Microsoft-ServiceBus-Client

EventTitleChannelSampleRule
40300Service Bus relay client connection-state event.Microsoft-ServiceBus-ClientNY
40301Service Bus relay client connection-state event.Microsoft-ServiceBus-ClientNY
40302Service Bus relay client connection-state event.Microsoft-ServiceBus-ClientNY

Event ID 40300: Service Bus relay client connection-state event.

#
Channel
Microsoft-ServiceBus-Client

Description

Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).

Detection Patterns #

Community Notes #

Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.

Event ID 40301: Service Bus relay client connection-state event.

#
Channel
Microsoft-ServiceBus-Client

Description

Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).

Detection Patterns #

Community Notes #

Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.

Event ID 40302: Service Bus relay client connection-state event.

#
Channel
Microsoft-ServiceBus-Client

Description

Connection-state or diagnostic event written by the Microsoft.ServiceBus relay client used by the Azure App Service Hybrid Connection Manager (Microsoft.HybridConnectionManager.Listener.exe) when it connects to or communicates over an Azure Relay / Service Bus hybrid connection (sb://*.servicebus.windows.net).

Detection Patterns #

Community Notes #

Matched (as the set 40300/40301/40302 plus HybridConnection / sb:// / servicebus.windows.net keywords) by the SigmaHQ 'HybridConnectionManager Service Running' rule, which detects Azure Hybrid Connection Manager persistence and tunneling. The channel and provider are Microsoft-documented; the specific event ids trace to SpecterOps research (Roberto Rodriguez) codified in the SigmaHQ rule, and no source distinguishes the per-id semantics (online / offline / error), so this entry does not assert one.

References #