Back
Id40cf9670-d4be-4149-9082-5809a2b12ca1
Rulenameiboss - Command-and-Control Detected
DescriptionIdentifies web traffic where the iboss platform flagged command-and-control (C2) activity. A populated CNCDetected flag indicates the gateway observed communication to a known or suspected C2 destination. Surfaces the user, destination URL, and host to support triage of potentially compromised endpoints.
SeverityHigh
TacticsCommandAndControl
TechniquesT1071
Required data connectorsibossAma
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/iboss/Analytic%20Rules/ibossCommandAndControlDetected.yaml
Version1.0.0
Arm template40cf9670-d4be-4149-9082-5809a2b12ca1.json
Deploy To Azure
ibossUrlEvent
| where CNCDetected == 1
| project EventTime, SrcUsername, Url, Domain, SrcIpAddr, DstIpAddr, DstPortNumber, DvcAction, UrlCategory, HttpUserAgent
name: iboss - Command-and-Control Detected
triggerOperator: gt
query: |
  ibossUrlEvent
  | where CNCDetected == 1
  | project EventTime, SrcUsername, Url, Domain, SrcIpAddr, DstIpAddr, DstPortNumber, DvcAction, UrlCategory, HttpUserAgent
queryFrequency: 1h
description: |
  Identifies web traffic where the iboss platform flagged command-and-control (C2) activity. A populated CNCDetected flag indicates the gateway observed communication to a known or suspected C2 destination. Surfaces the user, destination URL, and host to support triage of potentially compromised endpoints.
id: 40cf9670-d4be-4149-9082-5809a2b12ca1
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: ibossAma
  dataTypes:
  - CommonSecurityLog
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/iboss/Analytic%20Rules/ibossCommandAndControlDetected.yaml
relevantTechniques:
- T1071
tactics:
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: SrcUsername
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: SrcIpAddr
  entityType: IP
- fieldMappings:
  - identifier: Url
    columnName: Url
  entityType: URL
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/40cf9670-d4be-4149-9082-5809a2b12ca1')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/40cf9670-d4be-4149-9082-5809a2b12ca1')]",
      "properties": {
        "alertRuleTemplateName": "40cf9670-d4be-4149-9082-5809a2b12ca1",
        "customDetails": null,
        "description": "Identifies web traffic where the iboss platform flagged command-and-control (C2) activity. A populated CNCDetected flag indicates the gateway observed communication to a known or suspected C2 destination. Surfaces the user, destination URL, and host to support triage of potentially compromised endpoints.\n",
        "displayName": "iboss - Command-and-Control Detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "SrcUsername",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIpAddr",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "Url",
                "identifier": "Url"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/iboss/Analytic%20Rules/ibossCommandAndControlDetected.yaml",
        "query": "ibossUrlEvent\n| where CNCDetected == 1\n| project EventTime, SrcUsername, Url, Domain, SrcIpAddr, DstIpAddr, DstPortNumber, DvcAction, UrlCategory, HttpUserAgent\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl"
        ],
        "techniques": [
          "T1071"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}