Back
Idef1a293a-9e2b-b087-7816-2610814ed2d4
RulenameUniFi Site Manager: External WAN IP changed
DescriptionIdentifies when a site reports more than one distinct WAN external IP within an hour, which may indicate ISP DHCP refresh, WAN reconfiguration, or routing hijack.
SeverityHigh
TacticsReconnaissance
TechniquesT1590
Required data connectorsUniFiSiteManagerConnectorDefinition
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudExternalWANIPchanged.yaml
Version1.0.0
Arm templateef1a293a-9e2b-b087-7816-2610814ed2d4.json
Deploy To Azure
Unifi_SiteManager_Sites_CL
      | where TimeGenerated > ago(1h)
      | extend SiteName = tostring(Meta.name),
               currentIp = tostring(SiteStatistics.wans.WAN.externalIp)
      | where isnotempty(currentIp)
      | summarize DistinctIps = make_set(currentIp), arg_max(TimeGenerated, currentIp) by SiteId, SiteName
      | where array_length(DistinctIps) > 1
      | extend Activity = strcat('WAN IP changed; observed: ', tostring(DistinctIps))
      | project TimeGenerated, SiteId, SiteName, Activity, CurrentIp = currentIp, ObservedIps = DistinctIps
subTechniques:
- T1590.005
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'UniFi Site Manager: External WAN IP changed'
triggerOperator: gt
query: |
  Unifi_SiteManager_Sites_CL
        | where TimeGenerated > ago(1h)
        | extend SiteName = tostring(Meta.name),
                 currentIp = tostring(SiteStatistics.wans.WAN.externalIp)
        | where isnotempty(currentIp)
        | summarize DistinctIps = make_set(currentIp), arg_max(TimeGenerated, currentIp) by SiteId, SiteName
        | where array_length(DistinctIps) > 1
        | extend Activity = strcat('WAN IP changed; observed: ', tostring(DistinctIps))
        | project TimeGenerated, SiteId, SiteName, Activity, CurrentIp = currentIp, ObservedIps = DistinctIps
queryFrequency: 1h
description: |
  Identifies when a site reports more than one distinct WAN external IP within an hour, which may indicate ISP DHCP refresh, WAN reconfiguration, or routing hijack.
id: ef1a293a-9e2b-b087-7816-2610814ed2d4
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
  dataTypes:
  - Unifi_SiteManager_Sites_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudExternalWANIPchanged.yaml
relevantTechniques:
- T1590
tactics:
- Reconnaissance
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: CurrentIp
  entityType: IP
- fieldMappings:
  - identifier: HostName
    columnName: SiteName
  entityType: Host
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/ef1a293a-9e2b-b087-7816-2610814ed2d4')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/ef1a293a-9e2b-b087-7816-2610814ed2d4')]",
      "properties": {
        "alertRuleTemplateName": "ef1a293a-9e2b-b087-7816-2610814ed2d4",
        "customDetails": null,
        "description": "Identifies when a site reports more than one distinct WAN external IP within an hour, which may indicate ISP DHCP refresh, WAN reconfiguration, or routing hijack.\n",
        "displayName": "UniFi Site Manager: External WAN IP changed",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "CurrentIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "SiteName",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudExternalWANIPchanged.yaml",
        "query": "Unifi_SiteManager_Sites_CL\n      | where TimeGenerated > ago(1h)\n      | extend SiteName = tostring(Meta.name),\n               currentIp = tostring(SiteStatistics.wans.WAN.externalIp)\n      | where isnotempty(currentIp)\n      | summarize DistinctIps = make_set(currentIp), arg_max(TimeGenerated, currentIp) by SiteId, SiteName\n      | where array_length(DistinctIps) > 1\n      | extend Activity = strcat('WAN IP changed; observed: ', tostring(DistinctIps))\n      | project TimeGenerated, SiteId, SiteName, Activity, CurrentIp = currentIp, ObservedIps = DistinctIps\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Reconnaissance"
        ],
        "techniques": [
          "T1590"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}