, $Country, $City, $ASN

outcome:
  $Count = count(metadata.id)
  $FirstTime_Access = earliest(metadata.event_timestamp)

order:
  $FirstTime_Access desc
10 Aplikasi yang Paling Sering Diakses Pengguna
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Application = target.application
$Application != ""

match:
  $Log_Type, $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
KPI Siklus Proses Pengguna
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_DELETION"
or metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"

$User_Action = if(metadata.event_type = "USER_CREATION", "Total Creation", if(metadata.event_type = "USER_DELETION" or metadata.event_type = "USER_RESOURCE_DELETION", "Total Deletion", if(metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE" or metadata.event_type = "USER_CHANGE_PERMISSIONS" or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS", "Total Modification")))

match:
  $User_Action

outcome:
  $Count = count(metadata.id)

order:
  $Count asc
 
10 Pengguna yang Diblokir Teratas di Peristiwa Pengguna
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Event_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perubahan Sandi dari Waktu ke Waktu
metadata.event_type = "USER_CHANGE_PASSWORD"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Pengguna yang Diblokir Teratas dalam Peristiwa Peran
(metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase))
or
(metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase))
or
(metadata.product_event_type = /\bDelete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase))
security_result.action = "BLOCK"

$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$Event = metadata.product_event_type

match:
  $User, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perjalanan yang Mustahil
$first_login.metadata.event_type = "USER_LOGIN"
$first_login.security_result.action = "ALLOW"
$first_login.principal.ip_geo_artifact.location.state != "" and $Country1 = $first_login.principal.ip_geo_artifact.location.state
$Time = timestamp.get_timestamp($first_login.metadata.event_timestamp.seconds, "%F %T ")

$User = strings.coalesce($first_login.target.user.userid, $first_login.target.user.email_addresses)
$User != ""
$Latitude1  =  $first_login.principal.ip_geo_artifact.location.region_coordinates.latitude
$Longitude1 =  $first_login.principal.ip_geo_artifact.location.region_coordinates.longitude

$second_login.metadata.event_type = "USER_LOGIN"
$second_login.security_result.action = "ALLOW"
$second_login.principal.ip_geo_artifact.location.state != "" and $Country2 = $second_login.principal.ip_geo_artifact.location.state
$Time2 = timestamp.get_timestamp($second_login.metadata.event_timestamp.seconds, "%F %T ")

$User = strings.coalesce($second_login.target.user.userid, $second_login.target.user.email_addresses)
$User != ""
$Latitude2  =  $second_login.principal.ip_geo_artifact.location.region_coordinates.latitude
$Longitude2 =  $second_login.principal.ip_geo_artifact.location.region_coordinates.longitude
$first_login.metadata.event_timestamp.seconds < $second_login.metadata.event_timestamp.seconds

($Latitude1 != $Latitude2)
($Longitude1 != $Longitude2)

match:
  $User, $Time, $Country1, $Time2, $Country2 over 1h

outcome:
  $distance_kilometers = math.ceil(max(math.geo_distance($Latitude1, $Longitude1, $Latitude2, $Longitude2)) /1000)

condition:
  $first_login and $second_login and $distance_kilometers != 0
Total Akun Pengguna Unik yang Dihapus
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.userid, target.user.email_addresses))
Total Akun Pengguna Unik yang Dibuat
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.userid, target.user.email_addresses))

Ringkasan Peristiwa IDS / IPS

Dasbor ini memberikan ringkasan komprehensif tentang peristiwa keamanan yang terdeteksi oleh sistem deteksi penyusupan dan pencegahan.

Nama diagram Contoh kueri
Peristiwa IDS / IPS menurut Kategori
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$category = security_result.category
$category != "UNKNOWN_CATEGORY"
match:
$category
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
10 IP Teratas menurut Jumlah Peristiwa
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK" or $event_type = "SCAN_VULN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$source_ip = principal.ip
$rule_name = security_result.rule_name
$rule_name != ""
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$rule_name, $source_ip
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Peristiwa IDS / IPS menurut Tujuan
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK" or $event_type = "SCAN_VULN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$vendor = metadata.vendor_name
$destination_ip = target.ip
$action = security_result.action
$rule_name = security_result.rule_name
$rule_name != ""
$security_event_type = metadata.product_event_type
$security_event_type != ""
$security_event_type != /NetworkSecurityGroupFlowEvents|fileinfo|flow/ nocase
match:
$destination_ip, $rule_name, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Peristiwa IDS / IPS menurut Sumber
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK" or $event_type = "SCAN_VULN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$action = security_result.action
$action != "UNKNOWN_ACTION"
$hostname = principal.hostname
$rule_name = strings.coalesce(security_result.rule_name, metadata.description)
$rule_name != ""
$vendor = metadata.vendor_name
$security_event_type = metadata.product_event_type
$security_event_type != ""
$security_event_type != /NetworkSecurityGroupFlowEvents|fileinfo|flow/ nocase
match:
$hostname, $rule_name, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Peristiwa IDS / IPS Teratas menurut Aturan dan Tindakan
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$rule_name = security_result.rule_name
not $rule_name in %known_signatures
$rule_name != ""
$action = security_result.action
$action != "UNKNOWN_ACTION"
match:
$rule_name, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Peristiwa IDS / IPS dari Waktu ke Waktu menurut Tingkat Keparahan
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$severity = security_result.severity
$severity != "UNKNOWN_SEVERITY"
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$severity, $date
outcome:
$event_count = count(metadata.id)
order:
$date asc
10 Peristiwa IDS / IPS dengan Tingkat Keparahan Tinggi Teratas
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$action = security_result.action
$rule_name = strings.coalesce(security_result.rule_name, metadata.description)
$rule_name != ""
$severity = security_result.severity
$severity = "HIGH"
match:
$rule_name, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Peristiwa IDS / IPS menurut Tanda Tangan
$event_type = metadata.event_type
(($event_type = "SCAN_UNCATEGORIZED" or $event_type = "SCAN_NETWORK") or ($event_type >= 16000 and $event_type <= 16007))
$destination_ip = target.ip
$source_ip = principal.ip
$action = security_result.action
$rule_name = security_result.rule_name
$rule_name != ""
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$rule_name , $source_ip , $destination_ip , $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc

ISO27001 - Kontrol Organisasi

Dasbor ini memberikan visibilitas ke dalam kontrol keamanan organisasi dan performa kepatuhan berdasarkan standar ISO 27001. Solusi ini membantu tim keamanan memantau penerapan kontrol, melacak hasil audit, dan mengidentifikasi area yang perlu ditingkatkan. Dengan memusatkan metrik kepatuhan utama, dasbor ini mendukung keselarasan berkelanjutan dengan persyaratan ISO 27001 dan memperkuat pengelolaan keamanan informasi organisasi secara keseluruhan. Catatan: dasbor ini memerlukan penggunaan filter.

Nama diagram Contoh kueri
Pelanggaran DLP menurut Tingkat Keparahan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary, metadata.description) = /Violation/ nocase

$Severity = security_result.severity
$Severity != "UNKNOWN_SEVERITY"

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Aturan DLP Teratas
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary, metadata.description) = /Violation/ nocase

$Violation = strings.coalesce(security_result.rule_name, metadata.product_event_type, security_result.summary, metadata.description)

match:
  $Violation

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
  10
Pembuatan, Perubahan, dan Penghapusan Peran Terbaru
metadata.product_event_type = /CreateRole|add role definition/ nocase
or metadata.product_event_type = /UpdateRole|update role(?: definition)?/ nocase
or metadata.product_event_type = /DeleteRole|delete role definition/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$Product_Event = metadata.product_event_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Role = strings.coalesce(target.user.attribute.roles.name, target.resource.product_object_id, target.resource.name)

match:
  $Date, $Product_Event, $Source_IP, $Hostname, $Initiator, $Role

order:
  $Date desc
Perubahan Izin Terbaru
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Description = metadata.description

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Description

order:
  $Date desc
Traffic Jaringan yang Diblokir dari Waktu ke Waktu menurut Alasan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.action = "BLOCK"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Reason = security_result.summary

match:
  $Date, $Reason

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa Pengguna dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Event_Type = metadata.event_type

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Aplikasi Teratas yang Diakses
$Log_Type = metadata.log_type
$Application = target.application
$Application != ""

match:
  $Log_Type, $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Keluar Teratas menurut Volume Traffic
network.direction = "OUTBOUND"

$Log_Type = metadata.log_type
$Destination_IP = target.ip

match:
  $Log_Type, $Destination_IP

outcome:
  $Total_Bytes = sum(network.received_bytes + network.sent_bytes)/(1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
Perangkat dari Waktu ke Waktu
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Device = group(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)

match:
  $Date

outcome:
  $Count = count_distinct($Device)

order:
  $Date desc
Perubahan Sandi dari Waktu ke Waktu
metadata.event_type = "USER_CHANGE_PASSWORD"
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc

ISO27001 - Kontrol Fisik

Dasbor ini memusatkan data tentang kepatuhan terhadap kategori keamanan fisik, sehingga tim keamanan dapat melihat efektivitas kontrol dengan jelas. Laporan ini menyajikan metrik utama tentang efikasi kontrol akses dan peristiwa media yang dapat dilepas, yang sangat penting untuk mengidentifikasi kerentanan dengan cepat dan memprioritaskan upaya perbaikan. Dasbor ini memungkinkan pengambilan keputusan berbasis data untuk memitigasi risiko dan terus meningkatkan postur keamanan fisik organisasi Anda sesuai dengan standar ISO 27001.

Nama diagram Contoh kueri
Akses Jarak Jauh menurut Tingkat Keparahan
metadata.event_type = "NETWORK_CONNECTION"
target.port = 22
or target.port = 3389

$Severity = security_result.severity
$Severity != "UNKNOWN_SEVERITY"

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Media Penyimpanan Eksternal Terbaru
strings.coalesce(metadata.product_event_type, security_result.summary) = /\busb\b/ nocase

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$USB_Event = strings.coalesce(metadata.product_event_type, security_result.summary)
$Category = strings.coalesce(security_result.category_details, security_result.detection_fields["Category"])
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Date, $USB_Event, $User, $Hostname, $Source_IP, $Category

order:
  $Date desc
Check-In Badge Pengguna dari Waktu ke Waktu
metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_UNCATEGORIZED"
strings.coalesce(metadata.description, security_result.action_details, security_result.description, security_result.summary, additional.fields["plasectrxEvtypename"]) = /(?:access\sgranted|badge\sin)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Check-In Pengguna Terbaru Teratas
metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_UNCATEGORIZED"
strings.coalesce(metadata.description, security_result.action_details, security_result.description, security_result.summary, additional.fields["plasectrxEvtypename"]) = /(?:access\sgranted|badge\sin)/ nocase

$User = strings.coalesce(principal.user.user_display_name, principal.user.email_addresses, additional.fields["person"], principal.user.userid)
$Location = strings.coalesce(security_result.rule_labels["Place"], additional.fields["site"], target.location.name, principal.resource.name)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Date, $User, $Location

order:
  $Date desc

limit:
    10
10 Lokasi Sensor Teratas
metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_UNCATEGORIZED"

$Location = strings.coalesce(security_result.rule_labels["Place"], additional.fields["site"], target.location.name, principal.resource.name)
$Location != ""

match:
  $Location

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Lokasi Sensor dari Waktu ke Waktu
metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_UNCATEGORIZED"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Location = strings.coalesce(security_result.rule_labels["Place"], additional.fields["site"], target.location.name, principal.resource.name)
$Location != ""

match:
  $Date, $Location

outcome:
  $Count = count(metadata.id)

order:
  $Date desc

Aktivitas Living Off the Land

Dasbor ini memberikan insight penting tentang potensi penyalahgunaan alat dan proses sistem tepercaya oleh penyerang. Dasbor ini melacak dan memvisualisasikan aktivitas yang terkait dengan utilitas sistem seperti rundll32, regsvr32, mshta.exe, dan lainnya, yang biasanya dimanfaatkan oleh ancaman tingkat lanjut untuk menghindari deteksi.

Nama diagram Contoh kueri
Eksekusi msiexec yang Mencurigakan
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"
target.process.file.full_path = /msiexec/
target.process.command_line = /:\/\//

$Hostname = principal.hostname
$Parent_Process = principal.process.file.full_path
$Target_Process = target.process.file.full_path
$Command_Line = target.process.command_line
$Timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $Timestamp
order:
  $Timestamp desc
limit:
    50
Pembuatan Proses mshta.exe yang Mencurigakan
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"
principal.process.file.full_path = /(cmd|cscript|powershell|pwsh|regsvr32|rundll32|wscript)\.exe/
target.process.file.full_path = /mshta.exe/

$Hostname = principal.hostname
$Parent_Process = principal.process.file.full_path
$Target_Process = target.process.file.full_path
$Command_Line = target.process.command_line
$timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $timestamp
order:
  $timestamp desc
limit:
    50
Eksekusi Regsvr32 yang Mencurigakan
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"
target.process.command_line = /regsvr32/ nocase
target.process.command_line = /ProgramData|Temp\b|Users\\Public|Windows\\Temp|AppData\\Local\\Temp|AppData\\Roaming/ nocase

$Hostname = principal.hostname
$Parent_Process = principal.process.file.full_path
$Target_Process = target.process.file.full_path
$Command_Line = target.process.command_line
$timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $timestamp
order:
  $timestamp desc
limit:
    50
Koneksi Keluar yang Dimulai oleh Rundll32.exe
metadata.event_type = "NETWORK_CONNECTION"
principal.process.file.full_path = /rundll32/ nocase
network.direction = "OUTBOUND"
target.ip != /^(10\b|127|192\.168|172\.(1[6-9]|2[0-9]|3[01]))/
principal.process.command_line != /PcaSvc\.dll|PcaPatchSdbTask/ nocase

$Hostname = principal.hostname
$Process_Name = principal.process.file.full_path
$Destination_IP = target.ip
$Command_Line = principal.process.command_line
$timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Process_Name, $Destination_IP, $Command_Line, $timestamp
order:
  $timestamp desc
limit:
    50
Eksekusi Rundll32 yang Mencurigakan
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"
principal.process.command_line != /Shell32\.dll|Control_RunDLL|\.cpl/ nocase
target.process.command_line = /rundll32.*(javascript|\.RegisterXLL|OpenURL|OpenURLA|FileProtocolHandler|(url|zipfldr|shell32|mshtml|advpack|ieadvpack|ieframe|shdocvw|syssetup|setupapi|pcwutl|dfshim|scrobj|shimgvw|comsvcs)\.dll|RouteTheCall|Control_RunDLL|ShellExec_RunDLL|PrintHTML|LaunchINFSection|RegisterOCX|SetupInfObjectInstallAction|InstallHinfSection|LaunchApplication|ShOpenVerbApplication|http|ImageView_Fullscreen|MiniDump)/ nocase

$Hostname = principal.hostname
$Parent_Process = strings.coalesce(principal.process.file.full_path, principal.file.full_path)
$Target_Process = strings.coalesce(target.process.file.full_path, target.file.full_path)
$Command_Line = target.process.command_line
$timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $timestamp
order:
  $timestamp desc
limit:
    50
Perintah CertUtil yang Mencurigakan
target.process.command_line = /certutil.*(decode|encode|urlcache|verifyctl|encodehex|decodehex)/

$Hostname = principal.hostname
$Parent_Process = principal.process.file.full_path
$Target_Process = target.process.file.full_path
$Command_Line = target.process.command_line
$Timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $Timestamp
order:
  $Timestamp desc
limit:
    50
Skrip WMI Mencurigakan
target.process.command_line = /(jscript|vbscript)\.dll|format:/
target.process.file.full_path = /wmi.*\.exe/ nocase

$Hostname = principal.hostname
$Parent_Process = principal.process.file.full_path
$Target_Process = target.process.file.full_path
$Command_Line = target.process.command_line
$Timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Parent_Process, $Target_Process, $Command_Line, $Timestamp
order:
  $Timestamp
limit:
    50
Koneksi Jaringan Regsvr32 yang Mencurigakan
metadata.event_type = "NETWORK_CONNECTION"
principal.process.file.full_path = /regsvr32/
target.ip != /^(10\b|127|169\.254|172\.16|224|100\.64|198\.(18|51\.100)|203\.0\.113|240|192\.(0\.2|0\.0\.(8|9|10|170|171)|0|31\.196|52\.193|168|88\.99|175\.48))/

$Hostname = principal.hostname
$Process_Name = principal.process.file.full_path
$Command_Line = principal.process.command_line
$Destination_IP = target.ip
$timestamp = timestamp.get_timestamp(metadata.event_timestamp.seconds)

match:
  $Hostname, $Process_Name, $Destination_IP,  $Command_Line, $timestamp
order:
  $timestamp desc
limit:
    50

Peristiwa yang Ditandai MITRE ATT&CK

Dasbor ini memberikan ringkasan aktivitas deteksi berdasarkan framework MITRE ATT&CK, melacak deteksi, dan menyoroti tren untuk mengidentifikasi ancaman baru. Solusi ini membantu organisasi dan tim keamanan memahami lingkungan mereka dengan lebih baik dengan menampilkan dan memetakan taktik, teknik, dan prosedur (TTP), meningkatkan deteksi dan respons terhadap ancaman, serta memastikan pertahanan proaktif terhadap ancaman siber.

Nama diagram Contoh kueri
Taktik & Teknik Baru - 7 Hari Terakhir
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"

match:
  $Tactic, $Technique

outcome:
  $First_Seen = timestamp.get_timestamp(min(metadata.event_timestamp.seconds), "%F %T")
  $Last_Seen = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Diff_First_Seen = timestamp.diff(timestamp.current_seconds(), min(metadata.event_timestamp.seconds), "DAY")

order:
  $Diff_First_Seen asc
Tren Teknik dari Waktu ke Waktu
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Technique

outcome:
  $Count = count(strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))

order:
  $Date asc 
10 Teknik yang Teridentifikasi Teratas
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"

match:
  $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc

limit:
    10 
10 Teknik yang Teridentifikasi Teratas
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"

match:
  $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc

limit:
    10 
Tren Taktik dari Waktu ke Waktu
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Tactic

outcome:
  $Count = count(strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))

order:
  $Date asc 
Tren Taktik dari Waktu ke Waktu
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Tactic

outcome:
  $Count = count(strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))

order:
  $Date asc 
Total Pemberitahuan Vendor menurut Taktik
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Alert = strings.coalesce(security_result.rule_name, security_result.threat_name, security_result.summary, security_result.description)

match:
  $Tactic, $Alert

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Tactic asc
Taktik yang Diidentifikasi oleh Pengguna
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Username = strings.coalesce(principal.user.user_display_name, principal.user.userid)
$Username != ""
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""

match:
  $Username, $Hostname, $Tactic

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Count desc 
Teknik yang Diidentifikasi oleh Nama Host
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""
$IP_Address = strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Hostname, $IP_Address, $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc
Teknik yang Diidentifikasi oleh Nama Host
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""
$IP_Address = strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Hostname, $IP_Address, $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc
Taktik yang Diidentifikasi oleh Nama Host
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""
$IP_Address = strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Hostname, $IP_Address, $Tactic

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Count desc 
Teknik yang Diidentifikasi oleh Pengguna
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""
strings.coalesce(principal.user.user_display_name, principal.user.userid) != ""
strings.coalesce(principal.hostname, principal.asset.hostname) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Username = strings.coalesce(principal.user.user_display_name, principal.user.userid)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)

match:
  $Username, $Hostname, $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc
Teknik yang Diidentifikasi oleh Pengguna
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""
strings.coalesce(principal.user.user_display_name, principal.user.userid) != ""
strings.coalesce(principal.hostname, principal.asset.hostname) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Username = strings.coalesce(principal.user.user_display_name, principal.user.userid)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)

match:
  $Username, $Hostname, $Technique

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc
Total Pemberitahuan Vendor menurut Taktik
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Alert = strings.coalesce(security_result.rule_name, security_result.threat_name, security_result.summary, security_result.description)

match:
  $Tactic, $Alert

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Tactic asc
Taktik & Teknik Baru - 7 Hari Terakhir
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"

match:
  $Tactic, $Technique

outcome:
  $First_Seen = timestamp.get_timestamp(min(metadata.event_timestamp.seconds), "%F %T")
  $Last_Seen = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $First_Seen_Time = min(metadata.event_timestamp.seconds)
  $Last_Seen_Time = max(metadata.event_timestamp.seconds)
  $Diff_First_Seen = math.round(($Last_Seen_Time - $First_Seen_Time)/86400)

order:
  $Diff_First_Seen asc

unselect:
  $First_Seen_Time, $Last_Seen_Time
Taktik yang Diidentifikasi oleh Nama Host
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""
$IP_Address = strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Hostname, $IP_Address, $Tactic

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Count desc 
Distribusi Tingkat Keparahan Peristiwa MITRE
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"])))

order:
  $Count desc
Tren Teknik dari Waktu ke Waktu
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Technique

outcome:
  $Count = count(strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))

order:
  $Date asc 
Acara menurut Taktik dan Teknik
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""
strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"]) != ""
strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Technique = strings.concat(strings.coalesce(security_result.attack_details.techniques.id, security_result.detection_fields["Technique ID"])," - ", strings.coalesce(security_result.attack_details.techniques.name, security_result.detection_fields["Technique"]))
$Technique != "-"

match:
  $Tactic, $Technique

outcome:
  $Count = count(metadata.id)

order:
  $Tactic asc
Taktik yang Diidentifikasi oleh Pengguna
strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"]) != ""
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) != ""

$Tactic = strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]))
$Tactic != "-"
$Username = strings.coalesce(principal.user.user_display_name, principal.user.userid)
$Username != ""
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""

match:
  $Username, $Hostname, $Tactic

outcome:
  $Count = count(strings.concat(strings.coalesce(security_result.attack_details.tactics.id, security_result.detection_fields["Tactic ID"])," - ", strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"])))

order:
  $Count desc 

Microsoft 365 - SharePoint & OneDrive

Dasbor ini menawarkan tampilan mendetail tentang aktivitas pengguna, akses data, dan peristiwa keamanan di kedua platform. Layanan ini memberikan insight berharga kepada organisasi untuk melacak operasi file, tren akses, dan perilaku pengguna. Dasbor ini membantu mengidentifikasi akses tidak sah atau aktivitas yang tidak biasa, seperti lokasi login yang tidak terduga atau anomali dalam pola pengguna.

Nama diagram Contoh kueri
Aktivitas Pengguna
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$Application = strings.coalesce(principal.application, target.application, intermediary.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date,$User,$Source_IP, $Application,$Security_Event_Type

outcome:

  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Modifikasi Kebijakan Berbagi
metadata.product_event_type = "SharingPolicyChanged"

$Application = strings.coalesce(principal.application, target.application, intermediary.application)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Role = principal.user.attribute.roles.name
$Policy = target.labels.key
$Action = target.labels.value
($Action = "True" or $Action = "False")
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $User, $Role, $Policy, $Action, $Application

outcome:
  $Count = count(metadata.id)
order:
  $Count desc
10 Situs SharePoint yang Paling Sering Diakses
$Sites = strings.coalesce(target.url,network.http.referral_url,principal.url)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Sites, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Aktif Teratas
$User = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$Application = strings.coalesce(principal.application, target.application, intermediary.application)

match:
  $User, $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Teratas Aktivitas Akun Istimewa
principal.user.attribute.roles.name = /Admin|DcAdmin|Administrator|Root/ nocase //It will be updated as per the client's environment.

$Role = principal.user.attribute.roles.name
$Security_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Resource = if(target.resource.name = "Unknown",target.url,target.resource.name)
$Application = strings.coalesce(principal.application, target.application, intermediary.application)

match:
  $Role, $Security_Event_Type, $Application

outcome:
  $Username = array_distinct($User)
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Operasi File Teratas
metadata.product_event_type = /File/ nocase

$Security_Event_Type = metadata.product_event_type
$Action = security_result.action

match:
  $Security_Event_Type, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peta Geolokasi di Akses Pengguna
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region)
$Country != ""

match:
  $Country

outcome:
    $Count = count($User)
    $Latitude = max(principal.ip_geo_artifact.location.region_latitude)
    $Longitude = max(principal.ip_geo_artifact.location.region_longitude)

order:
    $Count desc
10 Alamat IP Sumber Teratas
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Source_IP, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Tren Aktivitas dari Waktu ke Waktu
$Application = strings.coalesce(principal.application, target.application, intermediary.application)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Application, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Jumlah Download File dari Waktu ke Waktu
metadata.product_event_type = "FileDownloaded"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Date, $User

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Download File
metadata.product_event_type = "FileDownloaded"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Downloaded_File = strings.coalesce(src.url,src.file.full_path)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Role = principal.user.attribute.roles.name

match:
  $Date, $User,$Role,$Downloaded_File

outcome:
  $Count = count(metadata.id)

order:
  $Count asc

Pemberitahuan Microsoft 365

Dasbor ini memberikan ringkasan peristiwa keamanan dan potensi ancaman, serta melacak pemberitahuan dan tren penting terkait aktivitas pengguna.

Nama diagram Contoh kueri
10 Pengguna Teratas menurut Notifikasi
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.summary = /threat(?:\s)?management/ nocase
target.user.userid != ""

$User = target.user.userid

match:
  $User
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
limit:
    10 
10 Pemberitahuan Teratas
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.summary = /threat(?:\s)?management/ nocase
security_result.rule_name != ""

$Alert = security_result.rule_name

match:
  $Alert
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
limit:
    10
10 Peringatan Tingkat Keparahan Tinggi Teratas
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.severity = "HIGH"
security_result.summary = /threat(?:\s)?management/ nocase
security_result.rule_name != ""

$Alert = security_result.rule_name

match:
  $Alert
outcome:
  $Count = count(metadata.id)
order:
  $Count desc
limit:
    10
Detail Pemberitahuan Terbaru
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.summary = /threat(?:\s)?management/ nocase

$Alert = security_result.rule_name
$Description = security_result.description
$Severity = security_result.severity
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Alert, $Description, $Severity
outcome:
  $Count = count(metadata.id)
order:
  $Date desc
limit:
    50
Distribusi Tingkat Keparahan Pemberitahuan
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.summary = /threat(?:\s)?management/ nocase

$Severity = security_result.severity

match:
  $Severity
outcome:
  $Count = count(metadata.id)
order:
  $Severity desc
Pemberitahuan dari Waktu ke Waktu
metadata.log_type = "MICROSOFT_GRAPH_ALERT"
metadata.product_name = "Office 365 Security and Compliance"
security_result.summary = /threat(?:\s)?management/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date
outcome:
  $Count = count(metadata.id)
order:
  $Date asc

Pengelolaan Perangkat Seluler

Dasbor ini membantu tim keamanan memantau perangkat seluler organisasi dengan memberikan insight tentang kepatuhan, tren ancaman, distribusi tingkat keparahan, dan aktivitas pengguna untuk memahami postur keamanan secara keseluruhan. Hal ini memungkinkan pengambilan keputusan yang tepat untuk mengatasi kerentanan, menerapkan kebijakan keamanan, dan mengurangi ancaman baru secara efektif.

