You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
name = "(Sample) Azure DevOps - Outlier in Pools Deleted Rapidly"
15
-
name_expression = "Azure DevOps - Outlier in Agent Pools Deleted in an Hour"
16
-
17
-
description_expression = <<-EOT
18
-
Context:
19
-
An Attacker with sufficient administrative access to Azure DevOps (ADO) may abuse this access to destroy existing resources by deleting pools.
20
-
21
-
Detection:
22
-
This detection identifies statistical outliers in user behavior for the number of pools deleted in an hourly window.
23
-
24
-
Recommended Actions:
25
-
If an alert occurs, investigate the actions taken by the account to determine if this is normal operation of deleting pools or if this suspicious activity.
26
-
27
-
Tuning Recommendations:
28
-
Determine if the baseline basis should be hourly or daily based on normal activity in your organization.
29
-
If the detection is proving to be too sensitive to the number of pools deleted, adjust the floor value (currently 3) to a number that is less sensitive but within reason. Use Sumo Search using a count and the _timeslice function to aggregate on the number of pools deleted within the hourly (or daily) periods to find what is an acceptable level of activity to not alert on.
0 commit comments