{
  "version": "Notebook/1.0",
  "items": [
    {
      "type": 1,
      "content": {
        "json": "## PCI-DSS Compliance Reporting and Analysis"
      },
      "name": "text - 1",
      "styleSettings": {
        "margin": "0"
      }
    },
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "parameters": [
          {
            "id": "3f9981ce-9bb6-4645-aad3-d400f17d898e",
            "version": "KqlParameterItem/1.0",
            "name": "SubscriptionToken",
            "label": "Subscription",
            "type": 6,
            "description": "Choose your subscription in which PCI assets are deployed",
            "isRequired": true,
            "typeSettings": {
              "additionalResourceOptions": [],
              "includeAll": true,
              "showDefault": false
            },
            "timeContext": {
              "durationMs": 86400000
            }
          },
          {
            "id": "ca9065a5-b239-43ca-913a-e300bc5e174f",
            "version": "KqlParameterItem/1.0",
            "name": "WorkspaceToken",
            "label": "Workspace",
            "type": 5,
            "description": "Choose Workspace where PCI assets reports logs",
            "isRequired": true,
            "typeSettings": {
              "additionalResourceOptions": [],
              "showDefault": false
            },
            "timeContext": {
              "durationMs": 86400000
            }
          },
          {
            "id": "70c7dce2-4f4a-4fe2-a0c7-e632a5fd97d7",
            "version": "KqlParameterItem/1.0",
            "name": "TimeToken",
            "label": "Time",
            "type": 4,
            "description": "Choose the time range apporpriate for your analysis",
            "isRequired": true,
            "value": {
              "durationMs": 2592000000
            },
            "typeSettings": {
              "selectableValues": [
                {
                  "durationMs": 900000
                },
                {
                  "durationMs": 1800000
                },
                {
                  "durationMs": 14400000
                },
                {
                  "durationMs": 43200000
                },
                {
                  "durationMs": 86400000
                },
                {
                  "durationMs": 259200000
                },
                {
                  "durationMs": 1209600000
                },
                {
                  "durationMs": 2592000000
                }
              ],
              "allowCustom": true
            },
            "timeContext": {
              "durationMs": 86400000
            }
          }
        ],
        "style": "pills",
        "queryType": 0,
        "resourceType": "microsoft.operationalinsights/workspaces"
      },
      "name": "parameters - 0"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "tabs",
        "links": [
          {
            "id": "4d1f108b-c166-44fb-af69-77838051c673",
            "cellValue": "selTab",
            "linkTarget": "parameter",
            "linkLabel": "Getting Started",
            "subTarget": "Getting Started",
            "style": "link"
          },
          {
            "id": "8895f25c-1d00-49b9-97fb-322a528d35a1",
            "cellValue": "selTab",
            "linkTarget": "parameter",
            "linkLabel": "Overview",
            "subTarget": "Overview",
            "style": "link"
          },
          {
            "id": "dc7ceb39-fd9c-4f61-be4b-f13d0966b6f8",
            "cellValue": "selTab",
            "linkTarget": "parameter",
            "linkLabel": "Audit Trail Reporting",
            "subTarget": "Audit Trail Reporting",
            "style": "link"
          },
          {
            "id": "942892a0-c339-459f-97f9-efdd82153262",
            "cellValue": "selTab",
            "linkTarget": "parameter",
            "linkLabel": "Further Analysis",
            "subTarget": "Further Analysis",
            "style": "link"
          }
        ]
      },
      "name": "linktab"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "The Microsoft Sentinel Solution for PCI Compliance provides real-time insights into activity and potential threats in your cardholder data environment. This solution is designed for Compliance Teams, Architects, Analysts, and Consultants to define and monitor their PCI assets, as well as identify and investigate compliance issues. This Solution is presented in two parts, as a Workbook and a Watchlist, with the ability to export data from pre-written queries for further exploration.  \r\n<br>\r\nThe Microsoft Sentinel team welcomes your feedback on this PCI-DSS Solution, and how we can expand our compliance content to better meet your organization’s needs. Please share any feedback with us [Here](https://forms.office.com/r/ChitppJ5T8). ",
              "style": "info"
            },
            "name": "text - 0"
          },
          {
            "type": 1,
            "content": {