Nama diagram Contoh kueri
Perangkat dengan Versi OS yang Sudah Tidak Berlaku / Rentan
(principal.asset.platform_software.platform_version = /Android|IOS|Windows|mac(?:os)?/ nocase
and not principal.asset.platform_software.platform_version = /Android(?:\s|\/)1[3-6]|IOS(?:\s|\/)1[5-8]|Windows(?:\s|\/)1[0-1]|mac(?:OS)?(?:\s|\/)1[3-5]/ nocase)
or (target.resource.attribute.labels["OS"] = /Android/ nocase
    and not (target.resource.attribute.labels["Version"] = /1[3-6]/
    or target.resource.attribute.labels["OSversion"] = /1[3-6]/))
or (target.resource.attribute.labels["OS"] = /IOS/ nocase
    and not (target.resource.attribute.labels["Version"] = /1[5-8]/
    or target.resource.attribute.labels["OSversion"] = /(15|16|17|18).*/))
or (target.resource.attribute.labels["OS"] = /Windows/ nocase
    and not (target.resource.attribute.labels["Version"] = /10|11/
    or target.resource.attribute.labels["OSversion"] = /10|11/))
or (target.resource.attribute.labels["OS"] = /mac(?:OS)?/ nocase
    and not (target.resource.attribute.labels["Version"] = /1[3-5]/
    or target.resource.attribute.labels["OSversion"] = /1[3-5]/))

$Device = strings.coalesce(principal.asset.hostname, principal.hostname)
$OS = strings.coalesce(principal.asset.platform_software.platform_version, target.resource.attribute.labels["OS"])
$Version = strings.coalesce(target.resource.attribute.labels["Version"], target.resource.attribute.labels["OSversion"])

match:
  $Device, $OS, $Version
10 Aset yang Paling Banyak Dimodifikasi
metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
metadata.product_event_type = /Patch MobileApp|Patch ManagedDevice|Patch DeviceConfiguration|(Application|Profile)Modified/ nocase

$Resource_Name = principal.hostname
$Resource_Name != ""

match:
  $Resource_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Distribusi OS
$Platform = principal.platform

match:
  $Platform

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Ancaman Perangkat Teratas
metadata.product_event_type = "THREAT_DETECTED"
or additional.fields["CompromisedStatus"] = /^Compromised/ nocase
or security_result.description = /Threat|Compromised/ nocase

$Threat_Event = strings.coalesce(metadata.product_event_type, security_result.category_details, security_result.description)

match:
  $Threat_Event

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Lokasi Teratas Perangkat
$Country = principal.ip_geo_artifact.location.country_or_region
$Latitude = principal.ip_geo_artifact.location.region_coordinates.latitude
$Latitude != 0
$Longitude = principal.ip_geo_artifact.location.region_coordinates.longitude
$Longitude != 0

match:
  $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perangkat yang Tidak Mematuhi Kebijakan dari Waktu ke Waktu
additional.fields["ComplianceState"] = /Not Compliant/ nocase
or target.resource.attribute.labels["Status"] = /NonCompliant/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count_distinct(principal.hostname)

order:
  $Date desc 
10 Pengguna Teratas berdasarkan Kegagalan Login
(metadata.event_type = "USER_LOGIN"
or metadata.product_event_type = /user(?:\s|\S|)?login/ nocase
and security_result.action = "BLOCK" or target.resource.attribute.labels["Status"] = /Failure/ nocase)
or metadata.product_event_type = /user(?:\s|\S)?login.*(?:failed)?/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$User = principal.user.userid
$User != ""

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Perangkat dengan Ancaman Terbaru dari Waktu ke Waktu
metadata.product_event_type = "THREAT_DETECTED"
or additional.fields["CompromisedStatus"] = /^Compromised/ nocase
or security_result.description = /Threat|Compromised/ nocase

$Device = principal.hostname
$Device != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Device

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Perangkat yang Dipasangi Patch dari Waktu ke Waktu
metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
metadata.product_event_type = /Patch MobileApp|Patch ManagedDevice|Patch DeviceConfiguration|(Application|Profile)Modified/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Perangkat Penting dari Waktu ke Waktu
security_result.severity = "CRITICAL"
or security_result.severity = "HIGH"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count_distinct(principal.hostname)

order:
  $Date desc
Ancaman yang Terdeteksi dari Waktu ke Waktu
metadata.product_event_type = "THREAT_DETECTED"
or additional.fields["CompromisedStatus"] = /^Compromised/ nocase
or security_result.description = /Threat|Compromised/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Threat_Event = strings.coalesce(metadata.product_event_type, security_result.category_details, security_result.description)

match:
  $Date, $Threat_Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Distribusi Tingkat Keparahan Perangkat
$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count_distinct(principal.hostname)

order:
  $Count desc
Penyiapan/Penghapusan Perangkat dari Waktu ke Waktu
metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.product_event_type = /DEVICE_ENROLLMENT|DeviceEnrolled/ nocase
or metadata.event_type = "USER_RESOURCE_DELETION"
or metadata.product_event_type = /^(Deviceun(?:enrolled|enrollment)|BreakMDMConfirmed|Delete\s?(?:ManagedDevice|Device)(?:Requested)?|Retire\s?ManageDevice|DeviceWipeRequested)$/ nocase

$Enrollment = if(metadata.product_event_type = /DEVICE_ENROLLMENT|DeviceEnrolled/ nocase, "Onboard", if(metadata.product_event_type = /^(Deviceun(?:enrolled|enrollment)|BreakMDMConfirmed|Delete\s?(?:ManagedDevice|Device)(?:Requested)?|Retire\s?ManageDevice|DeviceWipeRequested)$/ nocase, "Offboard"))
$Enrollment != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Enrollment

outcome:
  $Count = count_distinct(principal.hostname)

order:
  $Date desc
Acara dari Waktu ke Waktu
$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc

Pemantauan Autentikasi Multi-Faktor (MFA)

Dasbor ini memberikan analisis mendetail tentang penerapan dan efektivitas MFA di seluruh organisasi Anda. Laporan ini menawarkan insight real-time dan historis tentang tren penggunaan MFA, pemberitahuan kegagalan, dan status pendaftaran. Dengan memantau aspek-aspek utama ini, dasbor membantu organisasi mengidentifikasi potensi kerentanan, melacak performa autentikasi, dan memastikan kepatuhan terhadap protokol keamanan, yang pada akhirnya memperkuat keamanan akses dan pengelolaan pengguna secara keseluruhan.

Nama diagram Contoh kueri
Deteksi Bypass MFA Okta
$event_type = metadata.event_type
$event_type = "USER_UNCATEGORIZED"
$vendor = metadata.vendor_name
$vendor = /Okta/ nocase
$security_event_type = metadata.product_event_type
$security_event_type = "user.mfa.attempt_bypass"
$User = principal.user.user_display_name
$Summary = security_result.summary
$Action = security_result.action
$Action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$User, $Action, $Date,$Summary, $security_event_type
outcome:
$Count = count(metadata.id)
Tingkat Kegagalan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id =strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$Date
outcome:
$total_attempts = count(metadata.id)
$failure_attempts = sum(if(any security_result.action = "BLOCK", 1, 0))  // Sums only failure MFA attempts
$failure_rate = (($failure_attempts / $total_attempts) * 100 )
order:
$Date asc 
Upaya MFA yang Diblokir menurut Alasan
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$action = security_result.action
$action = "BLOCK"
$Reason = security_result.summary
$Reason != ""
$Location = principal.location.country_or_region
match:
$Reason, $Location
outcome:
$Count = count(metadata.id)
order:
$Count desc
Upaya MFA dari Waktu ke Waktu
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Location = principal.location.country_or_region
match:
$Date, $Location
outcome:
$Count = count(metadata.id)
order:
$Date asc
Upaya MFA menurut Lokasi
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$User = target.user.userid
$User != ""
$Action = security_result.action
$Action !="UNKNOWN_ACTION"
$Vendor = metadata.vendor_name
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Latitude = principal.location.region_coordinates.latitude
$Longitude = principal.location.region_coordinates.longitude
$Location = strings.coalesce(target.location.country_or_region, principal.location.country_or_region)
match:
$Vendor, $Date, $Location, $Latitude, $Longitude
outcome:
$Count = count(metadata.id)
Upaya MFA menurut Lokasi
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$User = target.user.userid
$User != ""
$Action = security_result.action
$Action !="UNKNOWN_ACTION"
$Vendor = metadata.vendor_name
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Latitude = principal.location.region_coordinates.latitude
$Longitude = principal.location.region_coordinates.longitude
$Location = strings.coalesce(target.location.country_or_region, principal.location.country_or_region)
match:
$Vendor, $Date, $Location, $Latitude, $Longitude
outcome:
$Count = count(metadata.id)
5 Pengguna Teratas berdasarkan Upaya MFA yang Gagal
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$User = strings.coalesce(target.user.userid, principal.user.userid)
$User != ""
$email_id = strings.coalesce(target.user.email_addresses,principal.user.email_addresses)
$Action = security_result.action
$Action = "BLOCK"
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$User, $Action
outcome:
$Count = count(metadata.id)
order:
$Count desc
limit:5
Tren Penggunaan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$event_type, $Date
outcome:
$Count = count($event_type)
order:
$Date asc 
5 Aplikasi Teratas yang Diakses melalui MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$Application = target.application
$Application != ""
match:
$Application
outcome:
$Count = count(metadata.id)
order:
$Count desc
limit : 5
Tingkat Keberhasilan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid,principal.user.userid)
$user !=""
$email_id =strings.coalesce(target.user.email_addresses,principal.user.email_addresses)
$action = security_result.action
$vendor = metadata.vendor_name
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
  $total_attempts = count(metadata.id)
  $successful_attempts = sum(if(any security_result.action = "ALLOW", 1, 0))  // Sums only successful MFA attempts
  $success_rate = (($successful_attempts / $total_attempts) * 100 )
order: $date asc
Tingkat Keberhasilan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid,principal.user.userid)
$user !=""
$email_id =strings.coalesce(target.user.email_addresses,principal.user.email_addresses)
$action = security_result.action
$vendor = metadata.vendor_name
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
  $total_attempts = count(metadata.id)
  $successful_attempts = sum(if(any security_result.action = "ALLOW", 1, 0))  // Sums only successful MFA attempts
  $success_rate = (($successful_attempts / $total_attempts) * 100 )
order: $date asc
5 Aplikasi Teratas yang Diakses melalui MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$Application = target.application
match:
$Application
outcome:
$Count = count(metadata.id)
order:
$Count desc
limit : 5
Upaya MFA yang Diblokir menurut Alasan
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$action = security_result.action
$action = "BLOCK"
$Reason = security_result.summary
$Reason != ""
$Location = principal.location.country_or_region
match:
$Reason, $Location
outcome:
$Count = count(metadata.id)
order:
$Count desc
Status Pendaftaran MFA
$event_type = metadata.event_type
$event_type = "USER_CREATION"
$security_event_type = metadata.product_event_type
$security_event_type = "enrollment"
$product_name = metadata.product_name
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$summary = security_result.summary
$summary != ""
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$vendor = metadata.vendor_name
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$summary
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Tingkat Kegagalan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id =strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$Date
outcome:
$total_attempts = count(metadata.id)
$failure_attempts = sum(if(any security_result.action = "BLOCK", 1, 0))  // Sums only failure MFA attempts
$failure_rate = (($failure_attempts / $total_attempts) * 100 )
order:
$Date asc 
Deteksi Bypass MFA Okta
$event_type = metadata.event_type
$event_type = "USER_UNCATEGORIZED"
$vendor = metadata.vendor_name
$vendor = /Okta/
$security_event_type = metadata.product_event_type
$security_event_type = "user.mfa.attempt_bypass"
$User = principal.user.user_display_name
$Summary = security_result.summary
$Action = security_result.action
$Action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$User, $Action, $Date,$Summary, $security_event_type
outcome:
$Count = count(metadata.id)
order:
$Count desc
5 Pengguna Teratas berdasarkan Upaya MFA yang Gagal
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$User = strings.coalesce(target.user.userid, principal.user.userid)
$User != ""
$email_id = strings.coalesce(target.user.email_addresses,principal.user.email_addresses)
$Action = security_result.action
$Action = "BLOCK"
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$User, $Action
outcome:
$Count = count(metadata.id)
order:
$Count desc
limit:5
Upaya MFA dari Waktu ke Waktu
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Location = principal.location.country_or_region
match:
$Date, $Location
outcome:
$Count = count(metadata.id)
order:
$Date asc
Pemberitahuan Kegagalan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action = "BLOCK"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$Date
outcome:
$Count = count(metadata.id)
$Action = array_distinct($action)
order:
$Date asc
Pemberitahuan Kegagalan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) nocase or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action = "BLOCK"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$Date
outcome:
$Count = count(metadata.id)
$Action = array_distinct($action)
order:
$Date asc
Status Pendaftaran MFA
$event_type = metadata.event_type
$event_type = "USER_CREATION"
$security_event_type = metadata.product_event_type
$security_event_type = "enrollment"
$product_name = metadata.product_name
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($requirement, `multiFactorAuthentication`) nocase or re.regex($result_value, `MFA`) nocase)
$summary = security_result.summary
$summary != ""
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$vendor = metadata.vendor_name
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$summary
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Tren Penggunaan MFA
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$product_name = metadata.product_name
$security_event_type = metadata.product_event_type
$requirement = additional.fields["AuthenticationRequirement"]
$result_value = security_result.detection_fields.value
(re.regex($product_name, "MULTI-FACTOR_AUTHENTICATION") or re.regex($security_event_type, `user.mfa`) or re.regex($requirement, `multiFactorAuthentication`) or re.regex($result_value, `MFA`))
$user = strings.coalesce(target.user.userid, principal.user.userid)
$user != ""
$email_id = strings.coalesce(target.user.email_addresses, principal.user.email_addresses)
$action = security_result.action
$action != "UNKNOWN_ACTION"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$event_type, $Date
outcome:
$Count = count($event_type)
order:
$Date asc 

NIST 800-53 - Kontrol Akses

Dasbor ini memberikan ringkasan komprehensif tentang aktivitas kontrol akses yang selaras dengan standar NIST 800-53. Layanan ini melacak tren akses di seluruh sumber, kebijakan, dan geolokasi untuk mengidentifikasi risiko, menyederhanakan pemantauan, dan memperkuat pengelolaan kontrol akses. Dasbor ini menggunakan daftar referensi nist_compliance_assets untuk mencakup data ke lingkungan NIST.

Nama diagram Contoh kueri
Penguncian Akun Pengguna
metadata.description =  /locked out/ nocase

$Summary = metadata.description
$Log_Type = metadata.log_type
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
   $Summary, $User, $Hostname, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Login Gagal Terbaru (24 Jam Terakhir)
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

$Log_Type = metadata.log_type
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Summary = strings.coalesce(security_result.summary, security_result.description, metadata.description, security_result.rule_name)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Destination_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

match:
   $Summary, $User,$Hostname, $Source_IP, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc

NIST 800-53 - Audit dan Akuntabilitas

Dasbor ini memberikan ringkasan komprehensif tentang pengelolaan log, yang selaras dengan standar NIST 800-53, sehingga Anda dapat memantau dan mengelola log audit secara efektif untuk tujuan keamanan dan kepatuhan.

Nama diagram Contoh kueri
Penghapusan Log Audit(Peristiwa Windows)
(metadata.product_event_type = "104" OR metadata.product_event_type = "1102" )

$Description = metadata.description
$Event_Type = metadata.event_type
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname)
$Log_Event = additional.fields["Channel"]
match:
  $Hostname,$Event_Type,$Description,$Log_Event

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")
  $Count = count(metadata.id)

order :
  $Count desc

NIST 800-53 - Identifikasi & Autentikasi

Dasbor ini memberikan ringkasan komprehensif tentang aktivitas identitas dan autentikasi, yang selaras dengan standar NIST 800-53. Log ini melacak metrik utama seperti perubahan sandi, pengelolaan akun, pembaruan izin, dan aktivitas autentikasi multi-faktor (MFA). Alat ini membantu Anda menerapkan kepatuhan terhadap proses identitas dan autentikasi, sehingga memastikan perlindungan sistem dan data sensitif.

Nama diagram Contoh kueri
Tingkat Keberhasilan MFA
metadata.product_name  = "MULTI-FACTOR_AUTHENTICATION"
or metadata.product_event_type = /mfa(?:\S)?auth|auth(?:.*)?mfa/ nocase

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Successful_Attempts = sum(if(security_result.action = "ALLOW", 1, 0))
  $Success_Rate = (($Successful_Attempts / $Count) * 100)

order:
  $Date desc
Perubahan Izin dari Waktu ke Waktu
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Pemrakarsa Teratas yang Membuat Akun Pengguna
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pemrakarsa Teratas yang Menghapus Akun Pengguna
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pembuat Grup Teratas
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /add group/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pengguna dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Acara dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.event_type = "GROUP_MODIFICATION"
security_result.action = "ALLOW"

$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Modifikasi Peran Terbaru
metadata.product_event_type = /UpdateRole|update role(?: definition)?/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Role_Modified = strings.coalesce(target.user.attribute.roles.name, target.resource.product_object_id, target.resource.name)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Role_Modified

order:
  $Date desc
Pembuatan Grup Terbaru
metadata.event_type = "GROUP_CREATION"
or metadata.product_event_type = /add group/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Product_Event = metadata.product_event_type
$Group_Name = target.group.group_display_name

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Product_Event, $Group_Name

order:
  $Date desc 
10 Pemrakarsa Teratas yang Menghapus Peran
metadata.product_event_type = /DeleteRole|delete role definition/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Penghapusan Akun Pengguna Terbaru
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$User_Deleted = target.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $User_Deleted

order:
  $Date desc 
10 Pemrakarsa Teratas yang Menghapus Grup
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete group/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Tingkat Kegagalan MFA
metadata.product_name  = "MULTI-FACTOR_AUTHENTICATION"
or metadata.product_event_type = /mfa(?:\S)?auth|auth(?:.*)?mfa/ nocase

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Failed_Attempts = sum(if(security_result.action = "BLOCK", 1, 0))
  $Failure_Rate = (($Failed_Attempts / $Count) * 100 )

order:
  $Date desc
Perubahan Izin Terbaru
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Description = metadata.description

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Description

order:
  $Date desc
Penghapusan Grup Terbaru
metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /delete group/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Product_Event = metadata.product_event_type
$Group_Name = target.group.group_display_name

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Product_Event, $Group_Name

order:
  $Date desc
10 Pemrakarsa Teratas yang Mengubah Peran
metadata.product_event_type = /UpdateRole|update role(?: definition)?/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pembuatan Akun Pengguna Terbaru
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$User_Created = target.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $User_Created

order:
  $Date desc 
Penghapusan Peran Terbaru
metadata.product_event_type = /DeleteRole|delete role definition/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Role_Deleted = strings.coalesce(target.user.attribute.roles.name, target.resource.product_object_id, target.resource.name)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Role_Deleted

order:
  $Date desc
10 Pembuat Peran Teratas
metadata.product_event_type = /CreateRole|add role definition/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Modifikasi Akun Pengguna Baru-Baru Ini
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$User_Modified = target.user.userid
$Event_Type = metadata.event_type

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Event_Type, $User_Modified

order:
  $Date desc 
Perubahan Sandi dari Waktu ke Waktu
metadata.event_type = "USER_CHANGE_PASSWORD"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Pemrakarsa Teratas yang Mengubah Grup
metadata.event_type = "GROUP_MODIFICATION"
and metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pembuatan Peran Terbaru
metadata.product_event_type = /CreateRole|add role definition/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Initiator = principal.user.userid
$Role_Created = strings.coalesce(target.user.attribute.roles.name, target.resource.product_object_id, target.resource.name)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Initiator, $Role_Created

order:
  $Date desc
Status Pendaftaran MFA
metadata.product_name  = "MULTI-FACTOR_AUTHENTICATION"
or strings.coalesce(additional.fields["AuthenticationRequirement"], security_result.detection_fields.value) = /mfa|multi(?:\s|\S)?factor(?:\s|\S)?authentication|/ nocase

metadata.product_event_type = "enrollment"
or target.resource_ancestors.resource_subtype = "AuthenticatorEnrollment"

$Result = security_result.summary

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Result

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Pemrakarsa Teratas yang Mengubah Akun Pengguna
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Log_Source = metadata.log_type
$Initiator = principal.user.userid

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Initiator, $Log_Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Peran dari Waktu ke Waktu
metadata.product_event_type = /CreateRole|add role definition/ nocase
or metadata.product_event_type = /DeleteRole|delete role definition/ nocase
or metadata.product_event_type = /UpdateRole|update role(?: definition)?/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Product_Event = metadata.product_event_type

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date,  $Product_Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Modifikasi Grup Terbaru
metadata.event_type = "GROUP_MODIFICATION"
and metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
security_result.action = "ALLOW"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Log_Source = metadata.log_type
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$Product_Event = metadata.product_event_type
$Group_Name = target.group.group_display_name

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Source, $Source_IP, $Hostname, $Product_Event, $Group_Name

order:
  $Date desc
Acara Kelompok dari Waktu ke Waktu
metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /add group/ nocase
or metadata.product_event_type = /delete group/ nocase
or (metadata.event_type = "GROUP_MODIFICATION"
and metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase)

$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 

NIST 800-53 - Perlindungan Media

Dasbor ini memberikan ringkasan komprehensif tentang aktivitas perlindungan media, yang selaras dengan standar NIST 800-53. Laporan ini melacak peristiwa keamanan berdasarkan tindakan dan frekuensi, serta menyoroti tren utama seperti aturan yang sering dipicu, host teratas, alamat IP, dan pengguna. Alat ini membantu Anda menerapkan kepatuhan untuk melindungi aset media sensitif.

Nama diagram Contoh kueri
10 Pengguna Teratas menurut Tindakan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$User = principal.user.userid
$User != ""
//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $User, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Host Sumber Teratas menurut Tindakan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$Hostname = principal.hostname
$Hostname != ""
//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Hostname, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Lokasi Pemberitahuan Vendor Teratas
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Alert = strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary)
$Country = target.location.country_or_region
$Latitude = target.location.region_coordinates.latitude
$Longitude = target.location.region_coordinates.longitude

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Alert, $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pemberitahuan Vendor Terbaru
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|drive\b/ nocase

$Vendor_Alert = strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary)
$User = strings.coalesce(principal.user.user_display_name, target.user.user_display_name)
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$File_Name = target.file.full_path
$Action = security_result.action
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Vendor_Alert, $Source_IP, $User, $File_Name, $Action

order:
  $Date desc
10 Pemberitahuan Vendor Teratas menurut Tindakan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$Alerts = strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Alerts, $Action

outcome:
  $Count = count_distinct(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas menurut Tindakan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$IP_Address = principal.ip
$IP_Address != ""
//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $IP_Address, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu menurut Tindakan
strings.coalesce(metadata.product_event_type, security_result.rule_name, security_result.summary) = /\busb|removable|drive\b/ nocase

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date desc

NIST 800-53 - Perlindungan Sistem dan Komunikasi

Dasbor ini meningkatkan keamanan dan kepatuhan dengan memberikan insight tentang pertahanan sistem dan jaringan. Solusi ini memantau aktivitas sensor EDR, peristiwa IDS/IPS, DDO, dan anomali traffic jaringan untuk mendeteksi potensi ancaman, sehingga memastikan kepatuhan terhadap standar keamanan NIST. Referensi ini menggunakan daftar referensi nist_compliance_assets untuk mencakup data ke lingkungan NIST.

Nama diagram Contoh kueri
Peristiwa IDS / IPS menurut Kategori
metadata.event_type = "SCAN_UNCATEGORIZED"
or metadata.event_type = "SCAN_NETWORK"
or metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Category = security_result.category
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Destination_IP, $Source_IP) in %NIST_Compliance_Assets

match:
  $Category

outcome:
  $Count = count(metadata.id)

Aktivitas DDOS
(metadata.log_type = /ddos/ nocase or (security_result.description  = /ddos/ nocase or security_result.summary  = /ddos/ nocase or metadata.description = /ddos/ nocase or security_result.rule_name = /ddos/ nocase or metadata.product_event_type = /ddos/ nocase))

$Summary = strings.coalesce(security_result.description, security_result.summary, metadata.description, security_result.rule_name, metadata.product_event_type)
$Action = security_result.action
$Log_Type = metadata.log_type
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.asset.hostname, target.hostname)
$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
$Destination_IP = strings.coalesce(target.asset.ip, target.ip)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

match:
  $Summary, $Hostname, $Source_IP, $Destination_IP, $Action, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Traffic Jaringan dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname,target.hostname, target.asset.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)
    
Traffic Masuk yang Diblokir menurut Geolokasi
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.action = "BLOCK"
network.direction = "INBOUND"

$Country = principal.location.country_or_region
$Country != ""

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.location.region_coordinates.latitude)
  $Longitude = max(principal.location.region_coordinates.longitude)

order:
  $Count desc
Peristiwa USB
(metadata.product_event_type = /usb/ nocase or security_result.summary = /usb/ nocase )

$Log_Type = metadata.log_type
$USB_Event = strings.coalesce(metadata.product_event_type, security_result.summary)
$Category = security_result.category_details
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Log_Type, $USB_Event, $User, $Hostname, $Source_IP, $Category

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Aktivitas Berbahaya Berbasis Jaringan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
(security_result.category = "NETWORK_DENIAL_OF_SERVICE" or security_result.category = "NETWORK_MALICIOUS" or security_result.category = "NETWORK_SUSPICIOUS" or security_result.category = "SOFTWARE_MALICIOUS" or security_result.category = "SOFTWARE_SUSPICIOUS" or security_result.category = "NETWORK_RECON")

$Log_Type = metadata.log_type
$Category = security_result.category
$Summary = strings.coalesce(security_result.description, security_result.summary, metadata.description, security_result.rule_name, metadata.product_event_type)
$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.hostname, target.asset.hostname)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

match:
  $Summary, $Category, $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc

Peringatan Vendor EDR
$Log_Type = metadata.log_type
$Rule_Name = security_result.rule_name
$Severity = security_result.severity
$User = strings.coalesce(principal.user.user_display_name, principal.user.email_addresses, principal.user.userid, target.user.userid, target.user.user_display_name, target.user.email_addresses)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Rule_Name, $Severity, $User, $Log_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Komunikasi Terenkripsi Lemah dari Waktu ke Waktu menurut Jenis Log
network.tls.cipher = /RSA|DES|RC4|SHA-1|3DES|MD5/ nocase

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Source_IP, Destination_IP) in %NIST_Compliance_Assets

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)
10 Pemberitahuan Vendor IDS / IPS Teratas menurut Tingkat Keparahan
metadata.event_type = "SCAN_UNCATEGORIZED"
or metadata.event_type = "SCAN_NETWORK"
or metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
(security_result.severity = "HIGH" or security_result.severity = "CRITICAL")

$Rule_Name = security_result.rule_name
$Rule_Name != ""
$Severity = security_result.severity

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Destination_IP, $Source_IP) in %NIST_Compliance_Assets

match:
  $Rule_Name, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Host Teratas dalam Peristiwa EDR menurut Jenis Log
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Hostname != ""
$Log_Type = metadata.log_type

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//strings.coalesce($Hostname, $Source_IP) in %NIST_Compliance_Assets

match:
  $Hostname, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Traffic Keluar yang Diblokir menurut Geolokasi
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.action = "BLOCK"
network.direction = "OUTBOUND"

$Country = principal.location.country_or_region
$Country != ""

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.location.region_coordinates.latitude)
  $Longitude = max(principal.location.region_coordinates.longitude)

order:
  $Count desc
Traffic jaringan dari Waktu ke Waktu menurut Arah
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

//If the user requires any inclusions for specific assets, these lines will need to be enabled in the query and update the NIST_Compliance_Assets reference list as needed.
//$Hostname = strings.coalesce(principal.asset.hostname, principal.hostname, target.asset.hostname, target.hostname)
//$Source_IP = strings.coalesce(principal.asset.ip, principal.ip)
//$Destination_IP = strings.coalesce(target.asset.ip, target.ip)
//strings.coalesce($Hostname, $Source_IP, $Destination_IP) in %NIST_Compliance_Assets

$Direction = network.direction
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Direction, $Date

outcome:
  $Total_Volume = sum(network.sent_bytes) + sum(network.received_bytes)
  $Total_Volume_GB = math.round($Total_Volume/ (1000 * 1000 * 1000), 2)
    

Ringkasan Traffic Jaringan

Dasbor ini menawarkan pemantauan real-time terhadap traffic jaringan cloud dan lokal menurut alamat IP, protokol, vendor, pemberitahuan, dan region, sehingga memungkinkan analisis yang efektif terhadap volume traffic dan potensi masalah.

