Back
Id9c0a7304-287e-f1b2-8b4f-c7444b8511ea
RulenameUniFi Site Manager: WAN external IP geographic deviation
DescriptionSites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification.
TacticsReconnaissance
TechniquesT1590
Required data connectorsUniFiSiteManagerConnectorDefinition
KindHuntingQuery
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml
Version1.0.0
Arm template9c0a7304-287e-f1b2-8b4f-c7444b8511ea.json
Deploy To Azure
Unifi_SiteManager_Sites_CL
| where TimeGenerated > ago(30d)
| extend Site = tostring(Meta.name),
         WanIp = tostring(SiteStatistics.wans.WAN.externalIp),
         Asn = toint(SiteStatistics.ispInfo.asn),
         Isp = tostring(SiteStatistics.ispInfo.name)
| where isnotempty(WanIp)
| summarize ['Distinct ASNs'] = make_set(Asn),
            ['Distinct ISPs'] = make_set(Isp),
            ['WAN IPs']      = make_set(WanIp),
            ['First seen']   = min(TimeGenerated),
            ['Last seen']    = max(TimeGenerated) by HostName = Site
| extend ['ASN count'] = array_length(['Distinct ASNs']),
         ['ISP count'] = array_length(['Distinct ISPs']),
         IPAddress = tostring(['WAN IPs'][0])
| where ['ASN count'] > 1 or ['ISP count'] > 1
| order by ['ASN count'] desc, ['ISP count'] desc
id: 9c0a7304-287e-f1b2-8b4f-c7444b8511ea
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
  dataTypes:
  - Unifi_SiteManager_Sites_CL
description: |
  Sites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification.
name: 'UniFi Site Manager: WAN external IP geographic deviation'
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: HostName
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: IPAddress
  entityType: IP
tactics:
- Reconnaissance
kind: HuntingQuery
relevantTechniques:
- T1590
query: |
  Unifi_SiteManager_Sites_CL
  | where TimeGenerated > ago(30d)
  | extend Site = tostring(Meta.name),
           WanIp = tostring(SiteStatistics.wans.WAN.externalIp),
           Asn = toint(SiteStatistics.ispInfo.asn),
           Isp = tostring(SiteStatistics.ispInfo.name)
  | where isnotempty(WanIp)
  | summarize ['Distinct ASNs'] = make_set(Asn),
              ['Distinct ISPs'] = make_set(Isp),
              ['WAN IPs']      = make_set(WanIp),
              ['First seen']   = min(TimeGenerated),
              ['Last seen']    = max(TimeGenerated) by HostName = Site
  | extend ['ASN count'] = array_length(['Distinct ASNs']),
           ['ISP count'] = array_length(['Distinct ISPs']),
           IPAddress = tostring(['WAN IPs'][0])
  | where ['ASN count'] > 1 or ['ISP count'] > 1
  | order by ['ASN count'] desc, ['ISP count'] desc
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/9c0a7304-287e-f1b2-8b4f-c7444b8511ea')]",
      "kind": "Huntingquery",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/9c0a7304-287e-f1b2-8b4f-c7444b8511ea')]",
      "properties": {
        "alertRuleTemplateName": "9c0a7304-287e-f1b2-8b4f-c7444b8511ea",
        "customDetails": null,
        "description": "Sites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification.\n",
        "displayName": "UniFi Site Manager: WAN external IP geographic deviation",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "IPAddress",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml",
        "query": "Unifi_SiteManager_Sites_CL\n| where TimeGenerated > ago(30d)\n| extend Site = tostring(Meta.name),\n         WanIp = tostring(SiteStatistics.wans.WAN.externalIp),\n         Asn = toint(SiteStatistics.ispInfo.asn),\n         Isp = tostring(SiteStatistics.ispInfo.name)\n| where isnotempty(WanIp)\n| summarize ['Distinct ASNs'] = make_set(Asn),\n            ['Distinct ISPs'] = make_set(Isp),\n            ['WAN IPs']      = make_set(WanIp),\n            ['First seen']   = min(TimeGenerated),\n            ['Last seen']    = max(TimeGenerated) by HostName = Site\n| extend ['ASN count'] = array_length(['Distinct ASNs']),\n         ['ISP count'] = array_length(['Distinct ISPs']),\n         IPAddress = tostring(['WAN IPs'][0])\n| where ['ASN count'] > 1 or ['ISP count'] > 1\n| order by ['ASN count'] desc, ['ISP count'] desc\n",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Reconnaissance"
        ],
        "techniques": [
          "T1590"
        ],
        "templateVersion": "1.0.0"
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}