              "json": "### Getting Started \r\n\r\nThere are two pre-requisites to getting started with the PCI-DSS Compliance Solution:<br>\r\n1. <u>Connect Data Sources:</u> Users will need to connect applicable data sources to populate the reports. This Solution provides support for the following data sources:\r\n    - AzureDaignostics (firewalls and other network devices)\r\n    - SecurityEvent (windows VM)\r\n\t- SecurityAlert (For anamolies detection)\r\n\t- Syslog (linux VM)\r\n\t- OracleDatabaseAuditEvent (Oracle Database Audit solution)\r\n2. <u>Define PCI Assets:</u> Users will need to define the PCI Assets within their compliance scope via the PCI Assets Watchlist\r\n    - Save the CSV file with all your pci assets name under column \"asset\".\r\n    - Open your workspace in sentinel\r\n\t- Go to watchlist under configration tab\r\n\t- Click on Add new \r\n\t- Enter \"pciassets\" in Name field\r\n\t- Enter Description \r\n\t- Enter \"pciassets\" in Alias field\r\n\t- SourceType should be LocalFile\r\n\t- File type CSV\r\n\t- Upload the CSV file here \r\n\t- Enter \"asset\" as search key\r\n\t- click on Review and Create and then Create\r\n<br>\r\n\r\n### Included in the Microsoft Sentinel PCI-DSS Compliance Solution \r\nThis Solution enables Microsoft Sentinel users to harness the power of their SIEM to assist in meeting PCI-DSS 3.2.1 requirements. This Solution comes with pre-defined dashboards, visualizations, and reports, providing users with immediate insights in their PCI environment.  \r\n<br>\r\nThe Watchlist included in this Solution allows users to define the PCI Assets included in their organization’s compliance scope. The Workbook included in this Solution contains three tabs, with the following information: \r\n\r\n\r\n<u>Overview Tab</u> This Workbook tab provides an overview of recent activity on the PCI Assets you define and trends over time, through the following tables and charts:  \r\n1. PCI Asset Status: Online and offline status of PCI assets, including how long a device has been offline \r\n2. PCI Network Asset Status: Online and offline status of network assets in PCI scope, including how long a network device has been offline \r\n3. Anomalous Activity Detected: summary of potentially anomalous activity detected on PCI assets, and correlation to the MITRE ATT&CK framework \r\n4. Network Traffic and Activity Events Over Time: Visualization of data movement over PCI assets \r\n5. Top 10 Activities: Visualization of the top 10 activities occurring on PCI assets \r\n6. Failed vs. Successful Log Ins: summary of login attempts and status on PCI assets \r\n7. Network Data Processed Over Time: Visualization of all network traffic passing through PCI assets, over time \r\n8. Top Actions on Cardholder DB: Visualization of top 10 actions performed on data within the defined cardholder databases\r\n\r\n<u>Audit Trail Reporting Tab</u> This Workbook tab provides a more in-depth look at the data summarized in the Overview, through the following tables and charts: \r\n1. Security Events, Network Traffic Logs, Process Running on PCI Assets: provides an audit trail of activities occurring on PCI assets  \r\n2. Login Activities: provides an audit trail of invalid logical access attempts on PCI assets \r\n3. Security Events: provides an audit trail of all actions taken by an individual with root or administrative privileges. This includes use of or changes to identification and authentication mechanisms, creation of new accounts, elevation of privileges, and all changes, additions, deletions to accounts with root or administrative privileges \r\n4. All Activities by User on Cardholder DB: provides audit trail of all events occurring on PCI servers that store cardholder data \r\n\r\n<u>Further Analysis Tab</u> This Workbook tab provides users with the ability to dive deeper into these results, with pre-written queries provided for export and further exploration.  \r\n\t",
              "style": "upsell"
            },
            "name": "text - 1"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "selTab",
        "comparison": "isEqualTo",
        "value": "Getting Started"
      },
      "name": "SummaryGroup"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nHeartbeat\r\n|where Computer in~ (watchlist)\r\n|extend Lastlog = TimeGenerated\r\n|summarize arg_max(Lastlog, *) by Computer\r\n|extend Current = now()\r\n|extend Offline_past_hours = datetime_diff('hour',now(),Lastlog)\r\n|project Computer,Lastlog,Current,Offline_past_hours",
              "size": 1,
              "title": "PCI Assets status",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Offline_past_hours",
                    "formatter": 8,
                    "formatOptions": {
                      "min": 10,
                      "max": 24,
                      "palette": "red"
                    }
                  }
                ],
                "sortBy": [
                  {
                    "itemKey": "$gen_heatmap_Offline_past_hours_3",
                    "sortOrder": 1
                  }
                ]
              },
              "sortBy": [
                {
                  "itemKey": "$gen_heatmap_Offline_past_hours_3",
                  "sortOrder": 1
                }
              ]
            },
            "customWidth": "50",
            "name": "query - 4",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nAzureDiagnostics \r\n|where Resource in~ (watchlist)\r\n|extend Lastlog = TimeGenerated\r\n|summarize arg_max(Lastlog, *) by Resource\r\n|extend Current = now()\r\n|extend Offline_past_hour = datetime_diff('hour',now(),Lastlog)\r\n|project Resource,Lastlog,Current,Offline_past_hour",
              "size": 1,
              "title": "PCI Network assets status",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Offline_past_hour",
                    "formatter": 8,
                    "formatOptions": {
                      "min": 2,
                      "max": 10,
                      "palette": "red"
                    }
                  }
                ]
              }
            },
            "customWidth": "50",
