Back
Idc7061f05-d0ed-40e1-862e-bc52e454e3a1
RulenameHoneyLabs TI Map IP Entity to CommonSecurityLog
DescriptionIdentifies source-IP matches in CommonSecurityLog (firewall, proxy and other CEF sources) against IP indicators from HoneyLabs honeypot telemetry. A match means a source IP that ran exploit or loader commands against HoneyLabs sensors also appeared as a source in your own logs. Only the structured SourceIP field is matched; destination IPs and IPs merely mentioned inside the free-text Message are ignored, because those are frequently unrelated and generate false positives. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.
SeverityMedium
TacticsInitialAccess
CommandAndControl
TechniquesT1190
T1071
Required data connectorsCEF
ThreatIntelligenceTaxii
KindScheduled
Query frequency1h
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapIPEntityCommonSecurityLog.yaml
Version1.0.0
Arm templatec7061f05-d0ed-40e1-862e-bc52e454e3a1.json
Deploy To Azure
let dt_lookBack = 1h;
let ioc_lookBack = 14d;
let HoneyLabs_IPs = ThreatIntelIndicators
  | where TimeGenerated >= ago(ioc_lookBack)
  | where IsActive == true and ValidUntil > now()
  | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
  | where SourceSystem startswith 'HoneyLabs'
  | where ObservableKey == 'ipv4-addr:value'
  | extend TI_ipEntity = tostring(ObservableValue),
           HoneyLabsConfidence = Confidence,
           HoneyLabsLabels = tostring(Data.labels),
           IndicatorDescription = tostring(Data.description),
           HoneyLabsReport = strcat('https://honeylabs.net/lookup/', tostring(ObservableValue));
HoneyLabs_IPs
| join kind=innerunique (
    CommonSecurityLog
    | where TimeGenerated >= ago(dt_lookBack)
    | where isnotempty(SourceIP)
    | extend CS_ipEntity = SourceIP
    | extend CommonSecurityLog_TimeGenerated = TimeGenerated
) on $left.TI_ipEntity == $right.CS_ipEntity
| where CommonSecurityLog_TimeGenerated < ValidUntil
| summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, CS_ipEntity
| project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,
  HoneyLabsConfidence, HoneyLabsLabels, HoneyLabsReport, TI_ipEntity, CS_ipEntity, LogSeverity,
  DeviceAction, SourceIP, DestinationIP, DeviceName, SourceUserName
| extend timestamp = CommonSecurityLog_TimeGenerated
name: HoneyLabs TI Map IP Entity to CommonSecurityLog
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: |
  'Identifies source-IP matches in CommonSecurityLog (firewall, proxy and other CEF sources) against IP indicators from HoneyLabs honeypot telemetry. A match means a source IP that ran exploit or loader commands against HoneyLabs sensors also appeared as a source in your own logs. Only the structured SourceIP field is matched; destination IPs and IPs merely mentioned inside the free-text Message are ignored, because those are frequently unrelated and generate false positives. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.'
