Forum Discussion
No Analytics Rule for Dark Trace??
FahadAhmed You will see that a lot of the data connectors, especially those written by third parties, do not have any associate analytic rules. It is up to the 3rd party as to what to provide with their data connector. Hopefully, with the advent of the Content Hub, this will happen less and less as the analytic rules can be combined with the data connectors.
Based on the description of the Darktrace workbook, I would say the malicious activities shown are indeed items that need to be investigated. I would also suggest looking at the KQL in the workbook and seeing if you can use that to make your Analytics rules to create the alerts.
- Magnus TengmoNov 08, 2022Copper Contributor
- Clive_WatsonNov 08, 2022Bronze Contributor
Magnus Tengmo There are three out of the box now
or go to the Github: Azure-Sentinel/Solutions/Darktrace/Analytic Rules at f99d6c8fd39bb3751f41ed8dfe059f2b2c9d1130 · Azure/Azure-Sentinel (github.com)