            "name": "query - 6",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nAnomalies\r\n|where Entities has_any (watchlist) or AnomalyReasons has_any (watchlist)\r\n|summarize count() by RuleName, UserName,Tactics,Techniques, tostring(AnomalyReasons) ",
              "size": 0,
              "title": "Anomalous Activity Detected",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "table",
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Tactics",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "20ch"
                    }
                  },
                  {
                    "columnMatch": "Techniques",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "16ch"
                    }
                  },
                  {
                    "columnMatch": "AnomalyReasons",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "100ch"
                    }
                  },
                  {
                    "columnMatch": "count_",
                    "formatter": 8,
                    "formatOptions": {
                      "min": 0,
                      "max": 10,
                      "palette": "turquoise"
                    }
                  }
                ]
              }
            },
            "name": "query - 7",
            "styleSettings": {
              "margin": "0px",
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nAzureDiagnostics \r\n|where Resource in~ (watchlist)\r\n|make-series TotalEvents = count() default = 0 on TimeGenerated from {TimeToken:start} to {TimeToken:end} step {TimeToken:grain};",
              "size": 1,
              "title": "Network traffic events over time",
              "color": "lightBlue",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "unstackedbar"
            },
            "customWidth": "50",
            "name": "query - 5",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nunion Event,Syslog\r\n|where Computer in~ (watchlist)\r\n| make-series TotalEvents = count() default = 0 on TimeGenerated from {TimeToken:start} to {TimeToken:end} step {TimeToken:grain};",
              "size": 1,
              "title": "Activity Events over time",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "visualization": "barchart"
            },
            "customWidth": "50",
            "name": "query - 4",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nSecurityEvent \r\n|where Computer in~ (watchlist)\r\n|summarize count() by Activity,Computer\r\n|sort by count_\r\n|take 10",
              "size": 2,
              "title": "Top 10 activities",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "piechart",
              "tileSettings": {
                "showBorder": false,
                "titleContent": {
                  "columnMatch": "Activity",
                  "formatter": 1
                },
                "leftContent": {
                  "columnMatch": "count_",
                  "formatter": 12,
                  "formatOptions": {
                    "palette": "auto"
                  },
                  "numberFormat": {
                    "unit": 17,
                    "options": {
                      "maximumSignificantDigits": 3,
                      "maximumFractionDigits": 2
                    }
                  }
                }
              },
              "graphSettings": {
                "type": 0,
                "topContent": {
                  "columnMatch": "Activity",
                  "formatter": 1
                },
                "centerContent": {
                  "columnMatch": "count_",
                  "formatter": 1,
                  "numberFormat": {
                    "unit": 17,
                    "options": {
                      "maximumSignificantDigits": 3,
                      "maximumFractionDigits": 2
                    }
                  }
                }
              },
              "chartSettings": {
                "yAxis": [
                  "count_"
                ],
                "group": "Activity",
                "createOtherGroup": 10
              },
              "mapSettings": {
                "locInfo": "LatLong",
                "sizeSettings": "count_",
                "sizeAggregation": "Sum",
                "legendMetric": "count_",
                "legendAggregation": "Sum",
                "itemColorSettings": {
                  "type": "heatmap",
                  "colorAggregation": "Sum",
                  "nodeColorField": "count_",
                  "heatmapPalette": "greenRed"
                }
              }
            },
            "customWidth": "50",
            "name": "query - 4",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nSecurityEvent \r\n|where Computer in~ (watchlist)\r\n|where Activity has_any (\"An account failed to log on\",\"An account was successfully logged on\")\r\n|where SubjectUserName !has (\"$\")\r\n|summarize count() by Activity",
              "size": 2,
              "title": "Failed Vs Successful login",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "piechart"
            },
            "customWidth": "50",
            "name": "query - 5",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "AzureMetrics \r\n|where MetricName == \"DataProcessed\"\r\n|project TimeGenerated ,Resource , Average\r\n|extend Average = log10(Average) \r\n",
              "size": 0,
              "title": "Network Data Processed over time",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "areachart",
              "chartSettings": {
                "xAxis": "TimeGenerated",
                "yAxis": [
                  "Average"
                ],
                "group": "Resource",
