Detection rules › Kusto

Cisco Cloud Security - Windows PowerShell User-Agent Detected

Status
available
Severity
medium
Time window
15m
Source
github.com/Azure/Azure-Sentinel

'Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser.'

MITRE ATT&CK coverage

Rule body

id: b12b3dab-d973-45af-b07e-e29bb34d8db9
name: Cisco Cloud Security - Windows PowerShell User-Agent Detected
description: |
  'Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser.'
severity: Medium
status: Available
requiredDataConnectors:
  - connectorId: CiscoUmbrellaDataConnector
    dataTypes:
      - Cisco_Umbrella_proxy_CL
queryFrequency: 15m
queryPeriod: 15m
triggerOperator: gt
triggerThreshold: 0
tactics:
  - CommandAndControl
  - DefenseEvasion
  - Execution
relevantTechniques:
  - T1132
  - T1027
  - T1059.001
query: |
  Cisco_Umbrella
  | where EventType == "proxylogs"
  | where HttpUserAgentOriginal contains "WindowsPowerShell"
  | extend Message = "Windows PowerShell User Agent"
  | project TimeGenerated, Message, SrcIpAddr, DstIpAddr, UrlOriginal, HttpUserAgentOriginal
entityMappings:
  - entityType: URL
    fieldMappings:
      - identifier: Url
        columnName: UrlOriginal
  - entityType: IP
    fieldMappings:
      - identifier: Address
        columnName: SrcIpAddr
version: 1.1.3
kind: Scheduled

Stages and Predicates

Stage 1: source

Cisco_Umbrella

Stage 2: where

| where EventType == "proxylogs"

Stage 3: where

| where HttpUserAgentOriginal contains "WindowsPowerShell"

Stage 4: extend

| extend Message = "Windows PowerShell User Agent"

Stage 5: project

| project TimeGenerated, Message, SrcIpAddr, DstIpAddr, UrlOriginal, HttpUserAgentOriginal

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
DstIpAddrproject
HttpUserAgentOriginalproject
Messageproject
SrcIpAddrproject
TimeGeneratedproject
UrlOriginalproject