Detection rules › Sigma
Activity from Suspicious IP Addresses
Detects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Command & Control |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Microsoft 365 | Activity from suspicious IP addresses |
Rule body
title: Activity from Suspicious IP Addresses
id: a3501e8e-af9e-43c6-8cd6-9360bdaae498
status: test
description: |
Detects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence.
These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
references:
- https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
- https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference
author: Austin Songer @austinsonger
date: 2021-08-23
modified: 2022-10-09
tags:
- attack.command-and-control
- attack.t1573
logsource:
service: threat_detection
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
eventName: 'Activity from suspicious IP addresses'
status: success
condition: selection
falsepositives:
- Unknown
level: medium
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
eventSource: SecurityComplianceCenter
eventName: 'Activity from suspicious IP addresses'
status: success
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
eventName | eq |
| field:"aws::eventName" kind:eq value:"Activity from suspicious IP addresses" |
eventSource | eq |
| field:"aws::eventSource" kind:eq value:"SecurityComplianceCenter" |
status | eq |
| field:"status" kind:eq value:"success" |