↳ GitHub sourceAnalytics ruleMedium

High Number of Urgent Vulnerabilities Detected

Description

'This Creates an incident when a host has a high number of Urgent, severity 5, vulnerabilities detected.'
Rule type
Scheduled
Version
1.0.3
Declared status
Available
Query frequency
1h
Query period
1h
Trigger
gt 0

Declared MITRE coverage

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Connectors

Data types

KQL query

Original query, unchanged.

let threshold = 10;
QualysHostDetection
| where Severity == "5"
| summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated), count() by NetBios, IPAddress
| where count_ >= threshold

Declared entities

HostIP

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
3edb7215-250b-40c0-8b46-79093949242d
Additional source files 4Solutions/QualysVM/Analytic Rules/HighNumberofVulnDetectedV2.yamlsource ↗Detections/QualysVM/HighNumberofVulnDetected.yamlmigration-note ↗Detections/QualysVMV2/HighNumberofVulnDetectedV2.yamlmigration-note ↗Solutions/QualysVM/data/Solution_QualysVM.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.