Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Multiple Sources Affected by the Same TI Destination

RulenameMultiple Sources Affected by the Same TI Destination
DescriptionIdentifies multiple machines trying to reach out to the same destination blocked by TI in Azure Firewall. This can indicate attack on the organization by the same attack group.

Configurable Parameters:

- Minimum affected threshold - alert only if more than this number of hosts affected. Default is set to 5.

- Recommendation is to use the new resource specific logs. If you are using both, the TiTraffic Count will be duplicated.
Required data connectorsAzureFirewall
Query frequency1d
Query period1d
Trigger threshold1
Trigger operatorgt
Source Uri Firewall/Analytic Rules/Azure Firewall - Multiple Sources Affected by the Same TI Destination.yaml
Arm template4644baf7-3464-45dd-bd9d-e07687e25f81.json
Deploy To Azure
let RunTime = 1d; 
let StartRunTime = 1d; 
let EndRunTime = StartRunTime - RunTime; 
let MinAffectedThreshold = 5;
union isfuzzy=true
| where TimeGenerated  between (ago(StartRunTime) .. ago(EndRunTime))
| where OperationName == "AzureFirewallThreatIntelLog"
| parse msg_s with * "from " SourceIp ":" SourcePort:int " to " Fqdn ":" DestinationPort:int  "." * "Action: Deny. " ThreatDescription),
| where TimeGenerated between (ago(StartRunTime) .. ago(EndRunTime)))
| summarize TiTrafficCount = count(), dCountSourceIps = dcount(SourceIp), AffectedIps = make_set(SourceIp, 10000) by Fqdn, ThreatDescription
| where array_length(AffectedIps) > MinAffectedThreshold
| mv-expand SourceIp = AffectedIps
| order by TiTrafficCount desc, Fqdn asc, parse_ipv4(tostring(SourceIp)) asc
description: |
  'Identifies multiple machines trying to reach out to the same destination blocked by TI in Azure Firewall. This can indicate attack on the organization by the same attack group.

  Configurable Parameters:

  - Minimum affected threshold - alert only if more than this number of hosts affected. Default is set to 5.
  - Recommendation is to use the new resource specific logs. If you are using both, the TiTraffic Count will be duplicated.'  
version: 1.1.3
- Exfiltration
- CommandAndControl
- entityType: IP
  - columnName: SourceIp
    identifier: Address
- entityType: URL
  - columnName: Fqdn
    identifier: Url
queryFrequency: 1d
triggerThreshold: 1
query: |
  let RunTime = 1d; 
  let StartRunTime = 1d; 
  let EndRunTime = StartRunTime - RunTime; 
  let MinAffectedThreshold = 5;
  union isfuzzy=true
  | where TimeGenerated  between (ago(StartRunTime) .. ago(EndRunTime))
  | where OperationName == "AzureFirewallThreatIntelLog"
  | parse msg_s with * "from " SourceIp ":" SourcePort:int " to " Fqdn ":" DestinationPort:int  "." * "Action: Deny. " ThreatDescription),
  | where TimeGenerated between (ago(StartRunTime) .. ago(EndRunTime)))
  | summarize TiTrafficCount = count(), dCountSourceIps = dcount(SourceIp), AffectedIps = make_set(SourceIp, 10000) by Fqdn, ThreatDescription
  | where array_length(AffectedIps) > MinAffectedThreshold
  | mv-expand SourceIp = AffectedIps
  | order by TiTrafficCount desc, Fqdn asc, parse_ipv4(tostring(SourceIp)) asc  
triggerOperator: gt
status: Available
- T1041
- T1071
OriginalUri: Firewall/Analytic Rules/Azure Firewall - Multiple Sources Affected by the Same TI Destination.yaml
queryPeriod: 1d
id: 4644baf7-3464-45dd-bd9d-e07687e25f81
name: Multiple Sources Affected by the Same TI Destination
kind: Scheduled
- connectorId: AzureFirewall
  - AzureDiagnostics
  - AZFWThreatIntel
severity: Medium
  "$schema": "",
  "contentVersion": "",
  "parameters": {
    "workspace": {
      "type": "String"
  "resources": [
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/4644baf7-3464-45dd-bd9d-e07687e25f81')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/4644baf7-3464-45dd-bd9d-e07687e25f81')]",
      "properties": {
        "alertRuleTemplateName": "4644baf7-3464-45dd-bd9d-e07687e25f81",
        "customDetails": null,
        "description": "'Identifies multiple machines trying to reach out to the same destination blocked by TI in Azure Firewall. This can indicate attack on the organization by the same attack group.\n\nConfigurable Parameters:\n\n- Minimum affected threshold - alert only if more than this number of hosts affected. Default is set to 5.\n- Recommendation is to use the new resource specific logs. If you are using both, the TiTraffic Count will be duplicated.'\n",
        "displayName": "Multiple Sources Affected by the Same TI Destination",
        "enabled": true,
        "entityMappings": [
            "entityType": "IP",
            "fieldMappings": [
                "columnName": "SourceIp",
                "identifier": "Address"
            "entityType": "URL",
            "fieldMappings": [
                "columnName": "Fqdn",
                "identifier": "Url"
        "OriginalUri": " Firewall/Analytic Rules/Azure Firewall - Multiple Sources Affected by the Same TI Destination.yaml",
        "query": "let RunTime = 1d; \nlet StartRunTime = 1d; \nlet EndRunTime = StartRunTime - RunTime; \nlet MinAffectedThreshold = 5;\nunion isfuzzy=true\n(AzureDiagnostics \n| where TimeGenerated  between (ago(StartRunTime) .. ago(EndRunTime))\n| where OperationName == \"AzureFirewallThreatIntelLog\"\n| parse msg_s with * \"from \" SourceIp \":\" SourcePort:int \" to \" Fqdn \":\" DestinationPort:int  \".\" * \"Action: Deny. \" ThreatDescription),\n(AZFWThreatIntel\n| where TimeGenerated between (ago(StartRunTime) .. ago(EndRunTime)))\n| summarize TiTrafficCount = count(), dCountSourceIps = dcount(SourceIp), AffectedIps = make_set(SourceIp, 10000) by Fqdn, ThreatDescription\n| where array_length(AffectedIps) > MinAffectedThreshold\n| mv-expand SourceIp = AffectedIps\n| order by TiTrafficCount desc, Fqdn asc, parse_ipv4(tostring(SourceIp)) asc\n",
        "queryFrequency": "P1D",
        "queryPeriod": "P1D",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
        "techniques": [
        "templateVersion": "1.1.3",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 1
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"