Nama diagram Contoh kueri
Peristiwa Jaringan
$event.metadata.event_type = "NETWORK_FLOW"
or $event.metadata.event_type = "NETWORK_CONNECTION"
or $event.metadata.event_type = "NETWORK_FTP"
or $event.metadata.event_type = "NETWORK_DHCP"
or $event.metadata.event_type = "NETWORK_DNS"
or $event.metadata.event_type = "NETWORK_HTTP"
or $event.metadata.event_type = "NETWORK_SMTP"

outcome:
  $Count = count($event.metadata.id)
10 IP Sumber Teratas dalam Notifikasi Vendor
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.rule_name != ""

$Source_IP =  strings.coalesce(principal.ip, principal.asset.ip)

match:
  $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna yang Paling Banyak Diblokir
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
(security_result.action = "BLOCK" or security_result.action = "FAIL" or security_result.action_details = /fail|block/ nocase)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Peristiwa Teratas menurut Byte Terkirim
$Source_IP = principal.ip
$Event_Type = metadata.event_type

match:
  $Event_Type, $Source_IP

outcome:
  $Bytes_Sent = sum(network.sent_bytes) / (1000*1000*1000)

order:
  $Bytes_Sent desc

limit:
    10
Pemberitahuan Vendor dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.rule_name != ""

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa dari Waktu ke Waktu menurut Jenis Log
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Log_type = metadata.log_type

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 IP Keluar Teratas menurut Volume Traffic
network.direction = "OUTBOUND"

$Log_Type = metadata.log_type
$Destination_IP = target.ip

match:
  $Log_Type, $Destination_IP

outcome:
  $Total_Bytes = sum(network.received_bytes + network.sent_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
Pemberitahuan vendor dari waktu ke waktu menurut Jenis Log
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.rule_name != ""

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date , $Log_Type

outcome:
  $Count = count(security_result.rule_name)

order:
  $Date asc
10 Alamat IP Sumber Teratas
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Event_Type = $event.metadata.event_type
$Source_IP = $event.principal.ip
$Source_IP != ""

match:
   $Source_IP, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Pemberitahuan Vendor Teratas
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Rule_Name = security_result.rule_name

match:
  $Rule_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
IP Tujuan yang Berbeda
$event.metadata.event_type = "NETWORK_FLOW"
or $event.metadata.event_type = "NETWORK_CONNECTION"
or $event.metadata.event_type = "NETWORK_FTP"
or $event.metadata.event_type = "NETWORK_DHCP"
or $event.metadata.event_type = "NETWORK_DNS"
or $event.metadata.event_type = "NETWORK_HTTP"
or $event.metadata.event_type = "NETWORK_SMTP"

outcome:
  $Count = count_distinct($event.target.ip)
Penggunaan Versi TLS yang Lemah dari Waktu ke Waktu
network.tls.version != /1(\.|_)?(2|3)/ nocase

$Cipher_Version = network.tls.version
$Cipher_Version != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Cipher_Version, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Pengguna Teratas menurut Volume Traffic
$User = principal.user.userid

match:
  $User

outcome:
  $Total_Bytes = sum(network.sent_bytes + network.received_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
  10
10 Aplikasi Teratas menurut Byte yang Dikirim
$Source_IP = principal.ip
$Application = target.application

match:
  $Application, $Source_IP

outcome:
  $Total_Bytes = sum(network.sent_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
Volume Traffic Masuk vs. Keluar dari Waktu ke Waktu
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Direction = network.direction
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Direction, $Date

outcome:
  $Total_Volume = sum(network.sent_bytes) + sum(network.received_bytes)
  $Total_Volume_GB = $Total_Volume/ (1000 * 1000 * 1000)

order:
  $Date desc
Byte Rata-Rata
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Total_Bytes = sum(network.sent_bytes + network.received_bytes) / 2
  $Mean_GB_Total = math.round($Total_Bytes / 1073741824, 2)

order:
  $Date desc
Volume Traffic menurut IP dari Waktu ke Waktu
$IP_Address = principal.ip
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $IP_Address, $Date

outcome:
  $Total_Bytes = sum(network.sent_bytes + network.received_bytes) / (1000*1000*1000)

order:
  $Date desc
10 Lokasi Sumber Volume Traffic Teratas
$Country = principal.location.country_or_region
$Country != ""
$Latitude = principal.location.region_coordinates.latitude
$Longitude = principal.location.region_coordinates.longitude

match:
  $Country, $Latitude, $Longitude

outcome:
  $Total_Bytes = sum(network.received_bytes + network.sent_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
Peristiwa menurut Tingkat Keparahan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peta Panas Lokasi Traffic Masuk
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "INBOUND"

$Country = principal.ip_geo_artifact.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

order:
  $Count desc
10 Layanan Teratas Berdasarkan Volume Traffic
target.port != 0
network.ip_protocol != "UNKNOWN_IP_PROTOCOL"

$Service = strings.concat(target.port, "")
$Protocol = network.ip_protocol

match:
  $Service, $Protocol

outcome:
  $Total_Bytes = sum(network.received_bytes + network.sent_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
10 Port Teratas menurut Traffic - Keluar
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "OUTBOUND"

$Port = strings.concat(target.port, "")

match:
  $Port

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
IP Sumber Unik
$event.metadata.event_type = "NETWORK_FLOW"
or $event.metadata.event_type = "NETWORK_CONNECTION"
or $event.metadata.event_type = "NETWORK_FTP"
or $event.metadata.event_type = "NETWORK_DHCP"
or $event.metadata.event_type = "NETWORK_DNS"
or $event.metadata.event_type = "NETWORK_HTTP"
or $event.metadata.event_type = "NETWORK_SMTP"

outcome:
  $Count = count_distinct($event.principal.ip)
Volume Traffic menurut Jenis Log dari Waktu ke Waktu
$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Total_Bytes = sum(network.sent_bytes + network.received_bytes) / (1000*1000*1000)

order:
  $Date desc
Total Byte yang Dikirim
outcome:
  $Total_Bytes_Sent_GB = math.round(sum(network.sent_bytes) / (1000*1000*1000), 2)
Byte Simpangan Baku
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Stdev_Bytes = stddev(network.sent_bytes + network.received_bytes) / (1000*1000*1000)

order:
  $Date desc
Peta Panas Lokasi Traffic Keluar
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "OUTBOUND"

$Country = target.ip_geo_artifact.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(target.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(target.ip_geo_artifact.location.region_coordinates.longitude)

order:
  $Count desc
10 IP Sumber yang Diblokir Teratas ke IP Tujuan
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Event_Type = $event.metadata.event_type
$Source_IP = $event.principal.ip
$Destination_IP = $event.target.ip
$Block = $event.security_result.action
$Block = "BLOCK"

match:
  $Event_Type, $Source_IP, $Block, $Destination_IP
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Pelabuhan Teratas menurut Traffic - Masuk
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "INBOUND"

$Port = strings.concat(target.port, "")

match:
  $Port

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Negara Teratas yang Diblokir
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.action = "BLOCK"

$Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region)

match:
  $Country

outcome:
  $Count = count($Country)

order:
  $Count desc

limit:
    10
10 Alamat IP Tujuan Teratas
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type
$Destination_IP = $event.target.ip
$Destination_IP != ""

match:
  $Destination_IP, $Event_Type, $Log_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Distribusi Protokol Jaringan dari Waktu ke Waktu
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Protocol = network.application_protocol
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 File Target Mencurigakan Teratas
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Files = target.file.full_path
$Files = /\.exe|\.scr|\.com|\.pif|\.dll|\.js|\.vbs|\.ps1|\.bat|\.cmd|\.wsf|\.hta|\.docm|\.xlsm|\.pptm|\.dotm|\.pdf|\.zip|\.rar|\.iso|\.img|\.lnk|\.url/ nocase

match:
  $Files

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas di Pemberitahuan Vendor
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.rule_name != ""

$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)

match:
  $Source_User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 URL teratas
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$URL = target.url

match:
  $URL

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Lalu Lintas Jaringan yang Diizinkan vs. Diblokir
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Action = security_result.action

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Host Teratas menurut Ukuran Traffic
$Hostname = principal.hostname

match:
  $Hostname

outcome:
  $Total_Bytes = sum(network.sent_bytes + network.received_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10 
Port target menurut Protokol
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Port = strings.concat(target.port, "")
$Protocol = network.application_protocol

match:
  $Port, $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Koneksi yang Diizinkan Teratas
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Event_Type = $event.metadata.event_type
$Hostname = $event.principal.hostname
$Asset_Type = $event.principal.asset.type
$OS_Version = $event.target.asset.platform_software.platform_version
$Source_IP = $event.principal.ip
$Mac_Add = $event.principal.mac
$Nat_IP = $event.principal.nat_ip
$Destination_IP = $event.target.ip
$Destination_IP != ""
$Connection = $event.security_result.action
$Connection = "ALLOW"

match:
  $Event_Type, $Hostname, $OS_Version, $Source_IP, $Mac_Add, $Nat_IP, $Connection, $Destination_IP
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Traffic Masuk dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "INBOUND"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Byte Rata-Rata
outcome:
  $Average_Bytes = sum(network.sent_bytes + network.received_bytes) / 2
  $Average_Bytes_GB = math.round($Average_Bytes / (1000*1000*1000), 2)
10 Negara yang Diblokir Teratas
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"
$event.security_result.action = "BLOCK"

$Countries = $event.principal.location.country_or_region
$Latitude = $event.principal.location.region_coordinates.latitude
$Longitude = $event.principal.location.region_coordinates.longitude

match:
  $Countries, $Latitude, $Longitude
outcome:
  $Count = count_distinct($Countries)
limit:
    10
Traffic Keluar dari Waktu ke Waktu menurut Tindakan
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.direction = "OUTBOUND"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Kategori 10 acara teratas
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"

$Category = security_result.category

match:
   $Category

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Masuk Teratas menurut Volume Traffic
network.direction = "INBOUND"

$Log_Type = metadata.log_type
$Source_IP = principal.ip

match:
  $Log_Type, $Source_IP

outcome:
  $Total_Bytes = sum(network.received_bytes + network.sent_bytes) / (1000*1000*1000)

order:
  $Total_Bytes desc

limit:
    10
10 Koneksi Jaringan Teratas
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Source_Port = $event.principal.port
$Destination_Port = $event.target.port
$Source_IP = $event.principal.ip
$Destination_IP = $event.target.ip
$OS = $event.target.asset.platform_software.platform_version
$Direction = $event.network.direction
$Hostname = $event.principal.hostname
$Direction != "UNKNOWN_DIRECTION"
$OS != ""
$Hostname != ""

match:
  $Hostname, $OS, $Source_IP, $Source_Port, $Direction, $Destination_IP, $Destination_Port
outcome:
  $Time = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Time desc
limit:
    10
10 Alamat IP Sumber yang Paling Banyak Diblokir
$event.metadata.event_type = "NETWORK_FLOW"
 or $event.metadata.event_type = "NETWORK_CONNECTION"
 or $event.metadata.event_type = "NETWORK_FTP"
 or $event.metadata.event_type = "NETWORK_DHCP"
 or $event.metadata.event_type = "NETWORK_DNS"
 or $event.metadata.event_type = "NETWORK_HTTP"
 or $event.metadata.event_type = "NETWORK_SMTP"

$Event_Type = $event.metadata.event_type
$Source_IP = $event.principal.ip
$Source_IP != ""
$Destination_IP = $event.target.ip
$Log_Type = $event.metadata.log_type
$Block = $event.security_result.action
$Block = "BLOCK"

match:
  $Source_IP, $Block, $Destination_IP, $Log_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

Keamanan OT

Dasbor ini memberikan tampilan mendalam tentang keamanan dalam lingkungan OT, sehingga Anda dapat melacak dan mengevaluasi peristiwa keamanan. Alat ini mengidentifikasi tren, aset utama, pengguna, dan layanan, sekaligus memantau aktivitas jaringan dan geografis. Hal ini memungkinkan Anda memprioritaskan ancaman, mengoptimalkan strategi respons, dan meningkatkan keamanan sistem OT.

Nama diagram Contoh kueri
10 Protokol Non-OT Teratas menurut Jenis Log
network.application_protocol != "COAP"
network.application_protocol != "DNP3"
network.application_protocol != "MODBUS"
network.application_protocol != "MQTT"
network.application_protocol != "SNMP"

$Log_Type = metadata.log_type
$Protocol = network.application_protocol

match:
  $Protocol, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Aset Teratas yang Menggunakan Protokol Cleartext
network.application_protocol = "MODBUS"
or network.application_protocol = "DNP3"
or network.application_protocol = "CIP"
or network.application_protocol = "IEC104"
or network.application_protocol = "SNMP"
or network.application_protocol = "COTP"
or network.application_protocol = "GOOSE"
or network.application_protocol = "SV"
or network.application_protocol = "DEVICE_NET"
or network.application_protocol = "PTP"
or network.application_protocol = "HTTP"
or network.application_protocol = "RLOGIN"
or network.application_protocol = "FINGER"
or network.application_protocol = "SMTP"

$Protocol = network.application_protocol
$Asset = strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname)
$Asset != ""

match:
  $Asset, $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 CVE teratas
$CVE = principal.asset.vulnerabilities.cve_id
$CVE != ""
$Asset = principal.asset.hostname

match:
  $CVE, $Asset

outcome:
  $Count = count(principal.asset.vulnerabilities.cve_id)

order:
  $Count desc

limit:
    10
OT Sniffers Over Time
$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(observer.hostname)

order:
  $Date desc
10 Entitas Teratas yang Ditargetkan oleh Jaringan Eksternal
principal.ip != /^10\..|^172\.(1[6-9]|2\d|3[0-1])\..*|^192\.168\../
principal.ip != ""

$Entity = group(target.asset.hostname, target.asset.ip, target.asset.mac, target.user.userid)
$Entity != ""

match:
  $Entity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pemberitahuan Vendor dari Waktu ke Waktu menurut Aset
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
metadata.product_event_type != "Event"
metadata.product_event_type != "HealthCheck"
metadata.product_event_type != "Insight"

$Device = strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname)
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Vendor_Alert = metadata.product_event_type

match:
  $Date, $Device

outcome:
  $Count = count($Vendor_Alert)

order:
  $Count desc
Distribusi Protokol Teks Biasa
network.application_protocol = "MODBUS"
or network.application_protocol = "DNP3"
or network.application_protocol = "CIP"
or network.application_protocol = "IEC104"
or network.application_protocol = "SNMP"
or network.application_protocol = "COTP"
or network.application_protocol = "GOOSE"
or network.application_protocol = "SV"
or network.application_protocol = "DEVICE_NET"
or network.application_protocol = "PTP"
or network.application_protocol = "HTTP"
or network.application_protocol = "RLOGIN"
or network.application_protocol = "FINGER"
or network.application_protocol = "SMTP"

$Protocol = network.application_protocol

match:
  $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Notifikasi Vendor Teratas menurut Pengguna
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
metadata.product_event_type != "Event"
metadata.product_event_type != "HealthCheck"
metadata.product_event_type != "Insight"

$Event = metadata.product_event_type
$User = principal.user.user_display_name

match:
  $User, $Event

outcome:
  $Count = count(if((metadata.log_type = /claroty/ nocase and security_result.threat_id != "") or (metadata.log_type = /nozomi/ nocase and additional.fields["IsSecurity"] = "true") or (metadata.log_type = /TENABLE_OT/ nocase and security_result.category_details = /NetworkThreats/ nocase), 1, 0))

order:
  $Count desc

limit:
    10
10 Entity Teratas yang Memulai Jaringan Eksternal
target.ip != /^10\..|^172\.(1[6-9]|2\d|3[0-1])\..*|^192\.168\../

$Entity = group(principal.asset.hostname, principal.asset.ip, principal.asset.mac, principal.user.windows_sid, principal.user.userid)
$Entity != ""

match:
  $Entity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pemberitahuan Vendor Teratas menurut Tingkat Keparahan
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
 metadata.product_event_type != "Event"
 metadata.product_event_type != "HealthCheck"
 metadata.product_event_type != "Insight"

$Vendor_Alert = metadata.product_event_type
$Severity = security_result.severity

match:
  $Severity, $Vendor_Alert

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Protokol Aplikasi dari Waktu ke Waktu
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Application_Protocol = network.application_protocol

match:
  $Application_Protocol, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Aset OT Baru
metadata.product_event_type = /New Asset|SIGN:DHCP-OPERATION/ nocase

$Hostname = strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname)
$Hostname != ""

match:
  $Hostname 
Pemberitahuan Vendor dari Waktu ke Waktu
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
metadata.product_event_type != "Event"
metadata.product_event_type != "HealthCheck"
metadata.product_event_type != "Insight"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Vendor_Alert = metadata.product_event_type

match:
  $Date, $Vendor_Alert

outcome:
  $Count = count(if((metadata.log_type = /claroty/ nocase and security_result.threat_id != "") or (metadata.log_type = /nozomi/ nocase and additional.fields["IsSecurity"] = "true") or (metadata.log_type = /TENABLE_OT/ nocase and security_result.category_details = /NetworkThreats/ nocase), 1, 0))

order:
  $Count desc
Total Aset OT Baru
metadata.product_event_type = /New Asset|SIGN:DHCP-OPERATION/ nocase
strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname) != ""

outcome:
  $Count = count_distinct(strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname))
10 Aset Sumber Teratas
$Hostname = strings.coalesce(principal.asset.hostname, principal.asset.ip, principal.asset.mac, principal.hostname)
$Hostname != ""

match:
  $Hostname

outcome:
  $Count = count_distinct(strings.coalesce(target.asset.ip, target.ip))

order:
  $Count desc

limit:
    10
Pemberitahuan Vendor menurut Tindakan
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
 metadata.product_event_type != "Event"
 metadata.product_event_type != "HealthCheck"
 metadata.product_event_type != "Insight"
security_result.action_details = "Succeeded"
or security_result.action_details = "Failed"

$Action = security_result.action_details
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome:
  $Count = count(if((metadata.log_type = /claroty/ nocase and security_result.threat_id != "") or (metadata.log_type = /nozomi/ nocase and additional.fields["IsSecurity"] = "true") or (metadata.log_type = /TENABLE_OT/ nocase and security_result.category_details = /NetworkThreats/ nocase), 1, 0))

order:
  $Date desc
Total Aset OT
outcome:
  $Count = count_distinct(strings.coalesce(target.asset.hostname, target.asset.ip, target.asset.mac, target.hostname))
Pemberitahuan Vendor dari Waktu ke Waktu menurut Jenis Log
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
  metadata.product_event_type != "Event"
 metadata.product_event_type != "HealthCheck"
 metadata.product_event_type != "Insight"

$Log_Type =  metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Vendor_Alert = metadata.product_event_type

match:
  $Date, $Vendor_Alert, $Log_Type

outcome:
  $Count = count(if((metadata.log_type = /claroty/ nocase and security_result.threat_id != "") or (metadata.log_type = /nozomi/ nocase and additional.fields["IsSecurity"] = "true") or (metadata.log_type = /TENABLE_OT/ nocase and security_result.category_details = /NetworkThreats/ nocase), 1, 0))

order:
  $Date desc
10 Pemberitahuan Vendor Teratas menurut Kategori
(metadata.log_type = /CLAROTY_CTD|CLAROTY_EMC/ nocase
and security_result.threat_id != "")
or (metadata.log_type = /NOZOMI_GUARDIAN/ nocase
and additional.fields["IsSecurity"] = "true")
or (metadata.log_type = /TENABLE_OT/ nocase
and security_result.category_details = /NetworkThreats/ nocase)
 metadata.product_event_type != "Event"
 metadata.product_event_type != "HealthCheck"
 metadata.product_event_type != "Insight"

$Event = metadata.product_event_type
$Category = security_result.category_details

match:
  $Category, $Event

outcome:
  $Count = count(if((metadata.log_type = /claroty/ nocase and security_result.threat_id != "") or (metadata.log_type = /nozomi/ nocase and additional.fields["IsSecurity"] = "true") or (metadata.log_type = /TENABLE_OT/ nocase and security_result.category_details = /NetworkThreats/ nocase), 1, 0))

order:
  $Count desc

limit:
    10

PCI - Anti-Malware

Dasbor ini memberikan tampilan aset Industri Kartu Pembayaran (PCI) dan deteksi ancaman aktif. Referensi ini menggunakan daftar referensi pci_assets untuk mencakup data ke lingkungan PCI. Catatan: Diagram di dasbor ini tidak dimuat hingga daftar referensi yang diperlukan dibuat.

Nama diagram Contoh kueri
Peristiwa yang Diblokir menurut Jenis
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "BLOCK"

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
Peristiwa yang Diizinkan oleh Pengguna
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "ALLOW"

$Event_Type = $event.metadata.event_type
$User = strings.coalesce($event.principal.user.user_display_name, $event.principal.user.userid)

match:
  $User, $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    50
Ringkasan Peristiwa menurut Tindakan
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Action = $event.security_result.action

match:
  $Action
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
Total Peristiwa
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

outcome:
  $Count = count($event.security_result.action)
Total Pemberitahuan EDR menurut Tingkat Keparahan
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Severity = $event.security_result.severity
$Rule_Name = strings.coalesce($event.security_result.rule_name, $event.security_result.description)
$Rule_Name != ""
$Description = $event.metadata.description

match:
  $Rule_Name, $Description, $Log_Type, $Severity
outcome:
  $Count = count($event.security_result.rule_name)
order:
  $Severity desc
limit:
    50 
10 Jenis Peristiwa Teratas
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    10
Total Pemberitahuan EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

outcome:
  $Count = count($event.security_result.rule_name)
Pemberitahuan EDR menurut Taktik
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Tactic_ID = strings.coalesce($event.security_result.attack_details.tactics.id, $event.security_result.detection_fields["Tactic ID"])
$Tactic_ID != ""
$Tactic_Name = strings.coalesce($event.security_result.attack_details.tactics.name, $event.security_result.detection_fields["Tactic"])
$Tactic_Name != ""
$Severity = $event.security_result.severity

match:
  $Tactic_ID, $Tactic_Name, $Severity
outcome:
  $Count = count($event.security_result.rule_name)
order:
  $Severity desc
limit:
    50
Total Pemberitahuan EDR dari Waktu ke Waktu
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date
outcome:
  $Count = count($event.security_result.rule_name)
order:
  $Date asc
Peristiwa menurut Tingkat Keparahan
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type
$Severity = $event.security_result.severity

match:
  $Event_Type, $Log_Type, $Severity
outcome:
  $Count = count($event.security_result.action)
order:
  $Severity desc
limit:
    50 
Acara Lainnya
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

outcome:
  $Count = sum(if($event.security_result.action = "UNKNOWN_ACTION", 1, 0) + if($event.security_result.action = "FAIL", 1, 0) + if($event.security_result.action = "CHALLENGE", 1, 0))
Total Peristiwa menurut Jenis dari Waktu ke Waktu
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Event_Type = $event.metadata.event_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Event_Type, $Date
outcome:
  $Count = count($event.security_result.action)
order:
  $Date asc
Peristiwa yang Diizinkan Menurut Alamat IP
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "ALLOW"

$Event_Type = $event.metadata.event_type
$IP = $event.principal.ip

match:
  $IP, $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    50
Tindakan Peristiwa menurut Jenis Log
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Action = $event.security_result.action

match:
  $Action, $Log_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    10
Peristiwa yang Diblokir Menurut Alamat IP
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "BLOCK"

$Event_Type = $event.metadata.event_type
$IP = $event.principal.ip

match:
  $IP, $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    50
Peristiwa yang Diblokir oleh Pengguna
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "BLOCK"

$Event_Type = $event.metadata.event_type
$User = strings.coalesce($event.principal.user.user_display_name, $event.principal.user.userid)

match:
  $User, $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
limit:
    50
Peristiwa yang Dikarantina
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "QUARANTINE"

outcome:
  $Count = count($event.security_result.action)
10 Endpoint Teratas menurut Lokasi
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Countries = $event.principal.location.country_or_region
$Countries != ""
$Latitude = $event.principal.location.region_coordinates.latitude
$Longitude = $event.principal.location.region_coordinates.longitude
$Hostname = $event.target.asset.hostname

match:
  $Countries, $Latitude, $Longitude, $Hostname
outcome:
  $Count = count($event.principal.location.country_or_region)
limit:
    10
Acara yang Diblokir
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "BLOCK"

outcome:
  $Count = count($event.security_result.action)
Total Peristiwa dari Waktu ke Waktu
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date
outcome:
  $Count = count($event.security_result.action)
order:
  $Date asc
Peristiwa yang Diizinkan menurut Jenis
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "ALLOW"
or $event.security_result.action = "ALLOW_WITH_MODIFICATION"

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc
Peristiwa yang Diizinkan
$event.metadata.log_type = /_AV|EDR|BEYONDTRUST_ENDPOINT|BITDEFENDER|CISCO_AMP|CISCO_SECURE_WORKLOAD|CS_DETECTS|CS_IDP|CYBERARK_EPM|CYNET_360_AUTOXDR|ENDPOINT_PROTECTOR_DLP|FIREEYE_HX|HALCYON|IBM_SECURITY_VERIFY|JAMF_PRO|JAMF_PROTECT|JAMF_TELEMETRY|KOLIDE|LOOKOUT_MOBILE_ENDPOINT_SECURITY|MACOS|MACOS_ENDPOINT_SECURITY|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_ENDPOINT_IOS|MICROSOFT_DEFENDER_IDENTITY|MICROSOFT_GRAPH_ALERT|MICROSOFT_IAS|MICROSOFT_SCEP|MOBILEIRON|OPENPATH|PASSWORDSTATE|SAVIYNT_EIP|SENTINEL_DV|SENTINELONE_ALERT|SEP|SEQRITE_ENDPOINT|SOPHOS_CENTRAL|SPYCLOUD|TRENDMICRO_APEX_CENTRAL|TRENDMICRO_APEX_ONE|TRENDMICRO_DEEP_SECURITY|TRENDMICRO_STELLAR|TRENDMICRO_VISION_ONE|VENAFI_ZTPKI|WINDOWS_DEFENDER_ATP|WINEVTLOG|WINEVTLOG_XML/
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.action = "ALLOW"
or $event.security_result.action = "ALLOW_WITH_MODIFICATION"

outcome:
  $Count = count($event.security_result.action)

PCI - Enkripsi Data

Dasbor ini memberikan ringkasan praktik enkripsi di seluruh aset PCI. Dasbor ini meningkatkan visibilitas terhadap penggunaan kunci enkripsi, yang menawarkan insight tentang aktivitas Key Management Service (KMS), log Azure Key Vault, dan log Akeyless Vault. Fitur ini menggunakan daftar referensi pci_network_ranges untuk membatasi cakupan data ke lingkungan PCI.