                "createOtherGroup": 10,
                "seriesLabelSettings": [
                  {
                    "seriesName": "PCIFIREWALL",
                    "color": "orange"
                  }
                ],
                "ySettings": {
                  "min": 4,
                  "max": 10
                }
              }
            },
            "name": "query - 6",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nOracleDatabaseAuditEvent\r\n|where SrcDvcHostname has_any (watchlist)\r\n| where isnotempty(DbAction)\r\n| summarize TotalEvents = count() by DbAction",
              "size": 2,
              "title": "Top actions on card holder DB",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "piechart"
            },
            "customWidth": "50",
            "name": "query - 8"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "selTab",
        "comparison": "isEqualTo",
        "value": "Overview"
      },
      "name": "OverviewGroup"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nAzureDiagnostics\r\n| where Resource in~ (watchlist)\r\n|summarize count() by msg_s,Resource\r\n|project-away count_ ",
              "size": 0,
              "title": "Network Traffic logs",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "msg_s",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "93ch"
                    }
                  },
                  {
                    "columnMatch": "Resource",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "16ch"
                    }
                  }
                ]
              }
            },
            "customWidth": "50",
            "name": "query - 0",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nunion SecurityEvent,Syslog \r\n|where Computer in (watchlist)\r\n|where Process != \"\"\r\n|extend Process = coalesce(Process,ProcessName)\r\n|summarize count() by Process,Computer\r\n|project-away count_",
              "size": 0,
              "title": "Process running on PCI assets",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ]
            },
            "customWidth": "50",
            "name": "query - 1",
            "styleSettings": {
              "padding": "15px",
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nSecurityEvent \r\n|where Computer in~ (watchlist)\r\n| summarize count() by Account , AccountType ,Computer , Activity ,ParentProcessName",
              "size": 0,
              "title": "Security Events",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "table",
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Activity",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "80ch"
                    }
                  },
                  {
                    "columnMatch": "count_",
                    "formatter": 8,
                    "formatOptions": {
                      "min": 100,
                      "max": 3000,
                      "palette": "pink"
                    }
                  }
                ]
              }
            },
            "name": "query - 2",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nSecurityEvent \r\n|where Computer in~ (watchlist)\r\n|where Activity has_any (\"An account failed to log on\",\"An account was successfully logged on\")\r\n|where SubjectUserName !has (\"$\")\r\n|summarize count() by Account, AccountType,Computer , Activity ,WorkstationName",
              "size": 0,
              "title": "Login Activities",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "visualization": "table",
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Account",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "35ch"
                    }
                  },
                  {
                    "columnMatch": "AccountType",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "22ch"
                    }
                  },
                  {
                    "columnMatch": "Computer",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "20ch"
                    }
                  },
                  {
                    "columnMatch": "Activity",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "55ch"
                    }
                  },
                  {
                    "columnMatch": "WorkstationName",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "26ch"
                    }
                  },
                  {
                    "columnMatch": "count_",
                    "formatter": 8,
                    "formatOptions": {
                      "min": 2,
                      "max": 10,
                      "palette": "magenta",
                      "customColumnWidthSetting": "12ch"
                    }
                  }
                ]
              }
            },
            "name": "query - 3",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nSecurityEvent \r\n|where Computer has_any (watchlist)\r\n|project TimeGenerated , Account , Activity , Process\r\n|where Activity has \"privileged\"\r\n|distinct *\r\n|sort by TimeGenerated",
              "size": 0,
              "title": "All actions taken by any individual with root or administrative privileges ",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ]
            },
            "name": "query - 5",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nHeartbeat\r\n|where Computer in~ (watchlist) \r\n|project Computer ,ComputerIP,Category,OSType,OSName,tostring(ComputerPrivateIPs)\r\n|distinct *",
              "size": 0,
              "title": "Assets information",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ],
