Back
Idf3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72
RulenameCisco ASA - Possible Data Exfiltration Detection
DescriptionDetects potential data exfiltration when an internal source IP sends a large amount of outbound data to the internet, especially when the volume is significantly higher than its normal behavior.
SeverityMedium
TacticsExfiltration
TechniquesT1041
T1048
Required data connectorsCiscoAsaAma
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CiscoASA/Analytic%20Rules/CiscoASA-PossibleDataExfiltration.yaml
Version1.0.2
Arm templatef3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72.json
Deploy To Azure
let Lookback = 1h;
let MinUploadBytes = 1073741824;
let MinUploadRatio = 95.0;
CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceProduct has_any ("ASA", "FTD")
| where isnotempty(SourceIP) and isnotempty(DestinationIP)
| where ipv4_is_private(SourceIP)
| where not(ipv4_is_private(DestinationIP))
| where DeviceAction in~ ("allow", "allowed", "accept", "accepted", "permitted")
| extend SentBytesLong = tolong(SentBytes)
| extend ReceivedBytesLong = tolong(ReceivedBytes)
| where isnotnull(SentBytesLong)
| summarize
    TotalBytesSent = sum(SentBytesLong),
    TotalBytesReceived = sum(coalesce(ReceivedBytesLong, 0)),
    Connections = count(),
    DestinationPorts = make_set(DestinationPort, 20),
    Applications = make_set(ApplicationProtocol, 20),
    FirstSeen = min(TimeGenerated),
    LastSeen = max(TimeGenerated)
    by SourceIP, DestinationIP
| where TotalBytesSent >= MinUploadBytes
| extend TotalGBSent = round(TotalBytesSent / 1024.0 / 1024.0 / 1024.0, 2)
| extend TotalGBReceived = round(TotalBytesReceived / 1024.0 / 1024.0 / 1024.0, 2)
| extend UploadRatio = round(todouble(TotalBytesSent) / todouble(TotalBytesSent + TotalBytesReceived) * 100, 2)
| where UploadRatio >= MinUploadRatio
| project
    TimeGenerated = LastSeen,
    SourceIP,
    DestinationIP,
    TotalGBSent,
    TotalGBReceived,
    UploadRatio,
    Connections,
    DestinationPorts,
    Applications,
    FirstSeen,
    LastSeen
| order by TotalGBSent desc
name: Cisco ASA - Possible Data Exfiltration Detection
triggerOperator: gt
query: |
  let Lookback = 1h;
  let MinUploadBytes = 1073741824;
  let MinUploadRatio = 95.0;
  CommonSecurityLog
  | where TimeGenerated > ago(Lookback)
  | where DeviceProduct has_any ("ASA", "FTD")
  | where isnotempty(SourceIP) and isnotempty(DestinationIP)
  | where ipv4_is_private(SourceIP)
  | where not(ipv4_is_private(DestinationIP))
  | where DeviceAction in~ ("allow", "allowed", "accept", "accepted", "permitted")
  | extend SentBytesLong = tolong(SentBytes)
  | extend ReceivedBytesLong = tolong(ReceivedBytes)
  | where isnotnull(SentBytesLong)
  | summarize
      TotalBytesSent = sum(SentBytesLong),
      TotalBytesReceived = sum(coalesce(ReceivedBytesLong, 0)),
      Connections = count(),
      DestinationPorts = make_set(DestinationPort, 20),
      Applications = make_set(ApplicationProtocol, 20),
      FirstSeen = min(TimeGenerated),
      LastSeen = max(TimeGenerated)
      by SourceIP, DestinationIP
  | where TotalBytesSent >= MinUploadBytes
  | extend TotalGBSent = round(TotalBytesSent / 1024.0 / 1024.0 / 1024.0, 2)
  | extend TotalGBReceived = round(TotalBytesReceived / 1024.0 / 1024.0 / 1024.0, 2)
  | extend UploadRatio = round(todouble(TotalBytesSent) / todouble(TotalBytesSent + TotalBytesReceived) * 100, 2)
  | where UploadRatio >= MinUploadRatio
  | project
      TimeGenerated = LastSeen,
      SourceIP,
      DestinationIP,
      TotalGBSent,
      TotalGBReceived,
      UploadRatio,
      Connections,
      DestinationPorts,
      Applications,
      FirstSeen,
      LastSeen
  | order by TotalGBSent desc
queryFrequency: 1h
description: |
  'Detects potential data exfiltration when an internal source IP sends a large amount of outbound data to the internet, especially when the volume is significantly higher than its normal behavior.'
id: f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.2
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: CiscoAsaAma
  dataTypes:
  - CommonSecurityLog
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CiscoASA/Analytic%20Rules/CiscoASA-PossibleDataExfiltration.yaml
relevantTechniques:
- T1041
- T1048
tactics:
- Exfiltration
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: SourceIP
  entityType: IP
- fieldMappings:
  - identifier: Address
    columnName: DestinationIP
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72')]",
      "properties": {
        "alertRuleTemplateName": "f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72",
        "customDetails": null,
        "description": "'Detects potential data exfiltration when an internal source IP sends a large amount of outbound data to the internet, especially when the volume is significantly higher than its normal behavior.'\n",
        "displayName": "Cisco ASA - Possible Data Exfiltration Detection",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SourceIP",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "DestinationIP",
                "identifier": "Address"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/CiscoASA/Analytic%20Rules/CiscoASA-PossibleDataExfiltration.yaml",
        "query": "let Lookback = 1h;\nlet MinUploadBytes = 1073741824;\nlet MinUploadRatio = 95.0;\nCommonSecurityLog\n| where TimeGenerated > ago(Lookback)\n| where DeviceProduct has_any (\"ASA\", \"FTD\")\n| where isnotempty(SourceIP) and isnotempty(DestinationIP)\n| where ipv4_is_private(SourceIP)\n| where not(ipv4_is_private(DestinationIP))\n| where DeviceAction in~ (\"allow\", \"allowed\", \"accept\", \"accepted\", \"permitted\")\n| extend SentBytesLong = tolong(SentBytes)\n| extend ReceivedBytesLong = tolong(ReceivedBytes)\n| where isnotnull(SentBytesLong)\n| summarize\n    TotalBytesSent = sum(SentBytesLong),\n    TotalBytesReceived = sum(coalesce(ReceivedBytesLong, 0)),\n    Connections = count(),\n    DestinationPorts = make_set(DestinationPort, 20),\n    Applications = make_set(ApplicationProtocol, 20),\n    FirstSeen = min(TimeGenerated),\n    LastSeen = max(TimeGenerated)\n    by SourceIP, DestinationIP\n| where TotalBytesSent >= MinUploadBytes\n| extend TotalGBSent = round(TotalBytesSent / 1024.0 / 1024.0 / 1024.0, 2)\n| extend TotalGBReceived = round(TotalBytesReceived / 1024.0 / 1024.0 / 1024.0, 2)\n| extend UploadRatio = round(todouble(TotalBytesSent) / todouble(TotalBytesSent + TotalBytesReceived) * 100, 2)\n| where UploadRatio >= MinUploadRatio\n| project\n    TimeGenerated = LastSeen,\n    SourceIP,\n    DestinationIP,\n    TotalGBSent,\n    TotalGBReceived,\n    UploadRatio,\n    Connections,\n    DestinationPorts,\n    Applications,\n    FirstSeen,\n    LastSeen\n| order by TotalGBSent desc\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Exfiltration"
        ],
        "techniques": [
          "T1041",
          "T1048"
        ],
        "templateVersion": "1.0.2",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}