Skip to content

Commit d25d712

Browse files
committed
updating detection
1 parent 49fa1c1 commit d25d712

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

detections/application/cisco_ai_defense_security_alerts.yml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
name: Cisco AI Defense Security Alerts
1+
name: Cisco AI Defense Security Alerts by Application Name
22
id: 105e4a69-ec55-49fc-be1f-902467435ea8
33
version: 1
44
date: '2025-02-14'
@@ -9,17 +9,18 @@ description: The search surfaces alerts from the Cisco AI Defense product for po
99
data_source:
1010
- Cisco AI Defense Alerts
1111
search: |-
12-
`cisco_ai_defense`
12+
`cisco_ai_defense`
1313
| rename genai_application.application_name as application_name
1414
| rename connection.connection_name as connection_name
1515
```Aggregating data by model name, connection name, application name, application ID, and user ID```
1616
| stats count
17+
values(user_id) as user_id
1718
values(event_message_type) as event_message_type
1819
values(event_action) as event_action
1920
values(policy.policy_name) as policy_name
2021
values(event_policy_guardrail_assocs{}.policy_guardrail_assoc.guardrail_avail_entity.guardrail_entity_name) as guardrail_entity_name
2122
values(event_policy_guardrail_assocs{}.policy_guardrail_assoc.guardrail_avail_ruleset.guardrail_ruleset_type) as guardrail_ruleset_type
22-
by model.model_name connection_name application_name application_id user_id
23+
by model.model_name connection_name application_name application_id
2324
```Evaluating severity based on policy name and guardrail ruleset type```
2425
| eval severity=case(
2526
policy_name IN ("AI Runtime Latency Testing - Prompt Injection"), "critical",
@@ -53,7 +54,7 @@ drilldown_searches:
5354
rba:
5455
message: Cisco AI Defense Security Alert has been detected for the application name - [$application_name$]
5556
risk_objects:
56-
- field: application_id
57+
- field: application_name
5758
type: other
5859
score: 10
5960
threat_objects: []

0 commit comments

Comments
 (0)