Nama diagram Contoh kueri
Rotasi Kunci lebih dari 30 hari yang lalu
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "RotateKeyOnDemand" or $security_event_type = "RotateKey" or $security_event_type = "KeyRotate" or $security_event_type = /KeyRotationPolicy/ nocase or $security_event_type = "KeyRotateIfDue")
$difference = timestamp.diff(timestamp.current_seconds(), metadata.ingested_timestamp.seconds, "DAY")
$difference > 30
$label = principal.user.attribute.labels.key
$value = principal.user.attribute.labels.value
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$key = target.resource.name
$target_key = target.resource.attribute.labels.key
$target_key = "Recipient Account Id"
$account_Id = target.resource.attribute.labels.value
$date = timestamp.get_date(metadata.ingested_timestamp.seconds)
match:
$date, $account_Id, $user, $IP, $key, $label, $value
outcome:
$age = max($difference)
order:
$age desc
Dekripsi Kunci Gagal
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "Decrypt" or $security_event_type = "KeyDecrypt")
$summary = security_result.summary
$description = metadata.description
$result_type = additional.fields["resultType"]
(re.regex($summary, `Fail`) nocase or re.regex($result_type, `Fail`) nocase)
$message = strings.coalesce(security_result.summary, metadata.description)
$key = target.resource.name
$label = principal.user.attribute.labels.key
$label = "principalId"
$value = principal.user.attribute.labels.value
$role = principal.user.role_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
match:
$user, $IP, $key, $role, $message, $label, $value
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Penghapusan Kunci
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "KeyDelete" or $security_event_type = "ScheduleKeyDeletion" or $security_event_type = "Delete")
$label = principal.user.attribute.labels.key
$user = strings.coalesce(principal.user.attribute.labels.value, principal.user.userid, principal.user.user_display_name,principal.user.email_addresses)
$key = target.resource.name
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$user, $IP, $key, $label, $date
outcome:
$event_count = count(metadata.id)
order:
$date, $event_count desc
Komunikasi Terenkripsi / Tidak Terenkripsi yang Lemah
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$target_key = target.resource.attribute.labels.key
($target_key = "keyProperties_type" or $target_key = "requestParameters.keySpec")
$target_value = target.resource.attribute.labels.value
$target_value != /RSA|AES_256/ nocase
outcome:
$event_count = count_distinct(metadata.id) 
Komunikasi Terenkripsi Lemah/ Tidak Terenkripsi menurut Port
$IP = principal.ip
principal.ip in cidr %PCI_Network_Ranges
$event_type = metadata.event_type
($event_type >= 16000 and $event_type <= 16007)
$port = strings.concat(target.port, "")
$port = /(80|69|23|21|110|143|161|79|88)/
$direction = network.direction
match:
$port, $direction, $event_type
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Kunci Diputar
principal.ip in cidr %PCI_Network_Ranges
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
$log_type = metadata.log_type
$app = target.application
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "RotateKeyOnDemand" or $security_event_type = "RotateKey" or $security_event_type = "KeyRotate" or $security_event_type = /KeyRotationPolicy/ nocase or $security_event_type = "KeyRotateIfDue")
$label = principal.user.attribute.labels.key
$value = principal.user.attribute.labels.value
$user = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$key = target.resource.name
match:
$user, $IP, $key, $label, $value
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Kunci Diaktifkan
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "EnableKey" or $security_event_type = "KeyEnable")
outcome:
$event_count = count(metadata.id) 
Dekripsi Kunci Berhasil
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "Decrypt" or $security_event_type = "KeyDecrypt")
$summary = security_result.summary
$description = metadata.description
$result_type = additional.fields["resultType"]
(re.regex($summary, `Success`) nocase or re.regex($result_type, `Success`) nocase)
$message = strings.coalesce(security_result.summary, metadata.description)
$key = target.resource.name
$label = principal.user.attribute.labels.key
$value = principal.user.attribute.labels.value
$role = principal.user.role_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
match:
$user, $IP, $key, $role, $message, $label, $value
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
50
Kunci Baru
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "CreateKey" or $security_event_type = "KeyCreate")
outcome:
$event_count = count(metadata.id)
Komunikasi Terenkripsi Lemah / Tidak Terenkripsi dari Waktu ke Waktu
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$target_key = target.resource.attribute.labels.key
($target_key = "keyProperties_type" or $target_key = "requestParameters.keySpec")
$target_value = target.resource.attribute.labels.value
$target_value != /RSA|AES_256/ nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
$event_count = count(metadata.id)
order:
$date asc 
Kunci Dinonaktifkan selama lebih dari 30 hari
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
($security_event_type = "DisableKey" or $security_event_type = "Disable")
$difference = timestamp.diff(timestamp.current_seconds(), metadata.ingested_timestamp.seconds, "DAY")
$difference > 30
$account_id = target.resource.attribute.labels.value
$user = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$key = target.resource.name
match:
$account_id, $user, $IP, $key
outcome:
$age = max($difference)
order:
$age desc
Komunikasi Terenkripsi/ Tidak Terenkripsi yang Lemah - 10 Pengguna Teratas
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$target_key = target.resource.attribute.labels.key
($target_key = "keyProperties_type" or $target_key = "requestParameters.keySpec")
$target_value = target.resource.attribute.labels.value
$target_value != /RSA|AES_256/ nocase
$user = strings.coalesce(principal.user.attribute.labels.value, principal.user.userid, principal.user.user_display_name,principal.user.email_addresses)
match:
$user
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit :
10
10 Operasi Utama Teratas
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$security_event_type = metadata.product_event_type
match:
$security_event_type
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
10 Host Teratas dengan Komunikasi Terenkripsi Lemah / Tidak Terenkripsi
$log_type = metadata.log_type
$app = target.application
($log_type = /AZURE_KEYVAULT_AUDIT|AKEYLESS_VAULT/ or $app = "kms.amazonaws.com")
principal.ip in cidr %PCI_Network_Ranges
$IP = principal.ip
$target_key = target.resource.attribute.labels.key
($target_key = "keyProperties_type" or $target_key = "requestParameters.keySpec")
$target_value = target.resource.attribute.labels.value
$target_value != /RSA|AES_256/
$hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$hostname != ""
match:
$hostname
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10 

PCI - Ringkasan Pemberitahuan EDR

Dasbor ini menawarkan tampilan mendetail tentang elemen penting seperti aset, peristiwa, dan deteksi ancaman aktif. Referensi ini menggunakan daftar referensi pci_assets untuk mencakup data ke lingkungan PCI.

Nama diagram Contoh kueri
Jumlah Sensor EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

outcome:
  $Count = count_distinct($event.principal.asset.hostname)
10 Teknik Teratas
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Technique_ID = strings.coalesce($event.security_result.attack_details.techniques.id, $event.security_result.detection_fields["Technique ID"])
$Technique_Name  = strings.coalesce($event.security_result.attack_details.techniques.name, $event.security_result.detection_fields["Technique"])
$Technique_ID != ""
$Technique_Name  != ""

match:
  $Technique_Name
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    107
Tingkat keparahan berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.security_result.summary != ""

$Severity = $event.security_result.severity

match:
  $Severity
outcome:
  $Count = count($event.security_result.summary)
order:
  $Severity asc
limit:
    10
Total Pemberitahuan EDR dari Waktu ke Waktu
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Date asc
10 Pengguna Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$User = $event.principal.user.user_display_name
$User != ""

match:
  $User
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Taktik Teratas
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Tactic_ID = strings.coalesce($event.security_result.attack_details.tactics.id, $event.security_result.detection_fields["Tactic ID"])
$Tactic_Name = strings.coalesce($event.security_result.attack_details.tactics.name, $event.security_result.detection_fields["Tactic"])
$Tactic_ID != ""
$Tactic_Name != ""

match:
  $Tactic_Name
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Pemberitahuan EDR Teratas
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Log_Type = $event.metadata.log_type
$Detection = $event.security_result.summary
$Detection != ""

match:
  $Detection, $Log_Type
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
10 Host Teratas berdasarkan Pemberitahuan EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$Hostname != ""

match:
  $Hostname
outcome:
  $Count = count($event.security_result.summary)
order:
  $Count desc
limit:
    10
Sensor EDR Aktif
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

$EDR_Asset = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $EDR_Asset
limit:
    50
Total Pemberitahuan EDR
$event.metadata.log_type = /EDR|CS_DETECTS|FIREEYE_HX|MICROSOFT_DEFENDER_ENDPOINT|MICROSOFT_DEFENDER_IDENTITY|SENTINEL_DV/ nocase
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets

outcome:
  $Count = count($event.security_result.summary)

PCI - Identity and Access

Dasbor ini memberikan ringkasan mendetail dan real-time tentang aktivitas pengelolaan akses dan terkait identitas untuk mendukung kepatuhan PCI-DSS. Laporan ini menggabungkan metrik dan insight utama, termasuk izin akses pengguna, perubahan sandi, dan peristiwa autentikasi. Referensi ini menggunakan daftar referensi pci_assets untuk mencakup data ke lingkungan PCI.

Nama diagram Contoh kueri
Akun dengan sandi yang tidak pernah berakhir
$event_type = metadata.event_type
$event_type  >= 15000 and $event_type  <= 15014
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$vendor = metadata.vendor_name
$security_event_type = metadata.product_event_type
$key = principal.user.attribute.labels.key
$value = principal.user.attribute.labels.value
($key = /Password Never Expires/ nocase and $value = /true/ nocase)
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$action = security_result.action
match:
$user, $hostname, $vendor, $action, $security_event_type
outcome:
$event_count = count_distinct(metadata.id)
order:
$event_count desc
Mengubah Izin Akun Pengguna
$event_type = metadata.event_type
$event_type = "USER_CHANGE_PERMISSIONS"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$vendor = metadata.vendor_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$action = security_result.action
match:
$user, $hostname, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Akun Pengguna yang Dibuat
$event_type = metadata.event_type
$event_type = "USER_CREATION"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
outcome:
$event_count = count(metadata.id)
Akun Pengguna yang Dibuat
$event_type = metadata.event_type
$event_type = "USER_CREATION"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$vendor = metadata.vendor_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$action = security_result.action
match:
$user, $hostname, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Akun Pengguna Dihapus
$event_type = metadata.event_type
$event_type = "USER_DELETION"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$vendor = metadata.vendor_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$action = security_result.action
match:
$user, $hostname, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Upaya Perubahan Sandi oleh 10 Pengguna Teratas
$event_type = metadata.event_type
$event_type = "USER_CHANGE_PASSWORD"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$vendor = metadata.vendor_name
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$action = security_result.action
match:
$user, $hostname, $vendor, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Akun Pengguna Dihapus
$event_type = metadata.event_type
$event_type = "USER_DELETION"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
outcome:
$event_count = count(metadata.id)
Mengubah Izin Akun Pengguna
$event_type = metadata.event_type
$event_type = "USER_CHANGE_PERMISSIONS"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
outcome:
$event_count = count(metadata.id)
Perubahan Sandi dari waktu ke waktu
$event_type = metadata.event_type
$event_type = "USER_CHANGE_PASSWORD"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
$event_count = count(metadata.id)
order:
$date asc

PCI - Pemantauan dan Pengujian

Dasbor ini menyediakan pemantauan dan pelacakan akses ke data pemegang kartu pembayaran dalam lingkungan PCI. Fungsi ini menggunakan daftar referensi pci_assets dan default_users untuk mencakup data.

Nama diagram Contoh kueri
Peristiwa dari Waktu ke Waktu menurut Jenis Peristiwa
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Akses Resource Teratas menurut Sumber
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$Vendor = metadata.vendor_name
$Action = security_result.action
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Destination_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Source_IP, $Hostname, $Source_User, $Destination_User, $Vendor, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Akses Log Audit
(metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE")
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Vendor = metadata.vendor_name
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Destination_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Source_User, $Destination_User, $Vendor

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")

order:
  $Count desc
Akses Administratif ke Sistem
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Event_Type = metadata.event_type
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$Vendor = metadata.vendor_name
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$User in %Default_Users

match:
  $User, $Hostname, $Vendor, $Event_Type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")

order:
  $Count desc
10 Pengguna Teratas menurut Tindakan
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Action = security_result.action

match:
  $User, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pengguna Tidak Aktif (7 hari terakhir)
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
principal.user.last_login_time.seconds > 0

$Event_Type = metadata.event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Time_Difference = cast.as_int((metadata.event_timestamp.seconds-principal.user.last_login_time.seconds)/86400)

match:
  $User, $Time_Difference

outcome:
  $Logtime = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Lastime = timestamp.get_timestamp(max(principal.user.last_login_time.seconds), "%F %T")

order:
  $Time_Difference desc
   
Deteksi Penghapusan Log (Peristiwa Windows)
metadata.log_type = "WINEVTLOG"
(metadata.product_event_type = "1102" or metadata.product_event_type = "104" or metadata.event_type = "SYSTEM_AUDIT_LOG_WIPE")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Event_Type = metadata.event_type
$Security_Event_Type = metadata.product_event_type
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$Summary = strings.coalesce(metadata.description, security_result.summary, security_result.description)

match:
  $Hostname, $Event_Type, $Security_Event_Type, $Summary

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")

order:
  $Count desc
Perubahan Kebijakan Audit
metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or metadata.event_type = "STATUS_UPDATE"
(security_result.category_details = /AuditPolicyChanges/ nocase or strings.coalesce(metadata.description, security_result.description, security_result.summary, metadata.product_event_type) = /policy change/ nocase)

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Security_Event_Type = metadata.product_event_type
$Policy_Change = strings.coalesce(metadata.description, security_result.description, security_result.summary, security_result.category_details)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Destination_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Source_User, $Destination_User, $Security_Event_Type, $Policy_Change

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")

order:
  $Count desc
Perubahan Kebijakan Audit
(metadata.event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or metadata.event_type = "STATUS_UPDATE")
(security_result.category_details = /AuditPolicyChanges/ nocase or strings.coalesce(metadata.description, security_result.description, security_result.summary, metadata.product_event_type) = /policy change/ nocase)

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

outcome:
  $Count = count(metadata.id)
Peristiwa Gagal
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")
security_result.action = "BLOCK"

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

outcome:
  $Count = count(metadata.id)
Total Peristiwa Gagal menurut Alamat IP Sumber
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")
security_result.action = "BLOCK"

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$Vendor = metadata.vendor_name
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Destination_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Source_IP, $Source_User, $Destination_User, $Hostname, $Vendor, metadata.event_type

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")

order:
  $Count desc
Total Peristiwa menurut Jenis Peristiwa
(metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_DELETION")

(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)

$Event_Type = metadata.event_type
$Vendor = metadata.vendor_name
$Action = security_result.action

match:
  $Event_Type, $Vendor, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

PCI - Jaringan

Dasbor ini memberikan insight tentang performa jaringan dari antarmuka tertentu (sumber atau tujuan), visibilitas real-time untuk aktivitas jaringan teratas, serta tren dan analisis traffic. Fitur ini menggunakan daftar referensi pci_network_ranges untuk membatasi cakupan data ke lingkungan PCI.

Nama diagram Contoh kueri
Jumlah Total Traffic
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

outcome:
  $Count = count($event.network.direction)
10 Tujuan Teratas dengan Traffic menurut Lokasi
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges
$event.target.ip != ""

$Countries = $event.target.location.country_or_region
$Latitude = $event.target.location.region_coordinates.latitude
$Longitude = $event.target.location.region_coordinates.longitude
$Countries != ""

match:
  $Countries, $Latitude, $Longitude
outcome:
  $Count = count($event.target.ip)
limit:
    10
Traffic menurut 10 Tujuan Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$IP_Address = $event.target.ip

match:
  $IP_Address
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Aturan Jaringan yang Paling Sering Dipicu
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$event.metadata.event_type = "NETWORK_UNCATEGORIZED"
or $event.metadata.event_type = "NETWORK_FLOW"
or $event.metadata.event_type = "NETWORK_CONNECTION"
or $event.metadata.event_type = "NETWORK_FTP"
or $event.metadata.event_type = "NETWORK_DHCP"
or $event.metadata.event_type = "NETWORK_DNS"
or $event.metadata.event_type = "NETWORK_HTTP"
or $event.metadata.event_type = "NETWORK_SMTP"
or $event.metadata.event_type = "SCAN_NETWORK"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$Product_Network_Event = $event.security_result.rule_name
$Direction = $event.network.direction
$Product_Network_Event != ""

match:
  $Event_Type, $Log_Type, $Direction, $Product_Network_Event
outcome:
  $Count = count_distinct($event.metadata.id)
order:
  $Count desc
limit:
    10
Traffic menurut 10 Port Tujuan Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Ports = strings.concat($event.target.port, " ")

match:
  $Ports
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Aktivitas Jaringan Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$Security_Action = $event.security_result.action

match:
  $Event_Type, $Log_Type, $Security_Action
outcome:
  $Count = count($event.metadata.event_type)
order:
  $Count desc
limit:
    10
Ringkasan Aktivitas Port
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Source_Port = $event.principal.port
$Target_Port = $event.target.port
$Direction = $event.network.direction
$Event_Type = $event.metadata.event_type

match:
  $Source_Port, $Direction, $Target_Port, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50
Traffic menurut 10 Protokol Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Log_Type = $event.metadata.log_type
$Protocol = $event.network.ip_protocol
$Direction = $event.network.direction

match:
  $Protocol, $Direction
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Data Jaringan yang Diproses dari Waktu ke Waktu (Byte yang Dikirim)
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Total_Bytes = sum($event.network.sent_bytes)
  $GB = math.ceil($Total_Bytes / 1073741824)
order:
  $Date asc
limit:
    50
Data Jaringan yang Diproses dari Waktu ke Waktu (Byte yang Diterima)
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Log_Type = $event.metadata.log_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type
outcome:
  $Total_Bytes = sum($event.network.received_bytes)
  $GB = math.ceil($Total_Bytes / 1073741824)
order:
  $Date asc
limit:
    50
Traffic Jaringan dari Waktu ke Waktu
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Direction = $event.network.direction
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Direction
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Traffic menurut 10 Port Sumber Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Ports = strings.concat($event.principal.port, " ")

match:
  $Ports
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Jumlah Aset Jaringan
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Network_Asset = strings.coalesce($event.principal.ip, $event.principal.asset.ip)

outcome:
  $Count = count_distinct(strings.coalesce($event.principal.ip, $event.principal.asset.ip))
Traffic dari Waktu ke Waktu menurut Protokol
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Protocol = $event.network.ip_protocol
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Protocol
outcome:
  $Count = count_distinct($event.metadata.id)
order:
  $Date asc
Traffic dari Waktu ke Waktu menurut Tindakan
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Security_Result = $event.security_result.action

match:
  $Date, $Security_Result
outcome:
  $Count = count($event.security_result.action)
order:
  $Date asc
Traffic menurut 10 Sumber Teratas
$event.metadata.log_type = /ROUTER|SWITCH|DHCP|PROXY|NETWORK|VPN|FIREWALL|_FLOW|VPC|WIRELESS|IPS|IDS|ARUBA_EDGECONNECT_SDWAN|ARUBA_SWITCH|CISCO_APIC|CISCO_CALL_MANAGER|CISCO_DNAC|CISCO_ESTREAMER|CISCO_IOS|CISCO_PRIME|EFFICIENTIP_DDI|EXTREME_SWITCH|FORTINET_FORTIDDOS|FORTINET_FORTIMANAGER|ARUBA_CENTRAL|JUNIPER_JUNOS|JUNIPER_MIST|JUNIPER_SDWAN|NAGIOS|ARBOR_EDGE_DEFENSE|MICROSOFT_NPS|STEELHEAD|SHRUBBERY_TACACS|TRENDMICRO_DDI|VMWARE_NSX|WINDOWS_NET_POLICY_SERVER|ZYWALL|IMPERVA_FLEXPROTECT|PAN_IOT|NOZOMI_GUARDIAN|SURICATA_EVE|UMBRELLA_DNS|WINDOWS_SYSMON|COHESITY|RUBRIK|CISCO_MERAKI|CLAROTY_EMC|CLAROTY_CTD|HONEYD|AIRWATCH|IMPERVA_SECURESPHERE|SECURELINK|WALLIX_BASTION|CHECKPOINT_HARMONY|UNIFI_AP|DIGI_MODEMS|DESYNOVA_CONTIDO|CLOUDGENIX_SDWAN|JUNIPER_MX|SAP_WEBDISP|ADVA_FSP|HP_PROCURVE|VYOS|RSA_SECURID|HCNET_ACCOUNT_ADAPTER|INFOBLOX|VITALQIP|ASSET_STATIC_IP|BLUECAT_DDI|TWINGATE|SYMANTEC_VIP_AUTHHUB|ZSCALER_DECEPTION|BROCADE_SERVERIRON|KEMP_LOADBALANCER|A10_LOAD_BALANCER|AWS_ELB|F5_BIGIP_LTM|RADWARE_ALTEON|CITRIX_NETSCALER|AKAMAI_CLOUD_MONITOR|CISCO_ACE|GCP_LOADBALANCING|KERIOCONTROL|EXTRAHOP|NETFILTER_IPTABLES|CISCO_UMBRELLA_AUDIT|F5_AFM|NUTANIX_PRISM|SANGFOR_NGAF|VERCEL_WAF|PEPLINK_FW|NETDOCUMENTS|PAN_PANORAMA|PFSENSE|AZION|FIREEYE_PX|OPNSENSE|CISCO_FWSM|FORTINET_FORTIWEB|BARRACUDA_WAF|SYMANTEC_WSS|MENLO_SECURITY|DIGITALARTS_IFILTER|WEBMARSHAL|UMBRELLA_IP|AWS_SECURITY_HUB|EXTRAHOP|GUARDDUTY|MICROSOFT_ATA|ORCA|OSSEC|SURICATA_EVE|VMWARE_TANZU/ nocase
$event.principal.ip in cidr %PCI_Network_Ranges
or $event.principal.asset.ip in cidr %PCI_Network_Ranges

$IP_Address = $event.principal.ip

match:
  $IP_Address
outcome:
  $Count = count_distinct($event.metadata.id)
order:
  $Count desc
limit:
    10

PCI - Pengelolaan Patch

Dasbor ini memberikan tampilan komprehensif tentang siklus proses pengelolaan patch, sehingga organisasi dapat memantau dan mengelola update sistem mereka secara efektif. Fungsi ini menggunakan daftar referensi patch_updates dan pci_assets untuk mencakup data ke lingkungan PCI.

Nama diagram Contoh kueri
10 Penginstalan Berhasil Teratas menurut Host
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "19"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Date, $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Date desc
limit:
    10
Penginstalan Gagal dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "20"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Event = $event.metadata.product_event_type

match:
  $Event, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Sistem dengan Update yang Tersedia
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "40"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Hostname, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
limit:
    10
Penginstalan yang Dibatalkan dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "21"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Hostname, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Download Gagal dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "31"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Hostname, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Download Berhasil dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "16"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Hostname, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Download yang Dimulai dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "41"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Hostname, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
Update Terbaru yang Diinstal
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.description in regex %Patch_Updates
$event.metadata.product_event_type = "19"

$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)
$Hostname != ""
$Update = $event.metadata.description

match:
  $Hostname, $Update
limit:
    50
Penginstalan yang Berhasil dari Waktu ke Waktu
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "19"

$Event = $event.metadata.product_event_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Event, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
10 Penginstalan Gagal Teratas menurut Host
strings.coalesce($event.principal.asset.hostname, $event.principal.hostname) in %PCI_Assets
$event.metadata.product_event_type = "20"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)
$Hostname = strings.coalesce($event.principal.asset.hostname, $event.principal.hostname)

match:
  $Date, $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Date desc
limit:
    10

PCI - Konfigurasi Aman

Dasbor ini memberikan pemantauan real-time terhadap praktik konfigurasi yang aman. Layanan ini melacak metrik utama, menandai risiko, dan membantu mempertahankan konfigurasi penting. Fungsi ini menggunakan daftar referensi pci_assets dan default_users untuk mencakup data ke lingkungan PCI.

Nama diagram Contoh kueri
Upaya Login yang Gagal
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$action = security_result.action
$action = "BLOCK"
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Total Perubahan Kebijakan
$event_type = metadata.event_type
($event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or $event_type = "STATUS_UPDATE")
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$policy_change = strings.coalesce(security_result.description,metadata.product_event_type,security_result.about.registry.registry_key)
$policy_change = /policy change/ nocase
outcome:
$event_count = count(metadata.id)
Penggunaan Akun Default dari Waktu ke Waktu
$date = timestamp.get_date(metadata.event_timestamp.seconds)
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user in %Default_Users
match:
$date, $user
outcome:
$event_count = count(metadata.id)
order:
$date asc
10 Nama Pengguna Default Teratas
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user in %Default_Users
$event_type = metadata.event_type
match:
$user
outcome:
$event_types = array_distinct(metadata.event_type)
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Upaya Login yang Gagal dari Waktu ke Waktu
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$action = security_result.action
$action = "BLOCK"
match:
$date,$action
outcome:
$event_count = count(metadata.id)
order:
$date asc
Perubahan Kebijakan oleh Pengguna
$event_type = metadata.event_type
($event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or $event_type = "STATUS_UPDATE")
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$policy_change = strings.coalesce(security_result.description,metadata.product_event_type,security_result.about.registry.registry_key)
$policy_change = /policy change/ nocase
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
match:
$user
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Upaya Login Gagal menurut 10 Host Teratas
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$hostname != ""
$action = security_result.action
$action = "BLOCK"
match:
$hostname
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Upaya Login Gagal menurut Pengguna
$vendor = metadata.vendor_name
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname,principal.asset.hostname,target.hostname,target.asset.hostname)
$action = security_result.action
$action = "BLOCK"
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user != ""
match:
$user, $hostname, $vendor
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Penggunaan Akun Default menurut Nama Host
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname, principal.asset.hostname,target.hostname,target.asset.hostname)
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user in %Default_Users
match:
$hostname
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Total Autentikasi Nama Pengguna Default
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user in %Default_Users
outcome:
$event_count = count(metadata.id)
Perubahan Kebijakan menurut Sumber Log
$event_type = metadata.event_type
($event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or $event_type = "STATUS_UPDATE")
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$policy_change = strings.coalesce(security_result.description,metadata.product_event_type,security_result.about.registry.registry_key)
$policy_change = /policy change/ nocase
$log_source = metadata.log_type
match:
$log_source
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Perubahan Kebijakan dari Waktu ke Waktu
$event_type = metadata.event_type
($event_type = "SYSTEM_AUDIT_LOG_UNCATEGORIZED" or $event_type = "STATUS_UPDATE")
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$policy_change = strings.coalesce(security_result.description,metadata.product_event_type,security_result.about.registry.registry_key)
$policy_change = /policy change/ nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date, $policy_change
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
Ringkasan Autentikasi Nama Pengguna Default
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$log_type = metadata.log_type
(principal.hostname in %PCI_Assets or principal.asset.hostname in %PCI_Assets or target.hostname in %PCI_Assets or target.asset.hostname in %PCI_Assets)
$hostname = strings.coalesce(principal.hostname, principal.asset.hostname,target.hostname,target.asset.hostname)
$action = security_result.action
$user = strings.coalesce(principal.user.userid,principal.user.user_display_name,principal.user.email_addresses)
$user  in %Default_Users
match:
$user, $hostname, $log_type, $action
outcome:
$event_count = count(metadata.id)
order:
$event_count desc

PCI - Pengelolaan Kerentanan

Dasbor ini menyediakan pemantauan dan pelacakan kerentanan secara real time. Layanan ini mendukung upaya kepatuhan yang lebih luas, membantu mengidentifikasi, menilai, dan mengelola risiko untuk mempertahankan lingkungan pembayaran yang aman sekaligus menyederhanakan pelaporan. Fitur ini menggunakan daftar referensi pci_assets dan pci_network_ranges untuk membatasi cakupan data ke lingkungan PCI.

Nama diagram Contoh kueri
Kerentanan menurut Usia
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$vulnerability = extensions.vulns.vulnerabilities.description
$First_Found = timestamp.get_date(extensions.vulns.vulnerabilities.first_found.seconds)
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$Time_difference = timestamp.diff(metadata.event_timestamp.seconds, extensions.vulns.vulnerabilities.first_found.seconds, "DAY")
match:
$Time_difference,$vulnerability
outcome:
$Range = if(max($Time_difference) <= 30, "0-30Days", if(max($Time_difference) <= 60, "31-60Days", if(max($Time_difference) <= 90, "61-90Days", ">90Days")))
$event_count = count(metadata.id)
order:
$Time_difference desc
10 Host yang Rentan Teratas
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
$asset = strings.coalesce(principal.hostname,principal.asset.hostname,principal.ip,principal.asset.ip)
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$platform = principal.platform
match:
$asset, $platform
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
10 Kerentanan Teratas
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$vulnerability = extensions.vulns.vulnerabilities.description
$platform = principal.platform
match:
$vulnerability,$platform
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Kerentanan Baru
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$First_Found = timestamp.get_date(extensions.vulns.vulnerabilities.first_found.seconds)
$vulnerability = extensions.vulns.vulnerabilities.description
$severity = extensions.vulns.vulnerabilities.severity
$Time_difference = timestamp.diff(metadata.event_timestamp.seconds, extensions.vulns.vulnerabilities.first_found.seconds, "DAY")
$Time_difference < 30
match:
$vulnerability, $severity
outcome:
$event_count = count(metadata.id)
$age = max($Time_difference)
order:
$severity desc
Kerentanan Total
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
outcome:
$event_count = count(metadata.id)
Sistem yang Rentan
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$asset = strings.coalesce(principal.hostname,principal.asset.hostname,principal.ip,principal.asset.ip)
outcome:
$event_count = count_distinct($asset)
Kerentanan menurut Tingkat Keparahan
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$severity = extensions.vulns.vulnerabilities.severity
match:
$severity
outcome:
$event_count = count(metadata.id)
order:
$severity desc
Sistem yang Rentan (Persentase)
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$platform = principal.platform
match:
$platform
outcome:
$event_count = count($platform)
Kerentanan Per Sistem
$event_type = metadata.event_type
($event_type = "SCAN_VULN_HOST" or $event_type = "SCAN_VULN_NETWORK")
$asset = strings.coalesce(principal.hostname,principal.asset.hostname,principal.ip,principal.asset.ip)
(principal.hostname in %PCI_Assets) or (principal.asset.hostname in %PCI_Assets) or (principal.ip in cidr %PCI_Network_Ranges) or (principal.asset.ip in cidr %PCI_Network_Ranges)
$platform = principal.platform
match:
$asset
outcome:
$operating_system = array_distinct($platform)
$event_count = count(metadata.id)
order:
$event_count desc

Dasbor Pemantauan Perubahan Sandi

Dasbor ini melacak dan mencatat perubahan sandi serta memberikan tampilan komprehensif tentang peristiwa perubahan sandi, termasuk tanggal dan waktu perubahan sandi. Layanan ini memvisualisasikan tren, mengidentifikasi risiko seperti alamat IP, pengguna, dan lokasi yang mencurigakan, serta membantu mendeteksi dan merespons potensi insiden keamanan seperti perubahan sandi yang tidak sah.

