Analytic Rules

Overview of Analytic Rules

Analytic rules are scheduled queries that automatically monitor your KMIP logs for predefined threat patterns and anomalies. Unlike hunting queries which are run on-demand, analytic rules execute continuously and generate incidents when they detect suspicious activities. This enables real-time alerting and automated incident creation for your security team.

Three scheduled analytic rules ship with the solution to detect threats targeting your KMIP plane. Rules must be individually enabled from ConfigurationAnalytics Rule templates.

Rule

Severity

Detection Logic

Multiple KMIP authentication failures from same IP

Medium

≥ 5 authentication failures from one IP in 15 min

PERMISSION_DENIED burst for a KMIP user

Medium

≥ 10 permission denied events for one user in 30 min

Burst of KMIP DESTROY operations by a single user

High

≥ 20 successful destroy operations by one user in 10 min

Analytic rules

How to Enable the Rules

Follow these steps to activate each analytic rule in your Microsoft Sentinel workspace:

  1. Navigate to Configuration Analytics Rule templates.

  2. Search for Utimaco ESKM to find the available rules.

  3. Select a rule to view its detection logic.

  4. Click Create rule to enable it in your workspace.

  5. Configure notifications and automation playbooks as needed.

The rules will begin running on schedule and automatically generate incidents in Threat management Incidents when they detect suspicious patterns. Configured notifications will alert your team, and linked automation playbooks will trigger as needed.