id: c7061f05-d0ed-40e1-862e-bc52e454e3a1
triggerThreshold: 0
queryPeriod: 14d
query: |
  let dt_lookBack = 1h;
  let ioc_lookBack = 14d;
  let HoneyLabs_IPs = ThreatIntelIndicators
    | where TimeGenerated >= ago(ioc_lookBack)
    | where IsActive == true and ValidUntil > now()
    | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id
    | where SourceSystem startswith 'HoneyLabs'
    | where ObservableKey == 'ipv4-addr:value'
    | extend TI_ipEntity = tostring(ObservableValue),
             HoneyLabsConfidence = Confidence,
             HoneyLabsLabels = tostring(Data.labels),
             IndicatorDescription = tostring(Data.description),
             HoneyLabsReport = strcat('https://honeylabs.net/lookup/', tostring(ObservableValue));
  HoneyLabs_IPs
  | join kind=innerunique (
      CommonSecurityLog
      | where TimeGenerated >= ago(dt_lookBack)
      | where isnotempty(SourceIP)
      | extend CS_ipEntity = SourceIP
      | extend CommonSecurityLog_TimeGenerated = TimeGenerated
  ) on $left.TI_ipEntity == $right.CS_ipEntity
  | where CommonSecurityLog_TimeGenerated < ValidUntil
  | summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, CS_ipEntity
  | project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,
    HoneyLabsConfidence, HoneyLabsLabels, HoneyLabsReport, TI_ipEntity, CS_ipEntity, LogSeverity,
    DeviceAction, SourceIP, DestinationIP, DeviceName, SourceUserName
  | extend timestamp = CommonSecurityLog_TimeGenerated
version: 1.0.0
requiredDataConnectors:
- connectorId: ThreatIntelligenceTaxii
  dataTypes:
  - ThreatIntelligenceIndicator
- connectorId: CEF
  dataTypes:
  - CommonSecurityLog
severity: Medium
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapIPEntityCommonSecurityLog.yaml
relevantTechniques:
- T1190
- T1071
tactics:
- InitialAccess
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: CS_ipEntity
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/c7061f05-d0ed-40e1-862e-bc52e454e3a1')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/c7061f05-d0ed-40e1-862e-bc52e454e3a1')]",
      "properties": {
        "alertRuleTemplateName": "c7061f05-d0ed-40e1-862e-bc52e454e3a1",
        "customDetails": null,
        "description": "'Identifies source-IP matches in CommonSecurityLog (firewall, proxy and other CEF sources) against IP indicators from HoneyLabs honeypot telemetry. A match means a source IP that ran exploit or loader commands against HoneyLabs sensors also appeared as a source in your own logs. Only the structured SourceIP field is matched; destination IPs and IPs merely mentioned inside the free-text Message are ignored, because those are frequently unrelated and generate false positives. Indicator Confidence reflects how much evidence HoneyLabs holds (90 = 100+ observed attacks, 60 = a single sighting); raise the threshold in the query to trade coverage for precision.'\n",
        "displayName": "HoneyLabs TI Map IP Entity to CommonSecurityLog",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "CS_ipEntity",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/HoneyLabs/Analytic%20Rules/HoneyLabsTIMapIPEntityCommonSecurityLog.yaml",
        "query": "let dt_lookBack = 1h;\nlet ioc_lookBack = 14d;\nlet HoneyLabs_IPs = ThreatIntelIndicators\n  | where TimeGenerated >= ago(ioc_lookBack)\n  | where IsActive == true and ValidUntil > now()\n  | summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by Id\n  | where SourceSystem startswith 'HoneyLabs'\n  | where ObservableKey == 'ipv4-addr:value'\n  | extend TI_ipEntity = tostring(ObservableValue),\n           HoneyLabsConfidence = Confidence,\n           HoneyLabsLabels = tostring(Data.labels),\n           IndicatorDescription = tostring(Data.description),\n           HoneyLabsReport = strcat('https://honeylabs.net/lookup/', tostring(ObservableValue));\nHoneyLabs_IPs\n| join kind=innerunique (\n    CommonSecurityLog\n    | where TimeGenerated >= ago(dt_lookBack)\n    | where isnotempty(SourceIP)\n    | extend CS_ipEntity = SourceIP\n    | extend CommonSecurityLog_TimeGenerated = TimeGenerated\n) on $left.TI_ipEntity == $right.CS_ipEntity\n| where CommonSecurityLog_TimeGenerated < ValidUntil\n| summarize CommonSecurityLog_TimeGenerated = arg_max(CommonSecurityLog_TimeGenerated, *) by Id, CS_ipEntity\n| project CommonSecurityLog_TimeGenerated, IndicatorDescription, Id, ValidUntil,\n  HoneyLabsConfidence, HoneyLabsLabels, HoneyLabsReport, TI_ipEntity, CS_ipEntity, LogSeverity,\n  DeviceAction, SourceIP, DestinationIP, DeviceName, SourceUserName\n| extend timestamp = CommonSecurityLog_TimeGenerated\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P14D",
        "severity": "Medium",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "InitialAccess"
        ],
        "techniques": [
          "T1071",
          "T1190"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}