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "Computer",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "20ch"
                    }
                  },
                  {
                    "columnMatch": "ComputerIP",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "22ch"
                    }
                  },
                  {
                    "columnMatch": "Category",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "25ch"
                    }
                  },
                  {
                    "columnMatch": "OSType",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "20ch"
                    }
                  },
                  {
                    "columnMatch": "OSName",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "35ch"
                    }
                  },
                  {
                    "columnMatch": "ComputerPrivateIPs",
                    "formatter": 0,
                    "formatOptions": {
                      "customColumnWidthSetting": "26ch"
                    }
                  }
                ]
              }
            },
            "name": "query - 4",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "let watchlist = (_GetWatchlist('pciassets') | project asset);\r\nOracleDatabaseAuditEvent\r\n|where SrcDvcHostname has_any (watchlist)",
              "size": 0,
              "title": "All activities by user on card holder DB",
              "timeContextFromParameter": "TimeToken",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces",
              "crossComponentResources": [
                "{WorkspaceToken}"
              ]
            },
            "name": "query - 6",
            "styleSettings": {
              "showBorder": true
            }
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "selTab",
        "comparison": "isEqualTo",
        "value": "Audit Trail Reporting"
      },
      "name": "ReportingGroup"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "## For complete analaysis, We are providing the analytic KQL queries through which more in depth detailed can be extracted .",
              "style": "info"
            },
            "name": "text - 0"
          },
          {
            "type": 1,
            "content": {
              "json": "### Steps on how to run the query :\r\n\r\n1> Search and Select microsoft sentinel on azure portal </br>\r\n2> choose the correct workspace </br>\r\n3> choose logs and then paste the query </br>\r\n4> Run it for suitable time range </br>",
              "style": "info"
            },
            "name": "text - 1"
          },
          {
            "type": 1,
            "content": {
              "json": "## Query for extracting the failed and succesfull login attempts </br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset); </br>\r\nSecurityEvent </br>\r\n|where Computer in~ (watchlist) </br>\r\n|where Activity has_any (\"An account failed to log on\",\"An account was successfully logged on\")</br> \r\n|where SubjectUserName !has (\"$\")</br>\r\n</br>\r\n</br>\r\n## Query for fetching the traffic logs </br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset); </br>\r\nAzureDiagnostics </br>\r\n|where Resource in~ (watchlist) </br>\r\n|summarize count() by msg_s, Resource</br>\r\n|project-away count_ </br>\r\n</br>\r\n</br>\r\n## Query for getting the details of process running on PCI servers</br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);</br>\r\nSecurityEvent </br>\r\n|where Computer in (watchlist)</br>\r\n|where Process != \"\"</br>\r\n|summarize count() by Process,Computer</br>\r\n</br>\r\n</br>\r\n## Query for checking the activities on PCI servers </br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);</br>\r\nSecurityEvent </br>\r\n|where Computer in~ (watchlist)</br>\r\n|summarize count() by Activity,Computer</br>\r\n</br>\r\n</br>\r\n## Query for checking the status of PCI assets</br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);</br>\r\nHeartbeat</br>\r\n|where Computer in~ (watchlist)</br>\r\n|extend Lastlog = TimeGenerated</br>\r\n|summarize arg_max(Lastlog, *) by Computer</br>\r\n|extend Current = now()</br>\r\n|extend Diffrence = datetime_diff('minute',now(),Lastlog)</br>\r\n|project Computer,Lastlog,Current,Diffrence</br>\r\n</br>\r\n</br>\r\n## Query for fetching the activities performed by user</br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);</br>\r\nSecurityEvent </br>\r\n|where Computer in~ (watchlist)</br>\r\n|where SubjectUserName !has (\"$\")</br>\r\n|where SubjectUserName != \"\"</br>\r\n|project SubjectUserName , Activity, Process , ProcessName</br>\r\n|distinct *</br>\r\n<br>\r\n<br>\r\n## All actions taken by any individual with root or administrative privileges<br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);<br>\r\nSecurityEvent <br>\r\n|where Computer has_any (watchlist)<br>\r\n|where Activity has \"privileged\"<br>\r\n|distinct *<br>\r\n|sort by TimeGenerated<br>\r\n<br>\r\n<br>\r\n## All activities by user on card holder DB<br>\r\nlet watchlist = (_GetWatchlist('pciassets') | project asset);<br>\r\nOracleDatabaseAuditEvent<br>\r\n|where SrcDvcHostname has_any (watchlist)<br>\r\n\r\n\r\n\r\n",
              "style": "upsell"
            },
            "name": "text - 2"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "selTab",
        "comparison": "isEqualTo",
        "value": "Further Analysis"
      },
      "name": "AnalysisGroup"
    }
  ],
  "fromTemplateId": "sentinel-PCIDSSCompliance",
  "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
}
