Microsoft-ServiceBus-Client
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 40300 | Service Bus relay client connection-state event. | Microsoft-ServiceBus-Client | N | Y |
| 40301 | Service Bus relay client connection-state event. | Microsoft-ServiceBus-Client | N | Y |
| 40302 | Service Bus relay client connection-state event. | Microsoft-ServiceBus-Client | N | Y |
Event ID 40300: Service Bus relay client connection-state event.
#Description
Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).
Detection Patterns #
Persistence: Compromise Host Software Binary
1 rule
Community Notes #
Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.
Event ID 40301: Service Bus relay client connection-state event.
#Description
Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).
Detection Patterns #
Persistence: Compromise Host Software Binary
1 rule
Community Notes #
Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.
Event ID 40302: Service Bus relay client connection-state event.
#Description
Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).
Detection Patterns #
Persistence: Compromise Host Software Binary
1 rule
Community Notes #
Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.