Nama diagram Contoh kueri
10 IP Sumber Teratas menurut Pengguna
metadata.event_type = "USER_CHANGE_PASSWORD"

$Source_IP =  strings.coalesce(principal.ip, principal.asset.ip)
$Source_IP != ""
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )

match :
  $Source_IP,$User

outcome :
  $Count = count(metadata.id)

order :
  $Count desc

 limit:10

10 Reset Sandi Teratas
metadata.event_type = "USER_CHANGE_PASSWORD"

$Log_Type = metadata.log_type
$Password_Event_Type = metadata.product_event_type
$Description = metadata.description
($Password_Event_Type = /Reset/ nocase OR $Description = /Reset/ nocase)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )

match :
   $User

outcome :
  $Count = count(metadata.id)

order :
  $Count desc

limit: 10
Peristiwa dari Waktu ke Waktu menurut Jenis Log
metadata.event_type = "USER_CHANGE_PASSWORD"

$Log_Type = metadata.log_type

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match :
  $Date,$Log_Type

outcome :
  $Count = count(metadata.id)

Peristiwa Menurut Tindakan
metadata.event_type = "USER_CHANGE_PASSWORD"

$Action =  security_result.action

match :
  $Action

outcome :
  $Count = count(metadata.id)

Peta Panas Geolocation Sumber
metadata.event_type = "USER_CHANGE_PASSWORD"

$Country = principal.ip_geo_artifact.location.country_or_region

match :
  $Country

outcome :
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

order :
  $Count desc
10 Pengguna Teratas menurut tindakan
metadata.event_type = "USER_CHANGE_PASSWORD"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )
$Action =  security_result.action

match :
  $User,$Action

outcome :
  $Count = count(metadata.id)

order :
  $Count desc

limit :
    10
10 Deskripsi Acara Teratas
metadata.event_type = "USER_CHANGE_PASSWORD"

$Description = strings.coalesce(metadata.description,security_result.description,metadata.product_event_type)

match :
  $Description

outcome :

  $Count = count(metadata.id)

order :
  $Count desc

limit :
    10

Perubahan Sandi Pengguna Terbaru (24 jam)
metadata.event_type = "USER_CHANGE_PASSWORD"

$Log_Type = metadata.log_type
$Password_Event_Type = metadata.product_event_type
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses,target.user.userid,target.user.user_display_name,target.user.email_addresses )
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)

match :
  $User,$Hostname,$Source_IP,$Password_Event_Type,$Log_Type

outcome :
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds ), "%F %T")
  $Count = count(metadata.id)

order :
  $Count desc

Peristiwa Menurut Tingkat Keparahan
metadata.event_type = "USER_CHANGE_PASSWORD"

$Severity =  security_result.severity

match :
  $Severity

outcome :
  $Count = count(metadata.id)

Pemantauan Phishing

Dasbor ini memberikan insight tentang ancaman phishing, keamanan email, dan tren serangan. Fitur ini menawarkan visibilitas kepada tim keamanan terkait upaya phishing, sehingga tim dapat memantau aktivitas email berbahaya, mengidentifikasi pengirim dan pengguna yang menjadi target yang mencurigakan, serta menandai indikator yang berpotensi berbahaya.

Nama diagram Contoh kueri
10 Pengguna Teratas di Pemberitahuan Vendor
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"
security_result.rule_name != ""

$User = strings.coalesce(network.email.from, principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 URL Phishing Teratas yang Diakses
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"
metadata.product_event_type = /permit/ nocase

$URL = strings.coalesce (target.url, principal.process.file.embedded_urls, security_result.about.url, network.http.referral_url, principal.url)
$URL != ""
$User = strings.coalesce(network.email.from, principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Action = security_result.action

match:
  $URL, $Action

outcome:
  $User_List = array_distinct($User)
  $Count = count($URL)

order:
  $URL desc

//limit:
//10
10 Subjek Email Phishing Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$Subject = network.email.subject
$Action = security_result.action

match:
  $Subject, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Acara menurut Tindakan
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)

order:
  $Action desc
Peristiwa dari Waktu ke Waktu menurut Jenis Log
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name!= "NOT_PHISHING"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Total Peristiwa Phishing yang Terdeteksi
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

outcome:
  $Count = count(metadata.id)
10 Domain Terkait Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$Domain = strings.coalesce(principal.administrative_domain, target.administrative_domain, about.administrative_domain)
$Action = security_result.action

match:
  $Domain, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pemberitahuan Vendor dari Waktu ke Waktu menurut Tindakan
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"
security_result.rule_name != ""

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Action = security_result.action

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa Phishing Terbaru
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name!= "NOT_PHISHING"

$Security_Event_Type = metadata.product_event_type
$Summary = strings.coalesce(security_result.summary, metadata.description, security_result.description)
$Sender = strings.coalesce(network.email.from, principal.user.email_addresses)
$Subject = network.email.subject

match:
  $Security_Event_Type, $Summary, $Subject, $Sender

outcome:
  $Count = count(metadata.id)
  $Receiver_Count = count_distinct(strings.coalesce(network.email.to, network.email.reply_to, target.user.email_addresses))
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
10 Pemberitahuan Vendor Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"
security_result.rule_name != ""

$Rule_Name = security_result.rule_name

match:
  $Rule_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Nama Ancaman Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$Threat_Name = strings.coalesce(security_result.threat_name,security_result.category_details)
$Log_Type = metadata.log_type

match:
  $Threat_Name, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu menurut Tindakan
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Action = security_result.action

match:
  $Date, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Action asc
10 Pengirim Email Phishing Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

$Sender = strings.coalesce(network.email.from,principal.user.email_addresses)
$Action = security_result.action

match:
  $Sender, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Detail File Phishing
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"
strings.coalesce(target.file.full_path, about.file.full_path, target.file.names) != ""

$File_Path = strings.coalesce(target.file.full_path, about.file.full_path, target.file.names)
$File_Type = strings.coalesce(about.file.mime_type, target.file.mime_type)
$Action = security_result.action
$Receiver = strings.coalesce(network.email.to, network.email.reply_to,target.user.email_addresses)
$Sender = strings.coalesce(network.email.from,principal.user.email_addresses)
$File_Hash = strings.coalesce(about.file.md5, about.file.sha256, security_result.about.file.sha256)

match:
  $File_Path, $File_Type, $File_Hash, $Sender, $Receiver, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Count desc
Peristiwa menurut Jenis file
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$File_Type = strings.coalesce(about.file.mime_type, target.file.mime_type)

match:
  $File_Type

outcome:
  $Count = count(metadata.id)

order:
  $File_Type desc
Pemberitahuan Vendor dari Waktu ke Waktu menurut Jenis Log
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`)nocase)
security_result.threat_name != "NOT_PHISHING"
security_result.rule_name != ""

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 URL Phishing Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$URL = strings.coalesce(target.url, security_result.about.url, network.http.referral_url, principal.process.file.embedded_urls, principal.url)
$URL != ""

match:
  $URL

outcome:
  $Threat_Names = array_distinct(strings.coalesce(security_result.threat_name,security_result.category_details))
  $Categories = array_distinct(security_result.category)
  $Count = count($URL)

order:
  $Count desc

limit:
    10
10 Penerima Email Phishing Teratas
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name!= "NOT_PHISHING"

$Receiver = strings.coalesce(network.email.to, network.email.reply_to, target.user.email_addresses)
$Action = security_result.action

match:
  $Receiver, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Ringkasan Geolocation Sumber
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

$Country = principal.ip_geo_artifact.location.country_or_region
$Country != ""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

order:
  $Count desc
Peristiwa menurut Tingkat Keparahan
(security_result.category = "MAIL_PHISHING" or re.regex(security_result.threat_name,`Phish`) nocase or re.regex(security_result.category_details,`Phish`) nocase)
security_result.threat_name != "NOT_PHISHING"

$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Severity desc

Deteksi Pemindaian Port

Dasbor ini memberikan insight tentang aktivitas pemindaian port dan teknik pengintaian jaringan terkait lainnya yang dapat mengindikasikan potensi ancaman atau aktivitas berbahaya dalam infrastruktur jaringan. Dengan melacak dan memvisualisasikan jenis perilaku ini, Anda dapat mendeteksi, menyelidiki, dan memitigasi upaya akses jaringan yang tidak sah atau mencurigakan.

Nama diagram Contoh kueri
Peristiwa dari Waktu ke Waktu menurut Jenis Log
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Log_Type = metadata.log_type

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
Upaya Koneksi Gagal Terbaru ke Port Standar
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
security_result.action = "BLOCK"
target.port > 19
target.port < 1025

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Principal_IP = principal.ip
$Target_IP = target.ip
$Protocol = network.ip_protocol
$Port = target.port

match:
  $Date, $Principal_IP, $Protocol, $Port, $Target_IP

order:
  $Date desc
Distribusi Tingkat Keparahan
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Pemindaian Port dari Waktu ke Waktu menurut Pengguna
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$User = group(principal.user.userid, principal.user.email_addresses, target.user.userid, target.user.email_addresses)

match:
  $Date, $User

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
10 IP Tujuan Teratas
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$IP_Address = target.ip
$Log_Type = metadata.log_type

match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pemindaian Port Terbaru
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase
principal.ip != ""
target.ip != ""

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Description = strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description)
$Source_IP = principal.ip
$Target_IP = target.ip

match:
  $Date, $Source_IP, $Description, $Target_IP

outcome:
  $Port = array_distinct(target.port)

order:
  $Date desc 
10 Negara Asal Teratas
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Country = principal.location.country_or_region
$Country != ""

match:
  $Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Subnet Internal yang Ditargetkan
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase
net.ip_in_range_cidr(target.ip, "10.0.0.0/8")
or net.ip_in_range_cidr(target.ip, "172.16.0.0/12")
or net.ip_in_range_cidr(target.ip, "192.168.0.0/16")
or net.ip_in_range_cidr(target.ip, "fc00::/7")

$IP_Range = if(net.ip_in_range_cidr(target.ip, "192.168.0.0/16"), strings.concat(re.capture(target.ip, /^\d+\.\d+\.\d+\./), "0/16"),
            if(net.ip_in_range_cidr(target.ip, "172.16.0.0/12"), strings.concat(re.capture(target.ip, /^\d+\.\d+\./), "0.0/12"),
            if(net.ip_in_range_cidr(target.ip, "10.0.0.0/8"), strings.concat(re.capture(target.ip, /^\d+\./), "0.0.0/8"),
            if(net.ip_in_range_cidr(target.ip, "fc00::/7"), strings.concat(re.capture(target.ip, /^(?:[0-9A-Fa-f]{1,4}:){3}[0-9A-Fa-f]{1,4}/), "/64"), "Unknown IP address range"))))

match:
  $IP_Range

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Upaya Koneksi Gagal Terbaru ke Port Non-Standar
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
security_result.action = "BLOCK"
target.port < 19
or target.port > 1025

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Principal_IP = principal.ip
$Target_IP = target.ip
$Protocol = network.ip_protocol
$Port = target.port

match:
  $Date, $Principal_IP, $Protocol, $Port, $Target_IP

order:
  $Date desc
10 Port yang Paling Sering Ditargetkan
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Port = strings.concat(target.port, " ")
$Log_Type = metadata.log_type

match:
  $Port, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Sumber Pemindaian Port Teratas
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Country = principal.location.country_or_region
$Latitude = principal.location.region_coordinates.latitude
$Latitude != 0
$Longitude = principal.location.region_coordinates.longitude
$Longitude != 0

match:
  $Country, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc 
10 IP Sumber Teratas
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$IP_Address = principal.ip
$Log_Type = metadata.log_type

match:
  $IP_Address, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Rasio Port/IP
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Port = target.port
$Source_IP = principal.ip

outcome:
  $Ratio = math.round(count_distinct(target.port) / count_distinct(principal.ip), 2)
Distribusi Protokol
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Protocol = network.ip_protocol

match:
  $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Pemindaian Port dari Waktu ke Waktu menurut Nama Host
metadata.event_type = "SCAN_NETWORK"
or strings.coalesce(security_result.threat_name, security_result.rule_name, security_result.description, security_result.summary, metadata.product_event_type, metadata.description) = /port(?:\s|\_)?scan(?:ning|ner)?/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Hostname = group(principal.hostname, target.hostname)

match:
  $Date, $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 

Ringkasan Port dan Protokol

Dasbor ini menawarkan insight real-time dan historis tentang aktivitas port jaringan dan penggunaan protokol. Alat ini mengidentifikasi port aktif dan tidak aktif, potensi kerentanan, serta membantu mengoptimalkan keamanan dan performa jaringan sekaligus memastikan kepatuhan terhadap kebijakan.

Nama diagram Contoh kueri
Aktivitas Port Baru - Masuk
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Direction = network.direction
$Direction = "INBOUND"
$policy = security_result.rule_name
$port = strings.concat(target.port, "")
$port != /(40202|40203|40462|41611|41612|41620|41629|41674|41684|41685|41694|41703|41712|41721|41730|41747|43448|44924|44925|45071|52818|53025|54736|443|57903|58254|62977|80|88)/
$source_ip = principal.ip
$location = principal.ip_geo_artifact.location.country_or_region
$action = security_result.action
$action != "BLOCK"
match:
  $port, $action
outcome:
  $Source_IP = array_distinct($source_ip)
  $event_count = count(metadata.id)

order:
  $event_count desc
Traffic Port yang Diizinkan vs. Diblokir
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$action = security_result.action
$action != "UNKNOWN_ACTION"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
  $action, $Date
outcome:
  $Event_Count = count(metadata.id)
order:
  $Date asc
10 Port Teratas menurut Traffic - Keluar
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Logtype = metadata.log_type
$Direction = network.direction
$Direction = "OUTBOUND"
$Port = target.port
match:
  $Port
outcome:
  $event_count = count(metadata.id)
  $logtype = array_distinct($Logtype)
order:
  $event_count desc
limit:
    10
Distribusi Protokol
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Protocol = network.ip_protocol
$Protocol != "UNKNOWN_IP_PROTOCOL"
match:
  $Protocol
outcome:
  $Event_Count = count(metadata.id)
Distribusi Protokol
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Protocol = network.ip_protocol
$Protocol != "UNKNOWN_IP_PROTOCOL"
match:
  $Protocol
outcome:
  $Event_Count = count(metadata.id)
Traffic di Port yang Umumnya Dilarang
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$policy = security_result.rule_name
$port = strings.concat(target.port, "")
$port != /(443|53|8080|8081|34622|34756|35406|35466|35546|36602|37276|38976|41394|41672|41926|45432|46354|47416|48678|51664|51824|52086|52818|54052|54958|55276|55890|57488|57666|58546|58914|59388|60388|61000|64450|64482|64498|64598|64674|64707|64735|64739|64740|64795|64828|64880|64905|64945|64962|65004|65019|65050|65094|65114|65169|65202|65223|65264|65287|65323|65346|65378|65392|65456|8728|3389|6379|5555|2222|5060|3128|8888|27017|8088|1080)/
match:
  $port
outcome:
  $event_count = count(metadata.id)
order:
  $event_count desc
limit:
    20
10 Pelabuhan Teratas menurut Traffic - Masuk
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Direction = network.direction
$Direction = "INBOUND"
$Port = target.port
$Logtype = metadata.log_type
match:
  $Port
outcome:
  $event_count = count(metadata.id)
  $logtype = array_distinct($Logtype)
order:
  $event_count desc
limit:
    10
Traffic di Port yang Umumnya Dilarang
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$policy = security_result.rule_name
$port = strings.concat(target.port, "")
$port != /(443|53|8080|8081|34622|34756|35406|35466|35546|36602|37276|38976|41394|41672|41926|45432|46354|47416|48678|51664|51824|52086|52818|54052|54958|55276|55890|57488|57666|58546|58914|59388|60388|61000|64450|64482|64498|64598|64674|64707|64735|64739|64740|64795|64828|64880|64905|64945|64962|65004|65019|65050|65094|65114|65169|65202|65223|65264|65287|65323|65346|65378|65392|65456|8728|3389|6379|5555|2222|5060|3128|8888|27017|8088|1080)/
match:
  $port
outcome:
  $event_count = count(metadata.id)
order:
  $event_count desc
limit:
    20
10 Port Teratas menurut Traffic - Keluar
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Logtype = metadata.log_type
$Direction = network.direction
$Direction = "OUTBOUND"
$Port = target.port
match:
  $Port
outcome:
  $event_count = count(metadata.id)
  $logtype = array_distinct($Logtype)
order:
  $event_count desc
limit:
    10
Traffic Port yang Diizinkan vs. Diblokir
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$action = security_result.action
$action != "UNKNOWN_ACTION"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
  $action, $Date
outcome:
  $Event_Count = count(metadata.id)
order:
  $Date asc
10 Pelabuhan Teratas menurut Traffic - Masuk
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Direction = network.direction
$Direction = "INBOUND"
$Port = target.port
$Logtype = metadata.log_type
match:
  $Port
outcome:
  $event_count = count(metadata.id)
  $logtype = array_distinct($Logtype)
order:
  $event_count desc
limit:
    10
Aktivitas Port Baru - Masuk
$event_type = metadata.event_type
$event_type >= 16000 and $event_type <= 16007
$Direction = network.direction
$Direction = "INBOUND"
$policy = security_result.rule_name
$port = strings.concat(target.port, "")
$port != /(40202|40203|40462|41611|41612|41620|41629|41674|41684|41685|41694|41703|41712|41721|41730|41747|43448|44924|44925|45071|52818|53025|54736|443|57903|58254|62977|80|88)/
$source_ip = principal.ip
$location = principal.ip_geo_artifact.location.country_or_region
$action = security_result.action
$action != "BLOCK"
match:
  $port, $action
outcome:
  $Source_IP = array_distinct($source_ip)
  $event_count = count(metadata.id)

order:
  $event_count desc

PowerShell

Dasbor ini dirancang untuk menganalisis dan memantau aktivitas PowerShell dalam organisasi Anda. Log ini memberikan insight tentang eksekusi perintah, interaksi pengguna, dan potensi risiko keamanan. Dengan menggabungkan dan memvisualisasikan data ini, dasbor membantu mengidentifikasi potensi masalah, melacak ancaman, dan meningkatkan keamanan secara keseluruhan.

Nama diagram Contoh kueri
Jenis Peristiwa Eksekusi Powershell menurut Proses
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Event_Type, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Jalur File Paling Tidak Umum
$event.principal.process.file.full_path = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Full_Path = group($event.principal.process.file.full_path, $event.target.process.file.full_path)
$Full_Path != ""

match:
  $Full_Path
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100
Host yang Paling Jarang
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Hostname = $event.principal.hostname

match:
  $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100

Command Line yang Paling Jarang Digunakan
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    10
Command Line yang Paling Jarang Digunakan
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    10
10 Pengguna Teratas
$event.principal.user.userid != /\$$/
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$User = $event.principal.user.userid
$User != ""

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

PowerShell Events by Security Result Action
$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Action = $event.security_result.action

match:
  $Action
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc 
PowerShell Events by Security Result Action
$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Action = $event.security_result.action

match:
  $Action
outcome:
  $Count = count($event.security_result.action)
order:
  $Count desc 
Least Common Users
$event.principal.user.userid != /\$$/
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$User = $event.principal.user.userid

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100

Koneksi Jaringan Keluar PowerShell
$event.metadata.event_type = "NETWORK_CONNECTION"
$event.network.direction = "OUTBOUND"
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Destination_IP = $event.target.ip
$Source_IP = $event.principal.ip
$Direction = $event.network.direction

match:
  $Source_IP, $Direction, $Destination_IP, $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50
Koneksi Jaringan Keluar PowerShell
$event.metadata.event_type = "NETWORK_CONNECTION"
$event.network.direction = "OUTBOUND"
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Destination_IP = $event.target.ip
$Source_IP = $event.principal.ip
$Direction = $event.network.direction

match:
  $Source_IP, $Direction, $Destination_IP, $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50
Ringkasan Aktivitas Powershell
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type
$Direction = $event.network.direction

match:
  $Event_Type, $Log_Type, $Direction, $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50

10 Command Line Teratas
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Peristiwa PowerShell menurut Tingkat Keparahan
$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Severity = $event.security_result.severity

match:
  $Severity
outcome:
  $Count = count($event.security_result.severity)
order:
  $Count desc
Jenis Peristiwa Eksekusi Powershell menurut Proses
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
Obfuscation Variabel Char
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:powershell(?:\.exe)?).*\[char(?:\]|\[)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*(?:iex|invoke-expression)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*(?:tochararray)/ nocase

$Registry_Value = $event.target.registry.registry_value_data

match:
  $Command_Line, $Registry_Value
outcome:
  $Count = count($event.metadata.id)
limit:
    50
Top 10 Hosts
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Hostname = $event.principal.hostname
$Hostname != ""

match:
  $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Top 10 Users
$event.principal.user.userid != /\$$/
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$User = $event.principal.user.userid

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

File Downloads via PowerShell
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:powershell(?:\.exe)?).*?(?:Invoke\-(?:WebRequest|RestMethod)|Start\-BitsTransfer)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*?(?:system\.net\.(?:http\.httpclient|webclient).*?(?:downloadfile|writeallbytes))/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
limit:
    50
Top 10 Event Types Containing PowerShell
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Powershell Activity Summary
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type
$Log_Type = $event.metadata.log_type
$Direction = $event.network.direction

match:
  $Event_Type, $Log_Type, $Direction, $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    50

Top 10 Command Lines
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Least Common Users
$event.principal.user.userid != /\$$/
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$User = $event.principal.user.userid

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100

Top 10 Hosts
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Hostname = $event.principal.hostname

match:
  $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Top 10 Event Types Containing PowerShell
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Least Common File Paths
$event.principal.process.file.full_path = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Full_Path = group($event.principal.process.file.full_path, $event.target.process.file.full_path)
$Full_Path != ""

match:
  $Full_Path
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100
Powershell Execution by Process Event Type
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Event_Type, $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Top 10 File Paths
$event.principal.process.file.full_path = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Full_Path = group($event.principal.process.file.full_path, $event.target.process.file.full_path)
$Full_Path != ""

match:
  $Full_Path
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Char Variable Obfuscation
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:powershell(?:\.exe)?).*\[char(?:\]|\[)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*(?:iex|invoke-expression)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*(?:tochararray)/ nocase

$Registry_Value = $event.target.registry.registry_value_data

match:
  $Command_Line, $Registry_Value
outcome:
  $Count = count($event.metadata.id)
limit:
    50
Download File melalui PowerShell
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:powershell(?:\.exe)?).*?(?:Invoke\-(?:WebRequest|RestMethod)|Start\-BitsTransfer)/ nocase
or $Command_Line = /(?:powershell(?:\.exe)?).*?(?:system\.net\.(?:http\.httpclient|webclient).*?(?:downloadfile|writeallbytes))/ nocase

match:
  $Command_Line
outcome:
  $Count = count($event.metadata.id)
limit:
    50
Jenis Peristiwa Eksekusi Powershell menurut Proses
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
Peristiwa PowerShell menurut Tingkat Keparahan
$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Severity = $event.security_result.severity

match:
  $Severity
outcome:
  $Count = count($event.security_result.severity)
order:
  $Count desc
10 Jalur File Teratas
$event.principal.process.file.full_path = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Full_Path = group($event.principal.process.file.full_path, $event.target.process.file.full_path)
$Full_Path != ""

match:
  $Full_Path
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Host yang Paling Jarang
$Command_Line = group($event.principal.process.command_line, $event.target.process.command_line)
$Command_Line = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

$Hostname = $event.principal.hostname

match:
  $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    100

Pengelolaan Akses Istimewa

Dasbor ini melacak aktivitas akses istimewa, mengidentifikasi sumber seperti pengguna, nama host, dan alamat IP, sekaligus menandai aset utama. Fitur ini membantu tim keamanan memantau tren akses dan mengelola risiko, sehingga memastikan hanya individu yang berwenang yang dapat mengakses sistem dan data sensitif.

Nama diagram Contoh kueri
10 Administrator Teratas
principal.user.attribute.roles.type = "ADMINISTRATOR"

$Admin = principal.user.userid

match:
  $Admin

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Aset Teratas
$Asset = target.asset.hostname
$Asset != ""

match:
  $Asset

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Acara dari Waktu ke Waktu
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Akun Pengguna Teratas
$Account = target.user.userid
$Account != ""

match:
  $Account

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi Jenis Peristiwa
$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    50
10 Nama Host yang Paling Banyak Ditargetkan
$Hostname = target.hostname
$Hostname != ""

match:
  $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 IP Sumber Teratas
$Source_IP = principal.ip
$Source_IP != ""

match:
  $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Nama Pengguna Sumber Teratas
$Username = principal.user.userid
$Username != ""

match:
  $Username

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 

Ringkasan Acara Proses

Dasbor ini memberi Anda tampilan komprehensif aktivitas jaringan dengan mengumpulkan dan memvisualisasikan data tentang berbagai kejadian proses, host, pengguna, dan peristiwa. Dasbor ini menyoroti metrik, diagram, dan anomali utama untuk memberikan insight penting tentang frekuensi peristiwa dan performa proses. Fitur ini berguna untuk memantau kesehatan sistem secara proaktif, mendeteksi potensi ancaman keamanan melalui perilaku anomali, dan mengidentifikasi area yang perlu ditingkatkan efisiensinya.

