↳ GitHub sourceAnalytics ruleHigh
Uniqkey - Platform threat detection
Description
Surfaces threat detections generated by the Uniqkey platform itself, such as employee credentials discovered in a data breach, as Microsoft Sentinel alerts. Promoting these vendor-side detections into Microsoft Sentinel lets them be triaged, correlated with other signals and tracked as incidents alongside the rest of the security stack. Each detection is raised as its own alert.
- Rule type
- Scheduled
- Version
- 1.0.0
- Query frequency
- 1h
- Query period
- 1h
- Trigger
- gt 0
Declared MITRE coverage
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Connectors
Data types
KQL query
Original query, unchanged.
UniqkeyEvents_CL
| where Category == "threat_detection"
| project TimeGenerated, ActorEmail, ActorType, Action, ActionId, TargetType, TargetName, ClientSystem, SrcIpAddrDeclared entities
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
712f5770-a5a9-4623-8adc-26cda17294a5
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC