Cisco Umbrella - Windows PowerShell User-Agent Detected
| Id | b12b3dab-d973-45af-b07e-e29bb34d8db9 |
| Rulename | Cisco Umbrella - Windows PowerShell User-Agent Detected |
| Description | Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser. |
| Severity | Medium |
| Tactics | CommandAndControl DefenseEvasion |
| Required data connectors | CiscoUmbrellaDataConnector |
| Kind | Scheduled |
| Query frequency | 15m |
| Query period | 15m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Detections/CiscoUmbrella/CiscoUmbrellaPowershellUserAgentDetected.yaml |
| Version | 1.1.2 |
| Arm template | b12b3dab-d973-45af-b07e-e29bb34d8db9.json |
let timeframe = 15m;
Cisco_Umbrella
| where EventType == "proxylogs"
| where TimeGenerated > ago(timeframe)
| where HttpUserAgentOriginal contains "WindowsPowerShell"
| extend Message = "Windows PowerShell User Agent"
| project Message, SrcIpAddr, DstIpAddr, UrlOriginal, TimeGenerated,HttpUserAgentOriginal
description: |
'Rule helps to detect Powershell user-agent activity by an unusual process other than a web browser.'
kind: Scheduled
tactics:
- CommandAndControl
- DefenseEvasion
requiredDataConnectors:
- connectorId: CiscoUmbrellaDataConnector
dataTypes:
- Cisco_Umbrella_proxy_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Detections/CiscoUmbrella/CiscoUmbrellaPowershellUserAgentDetected.yaml
severity: Medium
name: Cisco Umbrella - Windows PowerShell User-Agent Detected
triggerThreshold: 0
queryPeriod: 15m
query: |
let timeframe = 15m;
Cisco_Umbrella
| where EventType == "proxylogs"
| where TimeGenerated > ago(timeframe)
| where HttpUserAgentOriginal contains "WindowsPowerShell"
| extend Message = "Windows PowerShell User Agent"
| project Message, SrcIpAddr, DstIpAddr, UrlOriginal, TimeGenerated,HttpUserAgentOriginal
id: b12b3dab-d973-45af-b07e-e29bb34d8db9
queryFrequency: 15m
entityMappings:
- entityType: URL
fieldMappings:
- columnName: UrlOriginal
identifier: Url
- entityType: IP
fieldMappings:
- columnName: SrcIpAddr
identifier: Address
triggerOperator: gt
version: 1.1.2