Nama diagram Contoh kueri
Total Peristiwa Powershell
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

outcome:
  $Count = count($Powershell)
10 Proses Induk Teratas
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = metadata.event_type
$Parent_Process = re.capture(principal.process.file.full_path, `\w+.exe$`)
$Parent_Process != ""

match:
  $Parent_Process, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = $event.metadata.event_type
$User = strings.concat($event.principal.user.userid, " ")

match:
  $User, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Total Peristiwa Command Shell
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Shell = principal.process.command_line
$Command_Shell = /(?:cmd|shell)\.exe/ nocase or $Command_Shell = /\/(bash|sh|zsh)/ nocase

outcome:
  $Count = count($Command_Shell)
Total Pengguna Unik
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count_distinct($event.principal.user.userid)
Total Peristiwa yang Diblokir
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$event.security_result.action = "BLOCK"

outcome:
  $Count = count($event.metadata.id)
Total Peristiwa Powershell
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Powershell = group(principal.process.command_line, target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

outcome:
  $Count = count($Powershell)
10 Peristiwa Powershell Teratas
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Powershell = group($event.principal.process.command_line, $event.target.process.command_line)
$Powershell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase

match:
  $Powershell
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Hash Teratas
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = metadata.event_type
$Hash = group(principal.process.file.md5, principal.process.file.sha1, principal.process.file.sha256, target.process.file.md5, target.process.file.sha1, target.process.file.sha256)
$Hash != ""

match:
  $Hash, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Memproses Peristiwa
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Hostname = $event.principal.hostname
$User = $event.principal.user.userid
$Parent_Process = $event.principal.process.file.full_path
$Parent_Command_Line = $event.principal.process.command_line
$Target_Process =  $event.target.process.file.full_path
$Target_Command_Line = $event.target.process.command_line

match:
  $Hostname, $User, $Parent_Process, $Parent_Command_Line, $Target_Process, $Target_Command_Line
outcome:
  $Time = timestamp.get_timestamp(max($event.metadata.event_timestamp.seconds))
order:
  $Time desc
limit:
    50
10 Perintah Shell Teratas menurut Pengguna
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Shell = principal.process.command_line
$Shell = /(?:pwsh|powershell(?:_ise)?)\.exe/ nocase
or $Shell = /(?:cmd|shell)\.exe/ nocase
or $Shell = /\/(bash|sh|zsh)/ nocase
$User = principal.user.userid

match:
  $Shell, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Memproses Peristiwa dari Waktu ke Waktu
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Nama Host Teratas
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = metadata.event_type
$Hostname = principal.hostname

match:
  $Hostname, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = metadata.event_type
$User = strings.concat(principal.user.userid, " ")

match:
  $User, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Penghentian Proses dari Waktu ke Waktu
metadata.event_type = "PROCESS_TERMINATION"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Total Peristiwa yang Diblokir
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

security_result.action = "BLOCK"

outcome:
  $Count = count(metadata.id)
Total Pengguna Unik
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count_distinct(principal.user.userid)
Total Peristiwa Proses
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count(metadata.id)
10 Host Teratas
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = $event.metadata.event_type
$Hostname = $event.principal.hostname

match:
  $Hostname, $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Total Peristiwa Proses
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count($event.metadata.id)
Total Host Unik
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count_distinct($event.principal.hostname)
Total Nama Host Unik
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

outcome:
  $Count = count_distinct(principal.hostname)
Total Peristiwa Command Shell
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Shell = $event.principal.process.command_line
$Command_Shell = /(?:cmd|shell)\.exe/ nocase or $Command_Shell = /\/(bash|sh|zsh)/ nocase

outcome:
  $Count = count($Command_Shell)
Distribusi Jenis Peristiwa
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Proses Terbaru
metadata.event_type = "PROCESS_UNCATEGORIZED"
or metadata.event_type = "PROCESS_LAUNCH"
or metadata.event_type = "PROCESS_INJECTION"
or metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or metadata.event_type = "PROCESS_TERMINATION"
or metadata.event_type = "PROCESS_OPEN"
or metadata.event_type = "PROCESS_MODULE_LOAD"

$Hostname = principal.hostname
$User = principal.user.userid
$Parent_Process = principal.process.file.full_path
$Parent_Command_Line = principal.process.command_line
$Target_Process =  target.process.file.full_path
$Target_Command_Line = target.process.command_line

match:
  $Hostname, $User, $Parent_Process, $Parent_Command_Line, $Target_Process, $Target_Command_Line

outcome:
  $Time = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Time desc
10 Peristiwa Command Shell Teratas
$event.metadata.event_type = "PROCESS_UNCATEGORIZED"
or $event.metadata.event_type = "PROCESS_LAUNCH"
or $event.metadata.event_type = "PROCESS_INJECTION"
or $event.metadata.event_type = "PROCESS_PRIVILEGE_ESCALATION"
or $event.metadata.event_type = "PROCESS_TERMINATION"
or $event.metadata.event_type = "PROCESS_OPEN"
or $event.metadata.event_type = "PROCESS_MODULE_LOAD"

$Command_Shell = $event.principal.process.command_line
$Command_Shell = /(?:cmd|shell)\.exe/ nocase or $Command_Shell = /\/(bash|sh|zsh)/ nocase

match:
  $Command_Shell
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10

Pemantauan Sorotan Ransomware

Dasbor ini memberikan tampilan komprehensif tentang aktivitas terkait ransomware yang terdeteksi oleh berbagai alat keamanan dan sumber data. Fitur ini membantu tim keamanan mengidentifikasi dan merespons ancaman ransomware dengan cepat dengan menandai peristiwa terbaru, perangkat yang terpengaruh, dan sumber deteksi.

Nama diagram Contoh kueri
Peristiwa Email Ransomware Terbaru menurut URL/Lampiran
security_result.summary = /ransom/ nocase

$Subject = network.email.subject
$Sender = network.email.from
$Receiver = network.email.to
$Log_Type = metadata.log_type
$Attachments = strings.coalesce(about.file.full_path, security_result.detection_fields["attachmentNames"])
$Summary = security_result.summary
$Url = target.url
$Action = security_result.action
$Severity = security_result.severity

match:
  $Sender, $Receiver, $Subject, $Summary, $Url , $Attachments, $Action, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa VM Ransomware Terbaru
extensions.vulns.vulnerabilities.description = /ransom/ nocase

$Log_Type = metadata.log_type
$Summary = extensions.vulns.vulnerabilities.description
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)

match:
  $Summary, $Hostname, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:

  $Count desc
Peristiwa DLP Ransomware Terbaru
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or security_result.summary = /ransom/ nocase
or security_result.description = /ransom/ nocase or metadata.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase)

$Log_Type = metadata.log_type
$Summary = strings.coalesce(metadata.description, metadata.product_event_type, security_result.summary, security_result.rule_name, security_result.description, security_result.threat_name, security_result.category_details)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$File = strings.coalesce(target.file.full_path, about.file.full_path, target.url)
$Action = security_result.action
$Severity = security_result.severity

match:
  $Summary, $File, $Hostname, $Action, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Ransomware Endpoint Terbaru
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or security_result.summary = /ransom/ nocase or security_result.description = /ransom/ nocase or metadata.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase)

$Log_Type = metadata.log_type
$Summary = strings.coalesce(security_result.description, security_result.rule_name, security_result.threat_name, security_result.category_details, security_result.summary, metadata.description, metadata.product_event_type)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$IP = strings.coalesce(principal.ip, principal.asset.ip, target.ip, target.asset.ip)
$File = strings.coalesce(target.file.full_path, about.file.full_path, target.url)
$Action = security_result.action
$Severity = security_result.severity

match:
  $Summary, $File, $Hostname, $IP, $Action, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
10 Sumber Log Ransomware Teratas
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or extensions.vulns.vulnerabilities.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase or security_result.summary = /ransom/ nocase or metadata.description = /ransom/ nocase or security_result.description = /ransom/ nocase)

$Log_Type = metadata.log_type

match:
  $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Ransomware dari Waktu ke Waktu menurut Produk
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or extensions.vulns.vulnerabilities.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase or security_result.summary = /ransom/ nocase or metadata.description = /ransom/ nocase or security_result.description = /ransom/ nocase)

$Product = metadata.product_name
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Product, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Peristiwa NDR Ransomware Terbaru
(metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
or metadata.event_type = "NETWORK_UNCATEGORIZED")
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or security_result.summary = /ransom/ nocase
or security_result.description = /ransom/ nocase or metadata.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase)

$Log_Type = metadata.log_type
$Summary = strings.coalesce(metadata.product_event_type, metadata.description, security_result.summary, security_result.description, security_result.rule_name, security_result.category_details, security_result.threat_name)
$Threat_Name = security_result.threat_name
$Category = security_result.category_details
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$File = strings.coalesce(target.file.full_path, about.file.full_path, target.url)
$Action = security_result.action
$Severity = security_result.severity

match:
  $Summary, $File, $Threat_Name, $Category, $Hostname, $Action, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa Ransomware Terbaru menurut Nama Host
(security_result.rule_name = /ransom/ nocase or security_result.category_details = /ransom/ nocase or security_result.threat_name = /ransom/ nocase or extensions.vulns.vulnerabilities.description = /ransom/ nocase or metadata.product_event_type = /ransom/ nocase or security_result.summary = /ransom/ nocase or metadata.description = /ransom/ nocase or security_result.description = /ransom/ nocase)

$Log_Type = metadata.log_type
$Summary = strings.coalesce(security_result.summary, security_result.description, metadata.description, metadata.product_event_type, security_result.rule_name , extensions.vulns.vulnerabilities.description, security_result.threat_name, security_result.category_details)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.email_addresses, principal.user.user_display_name, target.user.userid, target.user.email_addresses, target.user.user_display_name)
$File = strings.coalesce(target.file.full_path, about.file.full_path, target.url)
$Action = security_result.action
$Severity = security_result.severity

match:
  $Summary, $File, $Hostname, $User, $Action, $Severity, $Log_Type

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Count desc

Audit Peran & Izin

Dasbor ini adalah dasbor analisis mendalam untuk mengaudit pengelolaan peran dan izin resource langsung.

Nama diagram Contoh kueri
10 Pengguna Teratas yang Membuat Peran
metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $Initiator

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Izin Resource
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
security_result.action = "ALLOW"

$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$Log_Type = metadata.log_type

match:
  $Log_Type, $Initiator

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Peran
metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $Initiator

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Peran yang Baru Dibuat
metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$Role = strings.coalesce(target.user.attribute.roles.name, target.resource.name)

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Role

order:
  $Date desc
10 Resource Teratas dengan Izin yang Diubah
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Resource_Name = target.resource.name

match:
  $Log_Type, $Resource_Name

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber yang Diblokir Teratas dalam Peristiwa Peran
(metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase))
or
(metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase))
or
(metadata.product_event_type = /Delete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase))
security_result.action = "BLOCK"

$IP_Address = principal.ip
$Event = metadata.product_event_type

match:
  $IP_Address, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Izin Resource Berubah dari Waktu ke Waktu
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Tindakan IAM dari Waktu ke Waktu
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_UNCATEGORIZED"
or metadata.event_type = "USER_BADGE_IN"
or metadata.event_type = "USER_COMMUNICATION"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_LOGIN"
or metadata.event_type = "USER_LOGOUT"
or metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_ACCESS"
or metadata.event_type = "USER_RESOURCE_CREATION"
or metadata.event_type = "USER_RESOURCE_DELETION"
or metadata.event_type = "USER_RESOURCE_UPDATE_CONTENT"
or metadata.event_type = "GROUP_UNCATEGORIZED"
or metadata.event_type = "GROUP_CREATION"
or metadata.event_type = "GROUP_DELETION"
or metadata.product_event_type = /(add|delete) group/ nocase
or metadata.event_type = "GROUP_MODIFICATION"
or metadata.product_event_type = /(RemoveUserFrom|AddUserTo|Add member to |Remove member from )|(?:group)/ nocase
or metadata.product_event_type = /(Create|Update|\bDelete).?Role/ nocase
or (security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /(add|update|delete) role definition/ nocase)
security_result.action = "ALLOW"

$Event = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Total Peran yang Diubah
metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase)
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.attribute.roles.name, target.resource.name))
10 IP Sumber Teratas yang Mengubah Peran
 metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count

limit:
    10 
Peran yang Dihapus dari Waktu ke Waktu
metadata.product_event_type = /Delete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Aktivitas di Critical Role
metadata.product_event_type = /Create|Remove|Add|Update/ nocase
strings.coalesce(principal.user.attribute.roles.name, principal.resource.name, target.user.attribute.roles.name, target.resource.name) = /admin/ nocase
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Role = strings.coalesce(principal.user.attribute.roles.name, principal.resource.name, target.user.attribute.roles.name, target.resource.name)
$Event = metadata.product_event_type
$User = if(strings.coalesce(principal.user.attribute.roles.name, principal.resource.name) = /admin/ nocase, strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses),
        if(strings.coalesce(target.user.attribute.roles.name, target.resource.name) = /admin/ nocase, strings.coalesce(target.user.windows_sid, target.user.userid, target.user.email_addresses), ""))
$IP = principal.ip

match:
  $Role, $Event, $Log_Type, $User, $IP

outcome:
  $Date = latest(metadata.event_timestamp)

dedup:
  $Role

order:
  $Date desc
Total Peran yang Dibuat
metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase)
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.attribute.roles.name, target.resource.name))
Peran yang Dibuat dari Waktu ke Waktu
metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peran yang Baru-Baru Ini Diubah
(metadata.event_type = "RESOURCE_WRITTEN"
and metadata.product_event_type = /UpdateRole/ nocase)
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role(?: definition)?/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")
$IP_Address = principal.ip
$Role = strings.coalesce(target.user.attribute.roles.name, target.resource.name)

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $Role

order:
  $Date desc
10 Peran Pembuatan IPS Sumber Teratas
metadata.product_event_type = /Create.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /add role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
KPI Siklus Proses Peran
(metadata.product_event_type = /Create.?Role/ nocase
    or
    (security_result.category_details = /RoleManagement/ nocase and metadata.product_event_type = /add role definition/ nocase)
    and security_result.action = "ALLOW")
or
(metadata.product_event_type = /Update.?Role/ nocase
    or
    (security_result.category_details = /RoleManagement/ nocase and metadata.product_event_type = /update role definition/ nocase)
    and security_result.action = "ALLOW")
or
(metadata.product_event_type = /Delete.?Role/ nocase
    or (security_result.category_details = /RoleManagement/ nocase and metadata.product_event_type = /delete role definition/ nocase)
    and security_result.action = "ALLOW")

$Event = if((metadata.product_event_type = /Create.?Role/ nocase or (security_result.category_details = /RoleManagement/ nocase and metadata.product_event_type = /add role definition/ nocase)), "Total Creation",
            if (metadata.product_event_type = /Update.?Role/ nocase or (security_result.category_details = /RoleManagement/ nocase and metadata.product_event_type = /update role definition/ nocase), "Total Modification", "Total Deletion"))

match:
  $Event

outcome:
  $Count = count_distinct(strings.coalesce(target.user.attribute.roles.name, target.resource.name))

order:
  $Count desc
Peran yang Diubah dari Waktu ke Waktu
metadata.product_event_type = /Update.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /update role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Log_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 IP Sumber Teratas yang Mengubah Izin Resource
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Total Peran yang Dihapus
metadata.product_event_type = /Delete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase)
security_result.action = "ALLOW"

outcome:
  $Count = count_distinct(strings.coalesce(target.user.attribute.roles.name, target.resource.name))
10 IP Sumber Teratas yang Menghapus Peran
metadata.product_event_type = /Delete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Pengguna Teratas yang Menghapus Peran
metadata.product_event_type = /Delete.?Role/ nocase
or
(security_result.category_details = /RoleManagement/ nocase
and metadata.product_event_type = /delete role definition/ nocase)
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator =  strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $Initiator

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 

Enumerasi SMB

Dasbor ini memberi Anda insight yang dapat ditindaklanjuti tentang aktivitas terkait UKM, termasuk tren enumerasi, upaya autentikasi, dan pola akses di seluruh pengguna dan alamat IP. Dengan mengidentifikasi perilaku mencurigakan dan potensi ancaman, fitur ini membantu memitigasi risiko secara efektif.

Nama diagram Contoh kueri
10 Upaya Enumerasi UKM Teratas menurut Pengguna
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Command_Line = target.process.command_line
$User = target.user.userid

match:
  $User, $Command_Line

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Upaya Autentikasi SMB yang Gagal Baru-Baru Ini
metadata.event_type = "NETWORK_CONNECTION"
or metadata.product_event_type = /5157/
target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445
security_result.action = "BLOCK"
or security_result.summary = /failed/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Hostname = principal.hostname
$Source_IP = principal.ip
$User = strings.coalesce(principal.user.userid, target.user.userid)
$Port = target.port

match:
  $Date, $Hostname, $Source_IP, $Port, $User

order:
  $Date desc
Distribusi Protokol Upaya Enumerasi SMB
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Protocol = network.ip_protocol

match:
  $Protocol

outcome:
  $Count = count(network.ip_protocol)

order:
  $Count desc
Distribusi Terdeteksi Alat Enumerasi
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:\bnmap\b.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Tool = re.capture(target.process.command_line, `^\w+`)

match:
  $Tool

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 IP yang Paling Sering Ditargetkan dalam Enumerasi SMB
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Hostname = principal.hostname
$Target_IP = target.ip

match:
  $Target_IP, $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi Status Enumerasi SMB
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Status = if(security_result.action = "ALLOW", security_result.action, "BLOCK")

match:
  $Status

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
IP Sumber dari Waktu ke Waktu
target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count_distinct(principal.ip)

order:
  $Date desc
Perintah SMB dari Waktu ke Waktu
target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smb(?:client|map|status)|enum4linux|(?:get|new|remove|set|close)\-smb)|\bnet\s+(?:use|view|share|session|file|user|group|localgroup|accounts|config|start|stop)\b/ nocase
target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 IP Sumber Teratas
target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445

$Hostname = principal.hostname
$Source_IP = principal.ip
$Source_IP != ""

match:
  $Source_IP, $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Rasio Enumerasi Rata-Rata
stage Enumeration{
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Target_IP = target.ip
$Hour_Bucket = timestamp.get_hour(metadata.event_timestamp.seconds)

match:
  $Hour_Bucket

outcome:
  $Ip_Count = count_distinct($Target_IP)
}

outcome:
  $Avg_Enumeration_Rate = math.round(avg($Enumeration.Ip_Count), 2)
10 Perintah Teratas yang Digunakan dalam Enumerasi SMB
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Command_Line = target.process.command_line

match:
  $Command_Line

outcome:
  $Count = count(target.process.command_line)

order:
  $Count desc

limit:
    10
Deteksi Enumerasi SMB dari Waktu ke Waktu
security_result.rule_name = /smb.*enumeration/ nocase
or (target.process.command_line = /(?:nmap.*(?:\-p(?:\s)?(?:137|138|139|445|139,445)?)(?:(?:\s)?--script smb)?|smbmap|smbclient --list|enum4linux)/ nocase
and (target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445))

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Distribusi Status Autentikasi SMB
metadata.event_type = "NETWORK_CONNECTION"
or metadata.product_event_type = /5156|5157/
target.port = 137
or target.port = 138
or target.port = 139
or target.port = 445

$Status = if(security_result.summary = /failed/, "BLOCK", security_result.action)

match:
  $Status

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

Audit & Pemantauan Aktivitas SecOps

Dasbor ini memberikan insight penting tentang postur keamanan, melacak peristiwa, aktivitas pengguna, dan tindakan yang diblokir dalam Chronicle Google API.

Nama diagram Contoh kueri
Acara dari Waktu ke Waktu
target.application = /(?:chronicle|backstory).googleapis\.com/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Jenis Peristiwa Teratas
target.application = /(?:chronicle|backstory).googleapis\.com/ nocase

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Tindakan yang Diblokir Baru-Baru Ini
target.application = /(?:chronicle|backstory).googleapis.com/ nocase
security_result.action = "BLOCK"

$Date = timestamp.get_timestamp((metadata.event_timestamp.seconds), "%F %T ")
$Description = metadata.description
$Event_Type = metadata.event_type
$User = principal.user.userid

match:
  $Date, $Event_Type, $Description, $User

order:
  $Date desc
10 IP Sumber Teratas menurut Jenis Peristiwa
target.application = /(?:chronicle|backstory).googleapis\.com/ nocase

$Event_Type = metadata.event_type
$Source_IP = principal.ip

match:
  $Event_Type, $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Acara yang Diblokir dari Waktu ke Waktu
target.application = /(?:chronicle|backstory).googleapis.com/ nocase
security_result.action = "BLOCK"

$Date = timestamp.get_date((metadata.event_timestamp.seconds))
$Event_Type = re.capture(metadata.product_event_type, `\b[A-Za-z]+$`)

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa Tidak Biasa di Luar Jam Kerja
target.application = /(?:chronicle|backstory).googleapis.com/ nocase

(
    (timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") = 1 or timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") = 7)
    or
    ((timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") >= 2 and timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") <= 6)
    and
    ((timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") >= 0 and timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") <= 8) or timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") > 19))
)

$Event_Type = metadata.event_type
$Product_Event = metadata.product_event_type

match:
  $Event_Type, $Product_Event

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")

order:
  $Date desc
Tindakan Berisiko Terbaru
target.application = /(?:chronicle|backstory).googleapis.com/ nocase
metadata.product_event_type = /\b(?:Delete|Remove|Disable|Update)/ nocase

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$Event_Type = re.capture(metadata.product_event_type, `\b(?:Delete|Remove|Disable|Update)[A-Za-z]+`)
$Description = metadata.description
$User = re.capture(principal.user.userid, `subject\/([^\/]+)`)

match:
  $Date, $Event_Type, $Description, $User

order:
  $Date desc
10 Pengguna Teratas berdasarkan Tindakan Berisiko
target.application = /(?:chronicle|backstory).googleapis.com/ nocase
metadata.product_event_type = /\b(?:Delete|Remove|Disable|Update)/ nocase

$Event_Type = re.capture(metadata.product_event_type, `\b(?:Delete|Remove|Disable|Update)[A-Za-z]+`)
$User = re.capture(principal.user.userid, `subject\/([^\/]+)`)

match:
  $User, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Pengguna Teratas menurut Jenis Peristiwa
target.application = /(?:chronicle|backstory).googleapis\.com/ nocase

$Event_Type = metadata.event_type
$User = principal.user.userid

match:
  $User, $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa SecOps yang Diblokir menurut Lokasi
target.application = /(?:chronicle|backstory).googleapis.com/ nocase
security_result.action = "BLOCK"

$Countries = principal.location.country_or_region
$Latitude = principal.location.region_coordinates.latitude
$Longitude = principal.location.region_coordinates.longitude

match:
  $Countries, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Tindakan menurut Jenis Peristiwa: Izinkan vs. Blokir
target.application = /(?:chronicle|backstory).googleapis\.com/ nocase
security_result.action = "ALLOW"
or security_result.action = "BLOCK"

$Event_Type = metadata.event_type
$Action = security_result.action

match:
  $Event_Type, $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Tindakan Tidak Biasa di Luar Jam Kerja menurut Kategori
target.application = /(?:chronicle|backstory).googleapis.com/ nocase

(
    (timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") = 1 or timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") = 7)
    or
    ((timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") >= 2 and timestamp.get_day_of_week(metadata.event_timestamp.seconds, "UTC") <= 6)
    and
    ((timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") >= 0 and timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") <= 8) or timestamp.get_hour(metadata.event_timestamp.seconds, "UTC") > 19))
)

$Event_Type = metadata.event_type
$Product_Event = metadata.product_event_type
$Service = re.capture(metadata.product_event_type, `([A-Za-z]+Service)`)

match:
  $Product_Event, $Service

outcome:
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T ")
  $Count = count(metadata.id)

order:
  $Date desc

Pemantauan Log SecOps

Dasbor ini memberikan insight tentang Pengelolaan Data Log, yang menyoroti latensi penyerapan dan status komponen. Alat ini membantu Anda mengoptimalkan performa, mengurangi kehilangan data, dan meningkatkan pemantauan keamanan.

Nama diagram Contoh kueri
Waktu Penyerapan Log Rata-Rata menurut Jenis Log
$Log_Type = metadata.log_type

$Ingestion_Time = math.abs(metadata.ingested_timestamp.seconds - metadata.event_timestamp.seconds)

match:
  $Log_Type

outcome:
  $Avg_Ingestion_Time_ = math.ceil(avg($Ingestion_Time))
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Date desc

Pengelolaan Postur Keamanan

Dasbor ini memberikan ringkasan real-time tentang status keamanan organisasi Anda, yang menyoroti ancaman, insiden, dan kerentanan. Laporan ini mencakup ringkasan deteksi, keamanan, dan update sistem serta pemantauan aset, sehingga tim keamanan dapat menilai risiko dan postur ancaman serta menerapkan strategi perbaikan secara efektif. Tampilan terpusat ini membantu meningkatkan keseluruhan postur keamanan dan menyederhanakan respons insiden.

Ringkasan Akun Layanan

Dasbor ini membantu tim dan administrator keamanan memantau aktivitas akun layanan dengan memberikan insight tentang pola penggunaan, upaya login, dan modifikasi akun. Hal ini memungkinkan pengambilan keputusan yang tepat untuk mengidentifikasi risiko keamanan, mengatasi kerentanan, dan memastikan integritas sistem. Catatan: gunakan filter yang tersedia untuk mempersempit hasil sesuai kebutuhan.

Nama diagram Contoh kueri
10 Tindakan Teratas
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Product_Event = metadata.product_event_type
$Product_Event != ""

match:
  $Product_Event

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Izin yang Baru-Baru Ini Diubah
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
Login Berhasil dari Waktu ke Waktu
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc 
10 Izin Pengguna Teratas yang Diubah
metadata.event_type = "RESOURCE_PERMISSIONS_CHANGE"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$User = strings.coalesce(target.user.userid, target.user.email_addresses)

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perubahan Sandi Terbaru
metadata.event_type = "USER_CHANGE_PASSWORD"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
Akun Layanan yang Dihapus dari Waktu ke Waktu
metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_DELETION"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Login Gagal dari Waktu ke Waktu
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Penggunaan dari Waktu ke Waktu
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Akun Layanan yang Baru Dihapus
metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_RESOURCE_DELETION"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
10 Akun Layanan Teratas berdasarkan Login
metadata.event_type = "USER_LOGIN"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Service_Account = group(principal.user.userid, target.user.userid)
$Service_Account != ""

match:
  $Service_Account

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akun Layanan yang Baru Dibuat
metadata.event_type = "USER_CREATION"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
10 Akun Layanan Teratas
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Service_Account = group(principal.user.userid, target.user.userid)
$Service_Account != ""

match:
  $Service_Account

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akun Layanan yang Dibuat dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Permintaan Tiket Layanan Kerberos Bervolume Tinggi
metadata.product_event_type = /4769/ nocase
target.application != /\$$/ nocase
additional.fields["TicketEncryptionType"] = /0x(1|2|3|12|17)/ nocase
additional.fields["TicketOptions"] = /0x408(1000|0000|1001)0/ nocase

$Host = principal.hostname

match:
  $Host over 1h

outcome:
  $Count = count_distinct(target.application)

condition:
  $Count >= 10

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas berdasarkan Login Gagal
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Source_IP = principal.ip
$Source_IP != ""

match:
  $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas menurut Login Interaktif
metadata.event_type = "USER_LOGIN"
extensions.auth.mechanism = "INTERACTIVE"
or extensions.auth.mechanism = "CACHED_INTERACTIVE"
or extensions.auth.mechanism = "CACHED_REMOTE_INTERACTIVE"
or extensions.auth.mechanism = "REMOTE_INTERACTIVE"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Source_IP = principal.ip

match:
  $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Login Interaktif dari Waktu ke Waktu
metadata.event_type = "USER_LOGIN"
extensions.auth.mechanism = "INTERACTIVE"
or extensions.auth.mechanism = "CACHED_INTERACTIVE"
or extensions.auth.mechanism = "CACHED_REMOTE_INTERACTIVE"
or extensions.auth.mechanism = "REMOTE_INTERACTIVE"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Perubahan Sandi dari Waktu ke Waktu
metadata.event_type = "USER_CHANGE_PASSWORD"
principal.user.account_type = "SERVICE_ACCOUNT_TYPE"
or principal.resource.resource_type = "SERVICE_ACCOUNT"
or principal.user.attribute.roles.type = "SERVICE_ACCOUNT"
or target.user.account_type = "SERVICE_ACCOUNT_TYPE"
or target.resource.resource_type = "SERVICE_ACCOUNT"
or target.user.attribute.roles.type = "SERVICE_ACCOUNT"
or strings.coalesce(principal.resource.type, principal.user.attribute.roles.name, principal.resource.resource_subtype, principal.user.userid, target.resource.type, target.user.attribute.roles.name, target.resource.resource_subtype, target.user.userid) = /(?i)service.*(?:account|^principal$)/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc

Pemantauan Single Sign-On (SSO)

Dasbor ini membantu tim keamanan melacak aktivitas SSO, mendeteksi akses tidak sah, dan mengoptimalkan autentikasi untuk meningkatkan keamanan dan memastikan kepatuhan.

