Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard
A security analyst is creating a new analytics rule in Microsoft Sentinel to detect a sophisticated attack pattern. The attack involves multiple distinct events occurring within a short timeframe, but not necessarily in a strict sequential order. The analyst needs to correlate these events from different tables into a single incident. Which type of analytics rule is best suited for this scenario?
- ANRT (Near Real-time) rule
- BFusion rule
- CMicrosoft Security rule
- DScheduled query rule
Show answer & explanationAnswer & explanation
Correct answer: B. Fusion rule
Fusion rules in Microsoft Sentinel use machine learning to correlate low-fidelity alerts and behavioral anomalies across multiple data sources into high-fidelity incidents, making them ideal for detecting complex, non-linear attack patterns.
Why the other options are wrong
- A. NRT rules are a type of scheduled query rule optimized for low-latency detection, but they still rely on explicit KQL and don't inherently perform the multi-stage, non-linear correlation of Fusion rules.
- C. Microsoft Security rules are pre-built rules from Microsoft security services (like Defender for Cloud) and don't allow custom correlation logic for sophisticated attack patterns.
- D. Scheduled query rules run KQL queries on a schedule and are good for specific detections, but less effective for complex, multi-stage, non-linear attack patterns across different tables without explicit KQL logic for each stage.
Microsoft Sentinel Fusion Rules
Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to automatically detect multi-stage attacks by correlating disparate alerts and behavioral anomalies across various data sources.
- Uses machine learning for correlation.
- Detects multi-stage, sophisticated attacks.
- Correlates low-fidelity alerts into high-fidelity incidents.
Memory trick: To 'Fuse' together many small clues into one big attack, use Fusion rules.