Back
Id0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0
RulenameTailscale Premium: DERP relay traffic surge
DescriptionIdentifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale IsRelayed flag, traffic via 127.3.3.40). Operational signal useful for spotting policy drift.
SeverityLow
TacticsCommandAndControl
TechniquesT1572
Required data connectorsTailscalePremiumCCF
KindScheduled
Query frequency15m
Query period15m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscalePremiumDerpRelaySurge.yaml
Version1.0.0
Arm template0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0.json
Deploy To Azure
let minFlows = 20;
let relayedPctThreshold = 75.0;
Tailscale_Network_CL
| where TimeGenerated > ago(15m)
| summarize
    TotalFlows = count(),
    RelayedFlows = countif(IsRelayed)
    by SrcNodeName, SrcUser, SrcOs, SrcTags=tostring(SrcTags)
| where TotalFlows >= minFlows
| extend RelayedPct = round(100.0 * RelayedFlows / TotalFlows, 1)
| where RelayedPct > relayedPctThreshold
| project SrcNodeName, SrcUser, SrcOs, SrcTags, TotalFlows, RelayedFlows, RelayedPct
| order by RelayedPct desc
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT6H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'Tailscale Premium: DERP relay traffic surge'
triggerOperator: gt
query: |
  let minFlows = 20;
  let relayedPctThreshold = 75.0;
  Tailscale_Network_CL
  | where TimeGenerated > ago(15m)
  | summarize
      TotalFlows = count(),
      RelayedFlows = countif(IsRelayed)
      by SrcNodeName, SrcUser, SrcOs, SrcTags=tostring(SrcTags)
  | where TotalFlows >= minFlows
  | extend RelayedPct = round(100.0 * RelayedFlows / TotalFlows, 1)
  | where RelayedPct > relayedPctThreshold
  | project SrcNodeName, SrcUser, SrcOs, SrcTags, TotalFlows, RelayedFlows, RelayedPct
  | order by RelayedPct desc
queryFrequency: 15m
description: Identifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale IsRelayed flag, traffic via 127.3.3.40). Operational signal useful for spotting policy drift.
id: 0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0
triggerThreshold: 0
queryPeriod: 15m
version: 1.0.0
kind: Scheduled
status: Available
severity: Low
requiredDataConnectors:
- connectorId: TailscalePremiumCCF
  dataTypes:
  - Tailscale_Network_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscalePremiumDerpRelaySurge.yaml
description-detailed: |
  Identifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale's IsRelayed flag, traffic via 127.3.3.40). Sustained high relay rate indicates direct WireGuard peer-to-peer is failing - causes include NAT/firewall changes, a network blocking UDP 41641, or potential evasion attempts. Operational signal but useful for spotting policy drift. Requires Tailscale Premium or Enterprise.
relevantTechniques:
- T1572
tactics:
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: SrcNodeName
  entityType: Host
- fieldMappings:
  - identifier: FullName
    columnName: SrcUser
  entityType: Account
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0')]",
      "properties": {
        "alertRuleTemplateName": "0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0",
        "customDetails": null,
        "description": "Identifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale IsRelayed flag, traffic via 127.3.3.40). Operational signal useful for spotting policy drift.",
        "description-detailed": "Identifies when a source node has more than 75 percent of its recent flows falling back to a DERP relay (Tailscale's IsRelayed flag, traffic via 127.3.3.40). Sustained high relay rate indicates direct WireGuard peer-to-peer is failing - causes include NAT/firewall changes, a network blocking UDP 41641, or potential evasion attempts. Operational signal but useful for spotting policy drift. Requires Tailscale Premium or Enterprise.\n",
        "displayName": "Tailscale Premium: DERP relay traffic surge",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "SrcNodeName",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "SrcUser",
                "identifier": "FullName"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT6H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tailscale%20%28CCF%29/Analytic%20Rules/TailscalePremiumDerpRelaySurge.yaml",
        "query": "let minFlows = 20;\nlet relayedPctThreshold = 75.0;\nTailscale_Network_CL\n| where TimeGenerated > ago(15m)\n| summarize\n    TotalFlows = count(),\n    RelayedFlows = countif(IsRelayed)\n    by SrcNodeName, SrcUser, SrcOs, SrcTags=tostring(SrcTags)\n| where TotalFlows >= minFlows\n| extend RelayedPct = round(100.0 * RelayedFlows / TotalFlows, 1)\n| where RelayedPct > relayedPctThreshold\n| project SrcNodeName, SrcUser, SrcOs, SrcTags, TotalFlows, RelayedFlows, RelayedPct\n| order by RelayedPct desc\n",
        "queryFrequency": "PT15M",
        "queryPeriod": "PT15M",
        "severity": "Low",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl"
        ],
        "techniques": [
          "T1572"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}