Detection rules › Kusto

Successful logins to SOC Prime platform from bad IP addresses

Status
available
Severity
medium
Time window
1h
Source
github.com/Azure/Azure-Sentinel

'This rule identifies successful logins from IP addresses previously flagged as malicious (e.g., botnets, TOR exit nodes, or known malicious IPs)'

MITRE ATT&CK coverage

TacticTechniques
Initial Access

Rule body

id: f8e7d6c5-b4a3-4122-8110-0987654321fe
name: Successful logins to SOC Prime platform from bad IP addresses
description: |
  'This rule identifies successful logins from IP addresses previously flagged as malicious (e.g., botnets, TOR exit nodes, or known malicious IPs)'
severity: Medium
status: Available
requiredDataConnectors:
  - connectorId: SOCPrimeAuditLogsDataConnector
    dataTypes:
      - SOCPrimeAuditLogs_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
triggerThreshold: 0
tactics:
  - InitialAccess
relevantTechniques:
  - T1078
query: |
  let blacklistIPs = _GetWatchlist('blacklistOfIps')
  | project IPAddress = column_ifexists('ip','IPAddress');
  SOCPrimeAuditLogs_CL
  | where EventName == "Logged in to the SOC Prime Platform"
  | where SourceIp in (blacklistIPs)
  | project TimeGenerated, EventName, UserEmail, UserName, SourceIp, Uri, Type
entityMappings:
  - entityType: Account
    fieldMappings:
      - identifier: Name
        columnName: UserName
  - entityType: IP
    fieldMappings:
      - identifier: Address
        columnName: SourceIp
version: 1.0.0
kind: Scheduled

Stages and Predicates

Let binding: blacklistIPs used in Stage 3

let blacklistIPs = _GetWatchlist('blacklistOfIps')
| project IPAddress = column_ifexists('ip','IPAddress');

Stage 1: source

SOCPrimeAuditLogs_CL

Stage 2: where

| where EventName == "Logged in to the SOC Prime Platform"

Stage 3: where

| where SourceIp in (blacklistIPs)

Stage 4: project

| project TimeGenerated, EventName, UserEmail, UserName, SourceIp, Uri, Type

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
EventNameproject
SourceIpproject
TimeGeneratedproject
Typeproject
Uriproject
UserEmailproject
UserNameproject