Back
Idafe2a5ff-f4fe-4dee-8b6b-fd28d29d6738
RulenameHoneyLabs TI Map URL Entity to CommonSecurityLog
DescriptionIdentifies requests in CommonSecurityLog to malware loader or command-and-control URLs that HoneyLabs pulled out of payloads captured by its honeypot sensors. A hit usually means a host inside your estate reached out to attacker-controlled infrastructure, so treat it as post-compromise until proven otherwise. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.
SeverityHigh
TacticsCommandAndControl
Execution
TechniquesT1071
T1105
Required data connectorsCEF
ThreatIntelligenceTaxii
KindScheduled
Query frequency1h
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapURLEntityCommonSecurityLog.yaml
Version1.0.0
Arm templateafe2a5ff-f4fe-4dee-8b6b-fd28d29d6738.json
Deploy To Azure
let dt_lookBack = 1h;
let ioc_lookBack = 14d;
let HoneyLabs_URLs = ThreatIntelIndicators
  | where TimeGenerated >= ago(ioc_lookBack)
  | where IsActive == true and ValidUntil > now()
  | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
  | where SourceSystem startswith 'HoneyLabs'
  | where ObservableKey == 'url:value'
  | extend TI_urlEntity = tostring(ObservableValue),
           HoneyLabsConfidence = Confidence,
           IndicatorDescription = tostring(Data.description);
HoneyLabs_URLs
| join kind=innerunique (
    CommonSecurityLog
    | where TimeGenerated >= ago(dt_lookBack)
    | where isnotempty(RequestURL)
    | extend CommonSecurityLog_TimeGenerated = TimeGenerated
) on $left.TI_urlEntity == $right.RequestURL
| where CommonSecurityLog_TimeGenerated < ValidUntil
| summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, TI_urlEntity
| project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,
  HoneyLabsConfidence, TI_urlEntity, SourceIP, DestinationIP, DeviceName, DeviceAction,
  SourceUserName, RequestClientApplication
| extend timestamp = CommonSecurityLog_TimeGenerated
name: HoneyLabs TI Map URL Entity to CommonSecurityLog
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: |
  'Identifies requests in CommonSecurityLog to malware loader or command-and-control URLs that HoneyLabs pulled out of payloads captured by its honeypot sensors. A hit usually means a host inside your estate reached out to attacker-controlled infrastructure, so treat it as post-compromise until proven otherwise. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.'
id: afe2a5ff-f4fe-4dee-8b6b-fd28d29d6738
triggerThreshold: 0
queryPeriod: 14d
query: |
  let dt_lookBack = 1h;
  let ioc_lookBack = 14d;
  let HoneyLabs_URLs = ThreatIntelIndicators
    | where TimeGenerated >= ago(ioc_lookBack)
    | where IsActive == true and ValidUntil > now()
    | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
    | where SourceSystem startswith 'HoneyLabs'
    | where ObservableKey == 'url:value'
    | extend TI_urlEntity = tostring(ObservableValue),
             HoneyLabsConfidence = Confidence,
             IndicatorDescription = tostring(Data.description);
  HoneyLabs_URLs
  | join kind=innerunique (
      CommonSecurityLog
      | where TimeGenerated >= ago(dt_lookBack)
      | where isnotempty(RequestURL)
      | extend CommonSecurityLog_TimeGenerated = TimeGenerated
  ) on $left.TI_urlEntity == $right.RequestURL
  | where CommonSecurityLog_TimeGenerated < ValidUntil
  | summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, TI_urlEntity
  | project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,
    HoneyLabsConfidence, TI_urlEntity, SourceIP, DestinationIP, DeviceName, DeviceAction,
    SourceUserName, RequestClientApplication
  | extend timestamp = CommonSecurityLog_TimeGenerated
version: 1.0.0
requiredDataConnectors:
- connectorId: ThreatIntelligenceTaxii
  dataTypes:
  - ThreatIntelligenceIndicator
- connectorId: CEF
  dataTypes:
  - CommonSecurityLog
severity: High
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapURLEntityCommonSecurityLog.yaml
relevantTechniques:
- T1071
- T1105
tactics:
- CommandAndControl
- Execution
entityMappings:
- fieldMappings:
  - identifier: Url
    columnName: TI_urlEntity
  entityType: URL
- fieldMappings:
  - identifier: Address
    columnName: SourceIP
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/afe2a5ff-f4fe-4dee-8b6b-fd28d29d6738')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/afe2a5ff-f4fe-4dee-8b6b-fd28d29d6738')]",
      "properties": {
        "alertRuleTemplateName": "afe2a5ff-f4fe-4dee-8b6b-fd28d29d6738",
        "customDetails": null,
        "description": "'Identifies requests in CommonSecurityLog to malware loader or command-and-control URLs that HoneyLabs pulled out of payloads captured by its honeypot sensors. A hit usually means a host inside your estate reached out to attacker-controlled infrastructure, so treat it as post-compromise until proven otherwise. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.'\n",
        "displayName": "HoneyLabs TI Map URL Entity to CommonSecurityLog",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "TI_urlEntity",
                "identifier": "Url"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SourceIP",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapURLEntityCommonSecurityLog.yaml",
        "query": "let dt_lookBack = 1h;\nlet ioc_lookBack = 14d;\nlet HoneyLabs_URLs = ThreatIntelIndicators\n  | where TimeGenerated >= ago(ioc_lookBack)\n  | where IsActive == true and ValidUntil > now()\n  | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id\n  | where SourceSystem startswith 'HoneyLabs'\n  | where ObservableKey == 'url:value'\n  | extend TI_urlEntity = tostring(ObservableValue),\n           HoneyLabsConfidence = Confidence,\n           IndicatorDescription = tostring(Data.description);\nHoneyLabs_URLs\n| join kind=innerunique (\n    CommonSecurityLog\n    | where TimeGenerated >= ago(dt_lookBack)\n    | where isnotempty(RequestURL)\n    | extend CommonSecurityLog_TimeGenerated = TimeGenerated\n) on $left.TI_urlEntity == $right.RequestURL\n| where CommonSecurityLog_TimeGenerated < ValidUntil\n| summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, TI_urlEntity\n| project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,\n  HoneyLabsConfidence, TI_urlEntity, SourceIP, DestinationIP, DeviceName, DeviceAction,\n  SourceUserName, RequestClientApplication\n| extend timestamp = CommonSecurityLog_TimeGenerated\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "High",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Execution"
        ],
        "techniques": [
          "T1071",
          "T1105"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}