Nama diagram Contoh kueri
Notifikasi Keamanan SSO
$auth_type = extensions.auth.type
$auth_type = "SSO"
$alert_state = security_result.alert_state
$alert_state = "ALERTING"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$action = security_result.action
$action != "UNKNOWN_ACTION"
$event_name = security_result.summary
$severity = security_result.severity
$category = security_result.category_details

match:
$event_name, $severity, $category
outcome :
$count  = count($event_name)

Login SSO dari Waktu ke Waktu menurut Tindakan
extensions.auth.type = "SSO"

$Action = security_result.action
$Event_Type = metadata.event_type
$Event_Type = "USER_LOGIN"
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Action

outcome :
  $Count  = count(metadata.id)

Akses SSO yang Tidak Sah
extensions.auth.type = "SSO"

$User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses, principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Action = security_result.action
$Action != "ALLOW"
$Summary = strings.coalesce(security_result.summary, metadata.description, security_result.description)
$Severity = security_result.severity
$Category = security_result.category_details

match:
  $Summary,$User, $Severity, $Action,$Category

outcome :
  $Count  = count(metadata.id)

Tingkat Keberhasilan vs. Kegagalan SSO
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$action = security_result.action
$action != "UNKNOWN_ACTION"

match:
$action

outcome :
$count  = count($action)
Upaya Login Gagal menurut Pengguna
metadata.event_type = "USER_LOGIN"
extensions.auth.type = "SSO"
security_result.action = "BLOCK"

$User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses, principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$User != ""
match:
  $User

outcome :
  $Count  = count(metadata.id)

order:
  $Count desc
Peristiwa SSO dari Waktu ke Waktu menurut Tingkat Keparahan
extensions.auth.type = "SSO"
$Severity = security_result.severity
(security_result.severity = "CRITICAL" or security_result.severity = "HIGH")

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
$Date, $Severity

outcome :
$Count = count(metadata.id)

order:
$Date asc
Total Login SSO
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""

outcome :
$count  = count($user)

Log Aktivitas SSO
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$location = principal.ip_geo_artifact.location.country_or_region
$summary = security_result.summary
$summary != ""
$action = security_result.action

match:
$summary, $location, $action

outcome :
$count  = count($summary)
order:
$count desc

Login SSO menurut 10 Aplikasi Teratas
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$application = target.application
$application != ""

match:
$application

outcome :
$count  = count($application)
order:
$count desc
limit: 10
Tren Penggunaan SSO
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = target.user.user_display_name
$user != ""
$location = principal.ip_geo_artifact.location.country_or_region
$date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
$auth_type, $date

outcome :
$count  = count($auth_type)

Akses SSO yang Tidak Sah
$auth_type = extensions.auth.type
$auth_type = "SSO"
$alert_state = security_result.alert_state
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$action = security_result.action
$action != "UNKNOWN_ACTION"
$event_name = security_result.summary
$event_name != ""
$severity = security_result.severity
$category = security_result.category_details
$category != ""

match:
$event_name,$user, $severity, $action,$category
outcome :
$count  = count($event_name)

Lokasi Login Anomali SSO
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""
$location = principal.ip_geo_artifact.location.country_or_region
$location != ""
$location != "United States"
match:
$location

outcome :
$count  = count($location)
$latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
$longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

Ringkasan Geolocation Sumber
metadata.event_type = "USER_LOGIN"
extensions.auth.type = "SSO"

$Location = principal.ip_geo_artifact.location.country_or_region

match:
  $Location

outcome :
  $Count  = count(metadata.id)
  $Latitude = max(principal.ip_geo_artifact.location.region_coordinates.latitude)
  $Longitude = max(principal.ip_geo_artifact.location.region_coordinates.longitude)

10 Pengguna Teratas menurut Login
$event_type = metadata.event_type
$event_type = "USER_LOGIN"
$auth_type = extensions.auth.type
$auth_type = "SSO"
$user = strings.coalesce(target.user.user_display_name, principal.user.user_display_name)
$user != ""

match:
$user

outcome :
$count  = count($user)
order:
$count desc
limit:
10
10 Aplikasi Teratas berdasarkan Login Gagal
metadata.event_type = "USER_LOGIN"
extensions.auth.type = "SSO"
security_result.action = "BLOCK"

$Application = target.application
$Application != ""
match:
  $Application

outcome :
  $Count  = count(metadata.id)

Order:
  $Count desc

limit:
    10
10 Pemberitahuan Vendor Teratas
extensions.auth.type = "SSO"

$Rule_Name = security_result.rule_name
$Rule_Name != ""

match:
  $Rule_Name

outcome :
  $Count  = count(metadata.id)

order:
  $Count desc

limit:
    10

Pemantauan Sysmon

Dasbor ini digunakan untuk menganalisis dan memantau log yang dibuat oleh sysmon. Alat ini memberikan insight tentang aktivitas sistem, termasuk pembuatan proses, koneksi jaringan, dan perubahan file. Dengan menggabungkan dan memvisualisasikan data ini, dasbor membantu analis keamanan mengidentifikasi perilaku mencurigakan, melacak potensi ancaman, dan meresponsnya dengan tepat.

Nama diagram Contoh kueri
Peristiwa Layanan Terbaru
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "4"
or metadata.product_event_type = "5"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Host Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$Hostname = $event.principal.hostname
$Hostname != ""

match:
  $Hostname
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
10 ID Peristiwa Sysmon Teratas
metadata.log_type = "WINDOWS_SYSMON"

$Event_ID = metadata.product_event_type

match:
  $Event_ID

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perubahan Registry Autorun dari Waktu ke Waktu
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "12"
or metadata.product_event_type = "13"
or metadata.product_event_type = "14"
target.registry.registry_key = /(?:HKCU|HKLM)\\Software\\Microsoft\\Windows(?:\sNT)?\\CurrentVersion\\(?:Run(?:Once)?|Winlogon\\(?:Shell|Userinit))/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa WMI Terbaru
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "19"
or metadata.product_event_type = "20"
or metadata.product_event_type = "21"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Peristiwa Pemuatan Gambar dari Waktu ke Waktu menurut Status Tanda Tangan
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "7"

$Signature_Status = target.resource.attribute.labels["SignatureStatus"]
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Signature_Status

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Distribusi Jenis Peristiwa
metadata.log_type = "WINDOWS_SYSMON"

$Event_Type = metadata.event_type

match:
  $Event_Type

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Host yang Berbeda
$event.metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count_distinct($event.principal.hostname)
10 Command Line Teratas
metadata.log_type = "WINDOWS_SYSMON"

$Command = target.process.command_line
$Command != ""

match:
  $Command

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Proses Teratas yang Memulai Koneksi Jaringan
metadata.log_type = "WINDOWS_SYSMON"
metadata.event_type = "NETWORK_CONNECTION"

$Process = principal.process.file.full_path

match:
  $Process

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Perincian Jenis Peristiwa
$event.metadata.log_type = "WINDOWS_SYSMON"

$Event_Type = $event.metadata.event_type

match:
  $Event_Type
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
10 File Teratas yang Dibuat
$event.metadata.log_type = "WINDOWS_SYSMON"
$event.metadata.event_type = "FILE_CREATION"

$File = $event.target.file.full_path

match:
  $File
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Domain yang Paling Sering Dikueri DNS menurut Proses Sumber
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "22"

$Source_Process = strings.coalesce(principal.process.file.full_path, principal.hostname)
$Domain = network.dns.questions.name

match:
  $Domain, $Source_Process

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Pengguna Unik
$event.metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count_distinct($event.principal.user.userid)
10 Penyelenggara Teratas
metadata.log_type = "WINDOWS_SYSMON"

$Hostname = principal.hostname
$Hostname != ""

match:
  $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Proses Induk Teratas
metadata.log_type = "WINDOWS_SYSMON"

$Process = principal.process.file.full_path
$Process != ""

match:
  $Process

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Pengguna Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$User = $event.principal.user.userid
$User != ""

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
Memproses Peristiwa Akses dengan Hak Injeksi dari Waktu ke Waktu
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "10"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Target_Process = target.process.file.full_path

match:
  $Date, $Target_Process

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Total Peristiwa Sysmon
$event.metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count($event.metadata.id)
10 Proses Teratas
metadata.log_type = "WINDOWS_SYSMON"

$Process = target.process.file.full_path
$Process != ""

match:
  $Process

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Proses Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$Process = $event.target.process.file.full_path
$Process != ""

match:
  $Process
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 Command Line Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$Command = $event.target.process.command_line
$Command != ""

match:
  $Command
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 ID Peristiwa Sysmon Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$Event_ID = $event.metadata.product_event_type

match:
  $Event_ID
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
Peristiwa Pemuatan Driver dari Waktu ke Waktu menurut Status Tanda Tangan
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "6"

$Signature_Status = target.resource.attribute.labels["SignatureStatus"]
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Signature_Status

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Tren Peristiwa Sysmon
$event.metadata.log_type = "WINDOWS_SYSMON"

$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
10 Proses Teratas yang Memulai Koneksi Jaringan
$event.metadata.log_type = "WINDOWS_SYSMON"
$event.metadata.event_type = "NETWORK_CONNECTION"

$Process = $event.principal.process.file.full_path

match:
  $Process
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 File Teratas yang Dibuat
metadata.log_type = "WINDOWS_SYSMON"
metadata.event_type = "FILE_CREATION"

$Source = principal.process.file.full_path
$File = target.file.full_path

match:
  $File, $Source

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas
metadata.log_type = "WINDOWS_SYSMON"

$User = principal.user.userid
$User != ""

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Total Peristiwa Sysmon
metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count(metadata.id)
Total Host Unik
metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count_distinct(principal.hostname)
Peristiwa Sysmon dari Waktu ke Waktu
metadata.log_type = "WINDOWS_SYSMON"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Kunci Registry yang Paling Banyak Diubah
metadata.log_type = "WINDOWS_SYSMON"
metadata.product_event_type = "13"

$Registry = target.registry.registry_key

match:
  $Registry

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Total Pengguna Unik
metadata.log_type = "WINDOWS_SYSMON"

outcome:
  $Count = count_distinct(principal.user.userid)
10 Proses Induk Teratas
$event.metadata.log_type = "WINDOWS_SYSMON"

$Process = $event.principal.process.file.full_path
$Process != ""

match:
  $Process
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 

Audit Siklus Proses Pengguna

Dasbor ini adalah dasbor mendetail bagi pengelola dan auditor keamanan untuk meninjau aktivitas pengelolaan akun pengguna. Laporan ini memberikan tampilan komprehensif tentang siklus proses pengguna, sehingga membantu memastikan bahwa kebijakan penyediaan dan penghapusan penyediaan diikuti dengan benar.

Nama diagram Contoh kueri
10 IP Sumber Teratas yang Membuat Pengguna
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Akun Pengguna yang Baru Dibuat
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User

order:
  $Date desc
Pengguna yang Dihapus dari Waktu ke Waktu
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Aktivitas dari Akun yang Dinonaktifkan atau Dihapus
$User = strings.coalesce(target.user.userid, target.user.email_addresses, target.user.windows_sid)
$User != ""

match:
  $User

outcome:
  $Deletion_Time = max(if(metadata.event_type = "USER_DELETION", metadata.event_timestamp.seconds, 0))
  $Deletion_Timestamp = timestamp.get_timestamp($Deletion_Time, "%F %T ")
  $Recent_Activity = max(metadata.event_timestamp.seconds)
  $Recent_Activity_Timestamp = timestamp.get_timestamp($Recent_Activity, "%F %T ")
  $Status = if($Deletion_Time != 0 AND ($Recent_Activity > $Deletion_Time), "Active Deleted Account", "Inactive Deleted Account")
  $Event_Activities = array_distinct(metadata.event_type)

condition:
    arrays.contains($Event_Activities, "USER_DELETION") AND $Status != "Inactive Deleted Account"

order:
  $User desc

unselect:
  $Event_Activities, $Deletion_Time, $Recent_Activity
10 IP Sumber Teratas yang Menghapus Pengguna
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Mengubah Pengguna
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Pengguna dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
or metadata.event_type = "USER_DELETION"
or metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$Event = metadata.event_type

match:
  $Date, $Event

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Pengguna yang Dibuat dari Waktu ke Waktu
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
Akun Pengguna Baru-Baru Ini Diubah
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Event_Type = metadata.event_type
$Log_Type = metadata.log_type
$User = strings.coalesce(target.user.userid, target.user.email_addresses)
$Initiator = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)
$IP_Address = principal.ip
$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds, "%F %T ")

match:
  $Date, $Log_Type, $Initiator, $IP_Address, $User, $Event_Type

order:
  $Date desc
Pengguna yang Diubah dari Waktu ke Waktu
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type

outcome:
  $Count = count(metadata.id)

order:
  $Date desc
10 Pengguna Teratas yang Menghapus Pengguna
metadata.event_type = "USER_DELETION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 IP Sumber Teratas yang Mengubah Pengguna
metadata.event_type = "USER_CHANGE_PERMISSIONS"
or metadata.event_type = "USER_CHANGE_PASSWORD"
or metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$IP_Address = principal.ip

match:
  $Log_Type, $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pengguna Teratas yang Membuat Pengguna
metadata.event_type = "USER_CREATION"
security_result.action = "ALLOW"

$Log_Type = metadata.log_type
$User = strings.coalesce(principal.user.windows_sid, principal.user.userid, principal.user.email_addresses)

match:
  $Log_Type, $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Ringkasan Login Pengguna

Dasbor ini memberikan analisis komprehensif tentang aktivitas autentikasi, sehingga membantu Anda mengidentifikasi dan memantau peristiwa login. Hal ini membantu Anda mendeteksi pengguna yang berpotensi berisiko, menganalisis status dan tren login, serta memahami aktivitas geografis dan host terkait. Anda juga dapat menyelidiki perilaku login yang tidak biasa, merespons potensi pelanggaran keamanan, dan mempertahankan keamanan yang kuat melalui pemantauan berkelanjutan dan deteksi ancaman proaktif.

Nama diagram Contoh kueri
Login menurut Negara
metadata.event_type = "USER_LOGIN"

$Country = principal.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Jumlah Login Berhasil dalam Sehari Terakhir
metadata.event_type = "USER_LOGIN"
security_result.action = $action
$action = "ALLOW"
match:
  $action
outcome:
  $event_count = count_distinct(metadata.id)
10 IP Teratas berdasarkan Status Login
metadata.event_type = "USER_LOGIN"

$IP_Address = principal.ip

match:
  $IP_Address

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc

limit:
    10
10 Pembicara Src/Dest Teratas Selama Sehari Terakhir - Byte
metadata.event_type = "NETWORK_CONNECTION"
$pip = principal.ip
$tip = target.ip
match:
  $pip, $tip
outcome:
  $event_count = count_distinct(metadata.id)
  $bytes_sent = sum(network.sent_bytes)
  $bytes_received = sum(network.received_bytes)
order:
  $bytes_sent desc
limit:
    10
10 Aplikasi Teratas menurut Login
metadata.event_type = "USER_LOGIN"

$Application = target.application

match:
  $Application

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Login menurut Aplikasi
target.application != ""
$application = target.application
$login_status = security_result.action
match:
  $application, $login_status
outcome:
  $event_count = count_distinct(metadata.id)
order:
  $event_count desc
10 Pasangan Target Sumber Teratas menurut Jumlah Peristiwa
principal.hostname != ""
target.ip != ""
$source = principal.hostname
$target = target.ip
match:
  $source, $target
outcome:
  $event_count = count_distinct(metadata.id)
order:
  $event_count desc
limit:
    10
Jumlah Login yang Berhasil
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

outcome:
  $Count = count(metadata.id)
Login menurut Status
metadata.event_type = "USER_LOGIN"
$security_result = security_result.action
match:
  $security_result
outcome:
  $event_count = count_distinct(metadata.id)
10 Pengguna Teratas yang Gagal Login
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

$User = target.user.userid

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
10
Pengguna berdasarkan Status Login
metadata.event_type = "USER_LOGIN"

$User = target.user.userid

match:
  $User

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc
Peta Lokasi Login
metadata.event_type = "USER_LOGIN"

$IP_Address = principal.ip
$Latitude = principal.location.region_latitude
$Latitude != 0
$Longitude = principal.location.region_longitude
$Longitude != 0

match:
  $IP_Address, $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Login menurut Status dari Waktu ke Waktu
metadata.event_type = "USER_LOGIN"

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Count asc
Nama Host menurut Status Login
metadata.event_type = "USER_LOGIN"

$Hostname = principal.hostname

match:
  $Hostname

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc
Jumlah Peristiwa Abu menurut IP Target
principal.hostname = "abu"
$target = target.ip
match:
  $target
outcome:
  $event_count = count_distinct(metadata.id)
Login menurut Aplikasi
metadata.event_type = "USER_LOGIN"

$Application = target.application

match:
  $Application

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc

limit:
    10
10 IP Teratas menurut Login Gagal
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

$IP_Address = principal.ip

match:
  $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
5 Pembicara Src/Dest Teratas Selama Sehari Terakhir
metadata.event_type = "NETWORK_CONNECTION"
$ip_pair = strings.concat(principal.ip,"/",target.ip)
principal.ip != "10.9.8.7"
match:
  $ip_pair
outcome:
  $event_count = count_distinct(metadata.id)
order:
  $event_count desc
limit:
    5
10 Nama Host Teratas berdasarkan Login yang Berhasil
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$Hostname = principal.hostname

match:
  $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa Login Akses Kredensial
metadata.event_type = "USER_LOGIN"
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) = /Credential Access/ nocase

outcome:
  $Count = count(metadata.id)
Jumlah Login yang Gagal
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

outcome:
  $Count = count(metadata.id)
IP menurut Status Login
metadata.event_type = "USER_LOGIN"

$IP_Address = principal.ip

match:
  $IP_Address

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc
Login Gagal menurut Jumlah (24 Jam Terakhir)
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

$Date = timestamp.get_timestamp(metadata.event_timestamp.seconds)
$Hostname = principal.hostname
$IP_Address = principal.ip
$User = strings.coalesce(target.user.userid, target.user.user_display_name, principal.user.userid, principal.user.user_display_name)

match:
  $Date, $User, $Hostname, $IP_Address

outcome:
  $Failed_Logins = count(metadata.id)

order:
  $Failed_Logins desc
10 IP Teratas berdasarkan Login yang Berhasil
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$IP_Address = principal.ip

match:
  $IP_Address

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Negara Teratas menurut Login
metadata.event_type = "USER_LOGIN"

$Country = principal.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Jumlah Peristiwa menurut Jenis Log menurut Tanggal
$log_type = metadata.log_type
$date = timestamp.get_date(metadata.event_timestamp.seconds, "America/Los_Angeles")
match:
  $date, $log_type
outcome:
  $event_count = count_distinct(metadata.id)
order:
  $event_count desc
Login menurut Status
metadata.event_type = "USER_LOGIN"

$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 Nama Host Teratas berdasarkan Login Gagal
metadata.event_type = "USER_LOGIN"
security_result.action = "BLOCK"

$Hostname = principal.hostname

match:
  $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Pembicara Src/Dest Teratas Selama Sehari Terakhir
metadata.event_type = "NETWORK_CONNECTION"
$pip = principal.ip
$tip = target.ip
match:
  $pip, $tip
outcome:
  $event_count = count_distinct(metadata.id)
order:
  $event_count desc
limit:
    10
Peristiwa Login Akses Awal
metadata.event_type = "USER_LOGIN"
strings.coalesce(security_result.attack_details.tactics.name, security_result.detection_fields["Tactic"]) = /Initial Access/ nocase

outcome:
  $Count = count(metadata.id)
10 Pengguna Teratas menurut Status Login
metadata.event_type = "USER_LOGIN"

$User = target.user.userid

match:
  $User

outcome:
  $Count = count(metadata.id)
  $Failed_Login_Count = sum(if(security_result.action = "BLOCK", 1, 0))
  $Successful_Login_Count = sum(if(security_result.action = "ALLOW", 1, 0))

order:
  $Count desc

limit:
    10
Tingkat Kegagalan Login
metadata.event_type = "USER_LOGIN"

outcome:
  $Total_Logins = count(metadata.id)
  $Failed_Logins = sum(if(security_result.action = "BLOCK", 1, 0))
  $Failure_Rate = math.round(($Failed_Logins / $Total_Logins), 2) * 100
10 Pengguna Teratas berdasarkan Login Berhasil
metadata.event_type = "USER_LOGIN"
security_result.action = "ALLOW"

$User = target.user.userid

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10

Pemantauan Aktivitas VPN

Dasbor ini memberikan insight tentang peristiwa VPN yang terkait dengan keamanan.

Nama diagram Contoh kueri
Sumber Koneksi Geografis
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$location = principal.location.country_or_region
$location != ""
match:
$location
outcome:
$event_count = count($location)
$latitude = max(principal.location.region_coordinates.latitude)
$longitude = max(principal.location.region_coordinates.longitude)
10 Upaya VPN Gagal Teratas Berdasarkan Pengguna dan IP
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$summary = security_result.summary
($summary = /fail/ or additional.fields["connection-attempt-status"] = /fail/ or metadata.product_event_type = /fail/)
$user = principal.user.user_display_name
$src_ip = principal.ip
match:
$user,$src_ip
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit :
10
Tren Penggunaan VPN
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
$event_count = count(metadata.id)
order:
$date asc 
Penggunaan Bandwidth VPN dari Waktu ke Waktu
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$sent_bytes = network.sent_bytes
$received_bytes = network.received_bytes
match:
$date
outcome:
$total_sent_bytes = sum($sent_bytes)
$total_received_bytes = sum($received_bytes)
$total_bandwidth = $total_sent_bytes + $total_received_bytes
$total_bandwidth_kb = $total_bandwidth/ 1024
order:
$date asc
Tren Penggunaan VPN
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date
outcome:
$event_count = count(metadata.id)
order:
$date asc 
Distribusi Platform Sumber
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$platform = principal.platform
match:
  $platform
outcome:
$event_count = count(metadata.id)  
10 Pengguna VPN Teratas menurut Jumlah Peristiwa
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$user = strings.coalesce(principal.user.user_display_name,target.user.user_display_name)
$user != ""
match:
$user
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
10 IP Target Teratas
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$dest_ip = target.ip
$dest_ip != ""
match:
$dest_ip
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
Penggunaan Bandwidth VPN dari Waktu ke Waktu
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$date = timestamp.get_date(metadata.event_timestamp.seconds)
$sent_bytes = network.sent_bytes
$received_bytes = network.received_bytes
match:
$date
outcome:
$total_sent_bytes = sum($sent_bytes)
$total_received_bytes = sum($received_bytes)
$total_bandwidth = $total_sent_bytes + $total_received_bytes
$total_bandwidth_kb = $total_bandwidth/ 1024
order:
$date asc
Koneksi VPN Aktif
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$src_ip = principal.ip
$dest_ip = target.ip
$end_time = additional.fields["connection-end-time"]
$end_time = "NA"
$user = target.user.user_display_name
$session_duration = timestamp.diff(metadata.ingested_timestamp.seconds,timestamp.as_unix_seconds(additional.fields["connection-start-time"]))
$session_duration > 100
match:
  $user,$src_ip,$dest_ip,$session_duration
outcome:
$event_count = count(metadata.id)
order:
$session_duration desc,$user asc
Sumber Koneksi Geografis
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$location = principal.location.country_or_region
$location != ""
match:
$location
outcome:
$event_count = count($location)
$latitude = max(principal.location.region_coordinates.latitude)
$longitude = max(principal.location.region_coordinates.longitude)
10 Upaya VPN Gagal Teratas Berdasarkan Pengguna dan IP
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$summary = security_result.summary
($summary = /fail/ or additional.fields["connection-attempt-status"] = /fail/ or metadata.product_event_type = /fail/)
$user = principal.user.user_display_name
$src_ip = principal.ip
match:
$user,$src_ip
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit :
10
Distribusi Platform Sumber
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$platform = principal.platform
match:
  $platform
outcome:
$event_count = count(metadata.id)  
Koneksi VPN Aktif
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$src_ip = principal.ip
$dest_ip = target.ip
$end_time = additional.fields["connection-end-time"]
$end_time = "NA"
$user = target.user.user_display_name
$session_duration = timestamp.diff(metadata.ingested_timestamp.seconds,timestamp.as_unix_seconds(additional.fields["connection-start-time"]))
$session_duration > 100
match:
  $user,$src_ip,$dest_ip,$session_duration
outcome:
$event_count = count(metadata.id)
order:
$session_duration desc,$user asc
Keberhasilan vs. Kegagalan Koneksi VPN
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$summary = strings.coalesce(security_result.summary, metadata.product_event_type, additional.fields["connection-attempt-status"])
($summary = /fail/ or $summary = /success/)
match:
$summary
outcome:
$event_count = count(metadata.id)  
Keberhasilan vs. Kegagalan Koneksi VPN
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$summary = strings.coalesce(security_result.summary, metadata.product_event_type, additional.fields["connection-attempt-status"])
($summary = /fail/ or $summary = /success/)
match:
$summary
outcome:
$event_count = count(metadata.id)  
10 Pengguna VPN Teratas menurut Jumlah Peristiwa
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$user = strings.coalesce(principal.user.user_display_name,target.user.user_display_name)
$user != ""
match:
$user
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10
10 IP Target Teratas
$log_type = metadata.log_type
$log_type = /VPN|Zscaler_ZPA|ZSCALER_DECEPTION|TWINGATE|SYMANTEC_VIP_AUTHHUB/nocase
$dest_ip = target.ip
$dest_ip != ""
match:
$dest_ip
outcome:
$event_count = count(metadata.id)
order:
$event_count desc
limit:
10

Pemantauan Firewall Aplikasi Web (WAF)

Dasbor ini dirancang untuk memantau dan menganalisis aktivitas firewall aplikasi web guna meningkatkan keamanan dan pengelolaan ancaman. Layanan ini memberikan insight real-time tentang keamanan aplikasi web dengan melacak berbagai metrik dan peristiwa yang terkait dengan operasi WAF, sehingga membantu Anda mengelola dan merespons potensi ancaman berbasis web secara efektif.

Nama diagram Contoh kueri
Deteksi Traffic yang Tidak Wajar
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Action = security_result.action
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date

outcome:

$count = count(metadata.id)
10 Hit Aturan WAF Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Rule_Name = security_result.rule_name

match:
$Rule_Name, $Log_Type

outcome:

$count = count(metadata.id)

order:
$count desc

limit:
10
10 IP Sumber Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Source_IP = principal.ip
$Geolocation = principal.location.country_or_region

match:
$Source_IP, $Geolocation

outcome:

$Action = array_distinct(security_result.action)
$count = count(metadata.id)

Order:
$count desc

limit:
10
Permintaan yang Diblokir vs. Permintaan yang Diizinkan
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Action = security_result.action

match:
$Action

outcome:

$count = count(metadata.id)
Permintaan yang Diblokir vs. Permintaan yang Diizinkan
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Action = security_result.action

match:
$Action

outcome:

$count = count(metadata.id)
Geolokasi Serangan
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Geolocation = principal.location.country_or_region

match:
$Geolocation

outcome:
$Latitude = max(principal.location.region_latitude)
$Longitude = max(principal.location.region_longitude)

$count = count(metadata.id)
10 IP Sumber Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Source_IP = principal.ip
$Source_IP != ""
$Geolocation = principal.location.country_or_region

match:
$Source_IP, $Geolocation

outcome:

$Action = array_distinct(security_result.action)
$count = count(metadata.id)

Order:
$count desc

limit:
10
10 Jenis Serangan Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Description = security_result.description

match:
$Description, $Log_Type

outcome:

$Action = array_distinct(security_result.action)
$count = count(metadata.id)

order:
$count desc

limit:
10
Deteksi Traffic Anomali
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Action = security_result.action
$date = timestamp.get_date(metadata.event_timestamp.seconds)
match:
$date

outcome:

$count = count(metadata.id)
10 Jenis Serangan Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Description = security_result.description
$Description != ""

match:
$Description, $Log_Type

outcome:

$Action = array_distinct(security_result.action)
$count = count(metadata.id)

order:
$count desc

limit:
10
Geolokasi Serangan
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$Geolocation = principal.location.country_or_region

match:
$Geolocation

outcome:
$Latitude = max(principal.location.region_latitude)
$Longitude = max(principal.location.region_longitude)

$count = count(metadata.id)
10 Hit URL Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$URL = target.url
$URL != ""

match:
$URL, $Log_Type

outcome:

$count = count(metadata.id)

order:
$count desc

limit:
10
10 Hit Aturan WAF Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/
$Rule_Name = security_result.rule_name
$Rule_Name != ""

match:
$Rule_Name, $Log_Type

outcome:

$count = count(metadata.id)

order:
$count desc

limit:
10
10 Hit URL Teratas
$Log_Type = metadata.log_type
$Log_Type = /WAF/ nocase
$URL = target.url

match:
$URL, $Log_Type

outcome:

$count = count(metadata.id)

order:
$count desc

limit:
10

Ringkasan Web Center

Dasbor ini memantau dan menganalisis pola traffic web dan aktivitas pengguna di seluruh jaringan. Laporan ini memberikan insight tentang agen pengguna, sumber, tujuan, dan URL teratas, sehingga membantu Anda melacak penggunaan dan mendeteksi potensi risiko.

