Analytic rule catalog
UniFi Site Manager WAN external IP geographic deviation
Back
| Id | 9c0a7304-287e-f1b2-8b4f-c7444b8511ea |
| Rulename | UniFi Site Manager: WAN external IP geographic deviation |
| Description | Sites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification. |
| Tactics | Reconnaissance |
| Techniques | T1590 |
| Required data connectors | UniFiSiteManagerConnectorDefinition |
| Kind | HuntingQuery |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml |
| Version | 1.0.0 |
| Arm template | 9c0a7304-287e-f1b2-8b4f-c7444b8511ea.json |
Unifi_SiteManager_Sites_CL
| where TimeGenerated > ago(30d)
| extend Site = tostring(Meta.name),
WanIp = tostring(SiteStatistics.wans.WAN.externalIp),
Asn = toint(SiteStatistics.ispInfo.asn),
Isp = tostring(SiteStatistics.ispInfo.name)
| where isnotempty(WanIp)
| summarize ['Distinct ASNs'] = make_set(Asn),
['Distinct ISPs'] = make_set(Isp),
['WAN IPs'] = make_set(WanIp),
['First seen'] = min(TimeGenerated),
['Last seen'] = max(TimeGenerated) by HostName = Site
| extend ['ASN count'] = array_length(['Distinct ASNs']),
['ISP count'] = array_length(['Distinct ISPs']),
IPAddress = tostring(['WAN IPs'][0])
| where ['ASN count'] > 1 or ['ISP count'] > 1
| order by ['ASN count'] desc, ['ISP count'] desc
id: 9c0a7304-287e-f1b2-8b4f-c7444b8511ea
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
dataTypes:
- Unifi_SiteManager_Sites_CL
description: |
Sites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification.
name: 'UniFi Site Manager: WAN external IP geographic deviation'
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml
entityMappings:
- fieldMappings:
- identifier: HostName
columnName: HostName
entityType: Host
- fieldMappings:
- identifier: Address
columnName: IPAddress
entityType: IP
tactics:
- Reconnaissance
kind: HuntingQuery
relevantTechniques:
- T1590
query: |
Unifi_SiteManager_Sites_CL
| where TimeGenerated > ago(30d)
| extend Site = tostring(Meta.name),
WanIp = tostring(SiteStatistics.wans.WAN.externalIp),
Asn = toint(SiteStatistics.ispInfo.asn),
Isp = tostring(SiteStatistics.ispInfo.name)
| where isnotempty(WanIp)
| summarize ['Distinct ASNs'] = make_set(Asn),
['Distinct ISPs'] = make_set(Isp),
['WAN IPs'] = make_set(WanIp),
['First seen'] = min(TimeGenerated),
['Last seen'] = max(TimeGenerated) by HostName = Site
| extend ['ASN count'] = array_length(['Distinct ASNs']),
['ISP count'] = array_length(['Distinct ISPs']),
IPAddress = tostring(['WAN IPs'][0])
| where ['ASN count'] > 1 or ['ISP count'] > 1
| order by ['ASN count'] desc, ['ISP count'] desc
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/9c0a7304-287e-f1b2-8b4f-c7444b8511ea')]",
"kind": "Huntingquery",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/9c0a7304-287e-f1b2-8b4f-c7444b8511ea')]",
"properties": {
"alertRuleTemplateName": "9c0a7304-287e-f1b2-8b4f-c7444b8511ea",
"customDetails": null,
"description": "Sites where the WAN external IP changed ASN or ISP within the last 30 days. Routine DHCP renewal stays within the same ISP; an ASN/ISP change suggests provider switch, BGP hijack, or routing anomaly that warrants verification.\n",
"displayName": "UniFi Site Manager: WAN external IP geographic deviation",
"enabled": true,
"entityMappings": [
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "HostName",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "IPAddress",
"identifier": "Address"
}
]
}
],
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Hunting%20Queries/UniFiCloudWANIPGeoDeviation.yaml",
"query": "Unifi_SiteManager_Sites_CL\n| where TimeGenerated > ago(30d)\n| extend Site = tostring(Meta.name),\n WanIp = tostring(SiteStatistics.wans.WAN.externalIp),\n Asn = toint(SiteStatistics.ispInfo.asn),\n Isp = tostring(SiteStatistics.ispInfo.name)\n| where isnotempty(WanIp)\n| summarize ['Distinct ASNs'] = make_set(Asn),\n ['Distinct ISPs'] = make_set(Isp),\n ['WAN IPs'] = make_set(WanIp),\n ['First seen'] = min(TimeGenerated),\n ['Last seen'] = max(TimeGenerated) by HostName = Site\n| extend ['ASN count'] = array_length(['Distinct ASNs']),\n ['ISP count'] = array_length(['Distinct ISPs']),\n IPAddress = tostring(['WAN IPs'][0])\n| where ['ASN count'] > 1 or ['ISP count'] > 1\n| order by ['ASN count'] desc, ['ISP count'] desc\n",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Reconnaissance"
],
"techniques": [
"T1590"
],
"templateVersion": "1.0.0"
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}