Nama diagram Contoh kueri
Penggunaan Versi TLS yang Lemah dari Waktu ke Waktu
metadata.event_type = "NETWORK_HTTP"
network.tls.version = /^tls/ nocase

$Date = timestamp.get_date(metadata.event_timestamp.seconds)
$TLS_Version = network.tls.version
$TLS_Version != ""

match:
  $Date, $TLS_Version

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Distribusi Cipher TLS
network.tls.cipher = /^tls/ nocase

$TLS = network.tls.cipher
$TLS != ""

match:
  $TLS

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
10 URL teratas
$event.metadata.event_type = "NETWORK_HTTP"

$URL = $event.target.url
$URL != ""

match:
  $URL
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
URL Paling Tidak Umum
metadata.event_type = "NETWORK_HTTP"

$URL = target.url
$URL != ""

match:
  $URL

outcome:
  $Count = count(metadata.id)

order:
  $Count asc

limit:
    10
Distribusi Komunikasi Tidak Terenkripsi
metadata.event_type = "NETWORK_UNCATEGORIZED"
or metadata.event_type = "NETWORK_FLOW"
or metadata.event_type = "NETWORK_CONNECTION"
or metadata.event_type = "NETWORK_FTP"
or metadata.event_type = "NETWORK_DHCP"
or metadata.event_type = "NETWORK_DNS"
or metadata.event_type = "NETWORK_HTTP"
or metadata.event_type = "NETWORK_SMTP"
network.application_protocol = "HTTP"
or network.application_protocol = "SMTP"
or network.application_protocol = "DNS"

$Protocol = network.application_protocol

match:
  $Protocol

outcome:
  $Count = count(metadata.id)

order:
  $Count desc
Peristiwa dari Waktu ke Waktu Menurut Metode HTTP
$event.metadata.event_type = "NETWORK_HTTP"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$HTTP_Method = $event.network.http.method
$HTTP_Method != ""
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type, $Event_Type, $HTTP_Method
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
10 IP Tujuan Teratas
$event.metadata.event_type = "NETWORK_HTTP"

$Destination_IP = $event.target.ip

match:
  $Destination_IP
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
10 Kategori Web Teratas
$event.metadata.event_type = "NETWORK_HTTP"

$Log_Type = $event.metadata.log_type
$Event_Type = $event.metadata.event_type
$Categories = $event.security_result.category_details
$Categories != ""

match:
  $Event_Type, $Log_Type, $Categories
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
10 Pengguna Teratas menurut Metode HTTP
metadata.event_type = "NETWORK_HTTP"

$User = principal.user.userid
$User != ""
$HTTP_Method = network.http.method
$HTTP_Method = /PUT|POST|DELETE/ nocase

match:
  $User, $HTTP_Method

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Agen Pengguna HTTP Teratas
$event.metadata.event_type = "NETWORK_HTTP"

$User_Agent = $event.network.http.user_agent
$User_Agent != ""

match:
  $User_Agent
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10
10 IP Sumber Teratas
metadata.event_type = "NETWORK_HTTP"

$Source_IP = principal.ip

match:
  $Source_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Peristiwa dari Waktu ke Waktu Menurut Metode HTTP
metadata.event_type = "NETWORK_HTTP"

$Log_Type = metadata.log_type
$Event_Type = metadata.event_type
$HTTP_Method = network.http.method
$HTTP_Method != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Log_Type, $Event_Type, $HTTP_Method

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 Pengguna Teratas berdasarkan Byte yang Didownload
metadata.event_type = "NETWORK_HTTP"
network.http.method = "GET"

$User = principal.user.userid
$User != ""

match:
  $User

outcome:
  $Count = sum(network.received_bytes)

order:
  $Count desc

limit:
    10 
10 Pengguna Teratas
$event.metadata.event_type = "NETWORK_HTTP"

$User = $event.principal.user.userid
$User != ""

match:
  $User
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
URL Paling Tidak Umum
$event.metadata.event_type = "NETWORK_HTTP"

$URL = $event.target.url
$URL != ""

match:
  $URL
outcome:
  $Count = count($event.metadata.id)
order:
  $Count asc
limit:
    10 
10 URL teratas
metadata.event_type = "NETWORK_HTTP"

$URL = target.url
$URL != ""

match:
  $URL

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 IP Tujuan Teratas
metadata.event_type = "NETWORK_HTTP"

$Destination_IP = target.ip

match:
  $Destination_IP

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Agen Pengguna HTTP Teratas
metadata.event_type = "NETWORK_HTTP"

$User_Agent = network.http.user_agent
$User_Agent != ""

match:
  $User_Agent

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Negara Teratas berdasarkan URL yang Diblokir
metadata.event_type = "NETWORK_HTTP"
security_result.action = "BLOCK"

$URL = target.url
$URL != ""
$Country = target.location.country_or_region

match:
  $Country

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Peristiwa dari Waktu ke Waktu Menurut Kode Respons HTTP
$event.metadata.event_type = "NETWORK_HTTP"

$Response_Code = strings.concat($event.network.http.response_code, " ")
$Date = timestamp.get_date($event.metadata.event_timestamp.seconds)

match:
  $Date, $Response_Code
outcome:
  $Count = count($event.metadata.id)
order:
  $Date asc
URL yang Diblokir Berdasarkan Lokasi
metadata.event_type = "NETWORK_HTTP"
security_result.action = "BLOCK"

$URL = target.url
$URL != ""

$Latitude = target.location.region_latitude
$Longitude = target.location.region_longitude

match:
  $Latitude, $Longitude

outcome:
  $Count = count(metadata.id)

order:
  $Count desc 
10 URL Teratas yang Diblokir
$event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.action = "BLOCK"

$Blocked_URL = $event.target.url

match:
  $Blocked_URL
outcome:
  $Event_Count = count($event.metadata.id)
order:
  $Event_Count desc
limit:
    10
Peristiwa dari Waktu ke Waktu Menurut Kode Respons HTTP
metadata.event_type = "NETWORK_HTTP"

$Response_Code = strings.concat(network.http.response_code, " ")
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Response_Code

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
10 URL Teratas yang Diblokir
metadata.event_type = "NETWORK_HTTP"
security_result.action = "BLOCK"

$Blocked_URL = target.url

match:
  $Blocked_URL

outcome:
  $Event_Count = count(metadata.id)

order:
  $Event_Count desc

limit:
    10
Tingkat Kegagalan Web
metadata.event_type = "NETWORK_HTTP"

$Response_Code = strings.concat(network.http.response_code, " ")

outcome:
  $Total_Count = count(metadata.id)
  $Failure_Count = sum(if($Response_Code = /^(4|5)/, 1, 0))
  $Failure_Rate = math.round($Failure_Count / $Total_Count, 2) * 100
10 Kategori Web Teratas
metadata.event_type = "NETWORK_HTTP"

$Log_Type = metadata.log_type
$Event_Type = metadata.event_type
$Categories = security_result.category_details
$Categories != ""

match:
  $Event_Type, $Log_Type, $Categories

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
Peristiwa HTTP yang Diblokir menurut Lokasi
$event.metadata.event_type = "NETWORK_HTTP"
$event.security_result.action = "BLOCK"

$URL = $event.target.url
$URL != ""

$Latitude = $event.target.location.region_latitude
$Longitude = $event.target.location.region_longitude

match:
  $Latitude, $Longitude
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc 
10 IP Utama Teratas
$event.metadata.event_type = "NETWORK_HTTP"

$Source_IP = $event.principal.ip

match:
  $Source_IP
outcome:
  $Count = count($event.metadata.id)
order:
  $Count desc
limit:
    10 
10 Pengguna Teratas
metadata.event_type = "NETWORK_HTTP"

$User = principal.user.userid
$User != ""

match:
  $User

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10 
10 Pengguna Teratas berdasarkan Byte yang Diupload
metadata.event_type = "NETWORK_HTTP"
network.http.method = "POST"

$User = principal.user.userid
$User != ""

match:
  $User

outcome:
  $Count = sum(network.sent_bytes)

order:
  $Count desc

limit:
    10 

Ringkasan Keamanan Windows

Dasbor ini menganalisis aktivitas pengguna dan sistem seperti pengelolaan akun, pola login, detail ancaman, dan perubahan konfigurasi untuk memberikan gambaran komprehensif tentang postur keamanan Windows serta meningkatkan kemampuan deteksi dan respons terhadap ancaman.

Nama diagram Contoh kueri
Tugas Terjadwal Terbaru yang Dibuat
metadata.product_event_type = "4698"
metadata.event_type = "SCHEDULED_TASK_CREATION"

$Description = strings.coalesce(metadata.description,security_result.description,security_result.summary)
$Event_Type = metadata.event_type
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses )
$Severity = security_result.severity

match:
  $Source_User, $Source_Hostname, $Description ,$Source_IP , $Event_Type, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Date desc, $Count desc
Login Berhasil vs. Gagal dari Waktu ke Waktu
(metadata.product_event_type = "4625" OR metadata.product_event_type = "4624")

$Action = security_result.action
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Action, $Date

outcome:
  $Count = count(metadata.id)

Order:
  $Date asc

Penghapusan Akun Pengguna
(metadata.event_type = "USER_DELETION" OR metadata.product_event_type = "4726")

$Action = security_result.action
$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname, principal.asset.asset_id,intermediary.hostname)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Target_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)

match:
  $Source_IP, $Hostname, $Source_User, $Target_User,$Action

outcome :
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Date desc 
10 Akun Pengguna Teratas berdasarkan Kegagalan Login
metadata.product_event_type = "4625"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, intermediary.hostname, target.hostname, target.asset.hostname)

 match:
  $User, $Hostname

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Distribusi Pemberitahuan menurut Host (Defender ATP)
metadata.product_event_type = "DeviceAlertEvents"

$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)

match:
   $Hostname

outcome:
  $Critical = sum(if(security_result.severity = "CRITICAL", 1, 0))
  $High = sum(if(security_result.severity = "HIGH", 1, 0))
  $Medium = sum(if(security_result.severity = "MEDIUM", 1, 0))
  $Low = sum(if(security_result.severity = "LOW", 1, 0))
  $Information = sum(if(security_result.severity = "INFORMATIONAL", 1, 0))
  $Error = sum(if(security_result.severity = "ERROR", 1, 0))
  $Unknown_Severity = sum(if(security_result.severity = "UNKNOWN_SEVERITY", 1, 0))
  $Count = count(security_result.severity)

order :
  $Count desc
Ancaman Windows Defender ATP
metadata.product_event_type = "DeviceAlertEvents"

$Threat_Name = security_result.threat_name
$Threat_Category = security_result.category_details
$Threat_Summary = security_result.summary
$Threat_Severity = security_result.severity
$Threat_Action = security_result.action
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$Threat_Name != ""

match:
  $Threat_Name, $Threat_Category, $Threat_Severity, $Threat_Action, $Hostname, $Threat_Summary

outcome:
  $Count = count(metadata.id)

order :
  $Count desc
Distribusi Tindakan Ancaman
security_result.threat_name != ""
$Action = security_result.action

match:
  $Action

outcome:
  $Count = count(metadata.id)
Log Peristiwa Keamanan Dihapus
(metadata.product_event_type = "104" OR metadata.product_event_type = "1102" )

$Description = strings.coalesce(metadata.description,security_result.description,security_result.summary)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Severity = security_result.severity

match:
  $Source_Hostname, $Description, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Count desc
Status Perlindungan Endpoint dari Waktu ke Waktu (Antivirus Defender)
(metadata.product_event_type = "MALWAREPROTECTION_RTP_DISABLED" OR metadata.product_event_type = "MALWAREPROTECTION_RTP_ENABLED")

$Event_Type = metadata.product_event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Date, $Event_Type

outcome:
  $Count = count(metadata.id)

order :
  $Date asc
Pembuatan & Penghapusan Akun dari Waktu ke Waktu
(metadata.event_type = "USER_CREATION" OR metadata.event_type = "USER_DELETION" OR metadata.product_event_type = "4726" OR metadata.product_event_type = "4720")

$Event_Type = metadata.event_type
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Event_Type, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Perubahan Kebijakan Audit Terbaru
metadata.product_event_type= "4719"

$Description = metadata.description
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Source_Domain = principal.administrative_domain
$Category = extracted.fields["AuditPolicyChanges"]
$Changes = extracted.fields["Changes"]
$Severity = security_result.severity

match:
   $User, $Source_Domain, $Hostname, $Description,$Severity, $Category, $Changes

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
   $Severity desc, $Count desc
Deteksi Ancaman dari Waktu ke Waktu
$Threat_Name = security_result.threat_name
$Threat_Name != ""
$Date = timestamp.get_date(metadata.event_timestamp.seconds)

match:
  $Threat_Name, $Date

outcome:
  $Count = count(metadata.id)

order:
  $Date asc
Ringkasan Penguncian Akun
metadata.product_event_type = "4740"

$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses, target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)

match:
  $User, $Hostname

outcome:

  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds))
  $Count = count(metadata.id)

order:
  $Count desc
Modifikasi Grup Istimewa
(metadata.product_event_type = "4728" OR metadata.product_event_type = "4729" OR metadata.product_event_type = "4730" OR metadata.product_event_type = "4731" OR metadata.product_event_type = "4732" OR metadata.product_event_type = "4733")

$Event_Type = metadata.event_type
$Description = metadata.description
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Target_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Target_Domain_Group = target.group.group_display_name
$Severity = security_result.severity
$Summary = additional.fields["Message"]

match:
  $Source_User, $Target_User, $Target_Domain_Group, $Event_Type, $Description, $Severity, $Summary

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Severity desc, $Count desc
Layanan yang Baru Diinstal
metadata.product_event_type = "7045"

$Description = metadata.description
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Service_Name = extracted.fields["ServiceName"]
$Service_Filepath = target.process.file.full_path
$Service_Account = extracted.fields["ServiceAccount"]
$Service_Type = additional.fields["ServiceType"]
$Service_StartType = extracted.fields["ServiceStartType"]
$Severity = security_result.severity

match:
  $User, $Hostname, $Description, $Service_Name, $Service_Filepath, $Service_Account, $Service_Type, $Service_StartType, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Severity desc, $Count desc
Ringkasan Deteksi Ancaman
$Threat_Name = security_result.threat_name
$Threat_Name != ""
$Log_Type = metadata.log_type
$Event_Type = metadata.product_event_type
$Action = security_result.action
$Severity = security_result.severity
$Description = strings.coalesce(metadata.description, security_result.description, security_result.summary)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$File_Path = strings.coalesce(target.file.full_path, target.registry.registry_key, principal.process.file.full_path)

match:
  $Log_Type, $Description, $Threat_Name, $Event_Type, $Source_Hostname, $File_Path, $Action, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Date desc,$Count desc

Jalur File 10 Ancaman Teratas
security_result.action = "ALLOW" OR security_result.action = "ALLOW_WITH_MODIFICATION" OR security_result.action = "UNKNOWN_ACTION"
security_result.threat_name != ""

$Severity = security_result.severity
$File_Path = strings.coalesce(target.file.full_path, target.registry.registry_key, principal.process.file.full_path)

match:
  $File_Path, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Ringkasan Perlindungan Endpoint (Antivirus Defender)
(metadata.product_event_type = "MALWAREPROTECTION_RTP_DISABLED" OR metadata.product_event_type = "MALWAREPROTECTION_RTP_ENABLED")

$Description = strings.coalesce(metadata.description, security_result.description, security_result.summary)
$Severity = security_result.severity
$Action = security_result.action
$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname, target.hostname, target.asset.hostname)
$Source_User = strings.coalesce(principal.user.user_display_name, principal.user.userid, principal.user.email_addresses)
$Version = metadata.product_version

match:
  $Description, $Hostname, $Source_User, $Severity, $Action, $Version

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Count desc, $Date desc
Distribusi Jenis Login
metadata.product_event_type = "4624"

$Logon_type = extensions.auth.mechanism

match:
  $Logon_type

outcome:
  $Count = count(metadata.id)

Proses Teratas yang Diluncurkan di Server (Windows Sysmon)
metadata.product_event_type = "1"

$Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Severity = security_result.severity
$Description = security_result.summary
$Principal_Process_Path = principal.process.file.full_path
$Target_Process_Path = target.process.file.full_path

match :
  $Hostname, $User, $Severity, $Principal_Process_Path, $Target_Process_Path

outcome:

  $Count = count(metadata.id)

order:
  $Count desc
Negara Login Jarak Jauh yang Berbeda
metadata.event_type = "USER_LOGIN"
metadata.product_event_type = "4624"
extensions.auth.mechanism = "REMOTE_INTERACTIVE"

$Logon = extensions.auth.mechanism
$Logon_type = extensions.auth.auth_details
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip)
$Source_Hostname = strings.coalesce(principal.hostname, principal.asset.hostname)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses )

match:
  $Source_User, $Source_IP, $Source_Hostname, $Logon, $Logon_type

outcome:
  $Country = array_distinct(principal.ip_geo_artifact.location.country_or_region)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")
  $Count = count(metadata.id)

order:
  $Date desc
Distribusi Versi Antivirus (Antivirus Defender)
$Anti_Virus_Version = metadata.product_version

match:
  $Anti_Virus_Version

outcome:
  $Count = count_distinct(principal.hostname)

limit:
    50
Pembuatan Akun Pengguna
(metadata.event_type = "USER_CREATION" OR metadata.product_event_type = "4720")

$Source_IP = strings.coalesce(principal.ip,principal.asset.ip)
$Hostname = strings.coalesce(principal.hostname,principal.asset.hostname, principal.asset.asset_id,intermediary.hostname)
$Source_User = strings.coalesce(principal.user.userid, principal.user.user_display_name, principal.user.email_addresses)
$Target_User = strings.coalesce(target.user.userid, target.user.user_display_name, target.user.email_addresses)
$Action = security_result.action

match:
  $Source_IP, $Hostname, $Source_User, $Target_User,$Action

outcome :
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order:
  $Date desc 

Keamanan Jaringan Nirkabel

Dasbor ini menawarkan insight tentang aktivitas dan keamanan jaringan, termasuk distribusi autentikasi, kegagalan login, deteksi AP berbahaya, dan perilaku koneksi klien. Fitur ini membantu melacak peristiwa keamanan berdasarkan tingkat keparahan, mengidentifikasi ID yang mencurigakan, dan mengoptimalkan performa jaringan untuk pengelolaan risiko proaktif.

Nama diagram Contoh kueri
Deteksi Titik Akses Ilegal
$Rogue = strings.coalesce(
                       if (extracted.fields["description"] = /Rogue|AP Detection|Spoof/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /Rogue|AP Detection|Spoof/ nocase, security_result.description, ""),
                       if (security_result.summary = /Rogue|AP Detection|Spoof/ nocase, security_result.summary, ""),
                       if (metadata.description = /Rogue|AP Detection|Spoof/ nocase, metadata.description,""))
$Rogue != ""
$Source_MAC = strings.coalesce(principal.mac, principal.asset.mac)
$ID = strings.coalesce(extracted.fields["ssid"], principal.resource.name)
$Description = strings.coalesce(metadata.description, security_result.summary)
$Source_IP= strings.coalesce(principal.ip, principal.asset.ip,extracted.fields["clientIp"])
$Log_Source = metadata.log_type
$Severity = security_result.severity
$Action = security_result.action
$Target_MAC = strings.coalesce(target.mac, target.asset.mac)

match:
   $Log_Source, $Description,$Source_MAC, $Source_IP, $ID, $Target_MAC,$Severity,$Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Severity desc,$Date desc
10 Jenis Autentikasi Teratas menurut Tindakan
metadata.event_type = "USER_LOGIN"

$Logon_type = extensions.auth.type
$Action = security_result.action

match:
  $Action,$Logon_type

outcome:
  $Count = count(metadata.id)

order :
  $Count desc

limit:
    10
10 SSID Teratas menurut MAC Sumber(Cisco Meraki)
$SSID = extracted.fields["ssid"]
$Log_Type = metadata.log_type
$SSID != ""
$Action = security_result.action

match:
   $SSID, $Action

outcome:
  $Count = count_distinct(strings.coalesce(principal.mac, principal.asset.mac))

order:
   $Count desc

limit:
   10
   
10 Titik Akses Teratas menurut MAC Sumber
 $Access_Point = strings.coalesce(target.hostname, target.asset.hostname, principal.user.company_name, observer.hostname,intermediary.hostname)
 $Log_Type = metadata.log_type

match:
  $Access_Point, $Log_Type

outcome:
  $Count = count_distinct(strings.coalesce(principal.mac, principal.asset.mac))

order :
   $Count desc

limit :
    10
10 Jenis Peristiwa Teratas menurut Tindakan
$Event_Type = metadata.event_type
$Action = security_result.action

match:
  $Event_Type,$Action

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
10 Alamat MAC Teratas berdasarkan Autentikasi Gagal
$Authentication_Failed = strings.coalesce(
                       if (extracted.fields["description"] = /authentication failed/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /failed to connect/ nocase, security_result.description, ""),
                       if (security_result.summary = /Failed Authentication|authentication failed/ nocase, security_result.summary, ""),
                       if (metadata.description = /Authentication failed|verification failed/ nocase, metadata.description,""))
($Authentication_Failed != "" OR (metadata.event_type= "USER_LOGIN"  AND  security_result.action ="BLOCK"))
$MAC_Address = strings.coalesce(principal.mac, principal.asset.mac, target.mac, target.asset.mac)
$Severity = security_result.severity

match:
  $MAC_Address, $Severity

outcome:
  $Count = count(metadata.id)

order:
  $Count desc

limit:
    10
Autentikasi Gagal Terbaru (24 Jam Terakhir)
$Authentication_Failed = strings.coalesce(
                       if (extracted.fields["description"] = /authentication failed/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /failed to connect/ nocase, security_result.description, ""),
                       if (security_result.summary = /Failed Authentication|authentication failed/ nocase, security_result.summary, ""),
                       if (metadata.description = /Authentication failed|verification failed/ nocase, metadata.description, ""))
($Authentication_Failed != "" OR (metadata.event_type= "USER_LOGIN"  AND  security_result.action ="BLOCK"))
$Log_Source = metadata.log_type
$Source_MAC = strings.coalesce(principal.mac, principal.asset.mac)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip,extracted.fields["clientIp"])
$Severity = security_result.severity
$Action = security_result.action
$Security_Event_Type = metadata.product_event_type
$Target_MAC = strings.coalesce(target.mac, target.asset.mac)
$Description = strings.coalesce(metadata.description,extracted.fields["description"], security_result.description,security_result.summary)
 $Access_Point = strings.coalesce(target.hostname, target.asset.hostname, principal.user.company_name, observer.hostname,intermediary.hostname)

match:
  $Log_Source,$Description, $Source_MAC, $Source_IP, $Access_Point, $Target_MAC, $Action, $Severity

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Date desc, $Severity desc

Total Perangkat Sumber
outcome:
  $Count = count_distinct(strings.coalesce(principal.mac, principal.asset.mac))
  
10 Deskripsi Teratas
$Description = strings.coalesce(metadata.description,security_result.description,security_result.summary,extracted.fields["description"])
$Log_Type = metadata.log_type
$Description != ""

match:
  $Log_Type, $Description

outcome :
  $Count = count(metadata.id)

order :
  $Count desc

limit:
    10
10 IP Klien Teratas yang Terdeteksi di Titik Akses Ilegal
 $Rogue = strings.coalesce(
                       if (extracted.fields["description"] = /Rogue|AP Detection|Spoof/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /Rogue|AP Detection|Spoof/ nocase, security_result.description, ""),
                       if (security_result.summary = /Rogue|AP Detection|Spoof/ nocase, security_result.summary, ""),
                       if (metadata.description = /Rogue|AP Detection|Spoof/ nocase, metadata.description,""))
$Rogue != ""
$Client_IP = strings.coalesce(principal.ip,principal.asset.ip,extracted.fields["clientIp"])
$Action = security_result.action

match:
   $Client_IP, $Action

outcome:
  $Count = count(metadata.id)

order :
  $Count desc

limit :
    10
Distribusi Jenis Autentikasi
$Logon_type = extensions.auth.type

match:
  $Logon_type

outcome:
  $Count = count(metadata.id)
Aktivitas Jaringan Ad-Hoc Terdeteksi (CISCO MERAKI)
extracted.fields["type"] = "adhoc_network_detected"

$Detection_Type = extracted.fields["type"]
$SSID = extracted.fields["ssid"]
$SSID != ""
$Source_IP = extracted.fields["clientIp"]
$Source_MAC = strings.coalesce(principal.mac, principal.asset.mac)
$Category = security_result.category
$Security_Description = security_result.description

match:
  $Security_Description, $Detection_Type, $SSID, $Source_MAC, $Source_IP, $Category

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Count desc

Aktivitas Nirkabel Mencurigakan
(security_result.category = "NETWORK_MALICIOUS" OR security_result.category = "NETWORK_SUSPICIOUS" OR security_result.category = "NETWORK_CATEGORIZED_CONTENT" OR security_result.category = "NETWORK_COMMAND_AND_CONTROL" OR security_result.category = "NETWORK_DENIAL_OF_SERVICE" OR security_result.category = "NETWORK_RECON" OR  security_result.category = "AUTH_VIOLATION")

$Log_Source = metadata.log_type
$Source_MAC = strings.coalesce(principal.mac, principal.asset.mac)
$ID = strings.coalesce(extracted.fields["ssid"], principal.resource.name)
$Source_IP = strings.coalesce(principal.ip, principal.asset.ip,extracted.fields["clientIp"])
$Severity = security_result.severity
$Action = security_result.action
$Target_MAC = strings.coalesce(target.mac, target.asset.mac)
$Description = strings.coalesce(metadata.description,extracted.fields["description"], security_result.description,security_result.summary)

match:
  $Log_Source, $Description, $Source_IP, $Source_MAC, $ID,  $Target_MAC , $Severity, $Action

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
   $Severity desc,$Date desc
SSID menurut Kegagalan Autentikasi(Cisco Meraki)
$Authentication_Failed = strings.coalesce(
                       if (extracted.fields["description"] = /authentication failed/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /failed to connect/ nocase,security_result.description, ""),
                       if (security_result.summary = /Failed Authentication/ nocase, security_result.summary, ""),
                       if (metadata.description = /Authentication failed|verification failed/ nocase, metadata.description,""))
($Authentication_Failed != "" OR (metadata.event_type= "USER_LOGIN"  AND  security_result.action ="BLOCK"))
$SSID = extracted.fields["ssid"]
$Source_IP = extracted.fields["clientIp"]
$SSID != ""
$Source_MAC = strings.coalesce(principal.mac, principal.asset.mac)
$Access_Point = strings.coalesce(target.hostname, target.asset.hostname, principal.user.company_name, observer.hostname,intermediary.hostname)
$AP_Model = target.asset.hardware.model
$Target_Url = target.url
$Source_Hostname = principal.hostname
$Resource_Name = principal.resource.name

match:
   $SSID, $Source_MAC, $Source_IP, $Access_Point, $AP_Model, $Target_Url, $Source_Hostname, $Resource_Name

outcome:
  $Count = count(metadata.id)
  $Date = timestamp.get_timestamp(max(metadata.event_timestamp.seconds), "%F %T")

order :
  $Count desc

Distribusi Tingkat Keparahan
$Severity = security_result.severity

match:
  $Severity

outcome:
  $Count = count(metadata.id)
Jumlah Deteksi Titik Akses Ilegal
$Rogue = strings.coalesce(
                       if (extracted.fields["description"] = /Rogue|AP Detection|Spoof/ nocase, extracted.fields["description"], ""),
                       if (security_result.description = /Rogue|AP Detection|Spoof/ nocase, security_result.description, ""),
                       if (security_result.summary = /Rogue|AP Detection|Spoof/ nocase, security_result.summary, ""),
                       if (metadata.description = /Rogue|AP Detection|Spoof/ nocase, metadata.description,""))
$Rogue != ""

outcome:
  $Count = count_distinct(strings.coalesce(target.hostname, target.asset.hostname, principal.user.company_name, observer.hostname,intermediary.hostname))
Ringkasan Geolocation Sumber
$Country = strings.coalesce(principal.location.country_or_region, principal.ip_geo_artifact.location.country_or_region)
$Country != ""

match:
  $Country

outcome:
  $Count = count(metadata.id)
  $Latitude = max(principal.location.region_latitude)
  $Longitude = max(principal.location.region_longitude)

order:
  $Count desc

Perlu bantuan lain? Dapatkan jawaban dari anggota Komunitas dan profesional Google SecOps.