Analytic rule catalog
Whisper Security - Tor Exit Node Communication
Back
| Id | f5567c93-91de-577a-b35e-c2807715493d |
| Rulename | Whisper Security - Tor Exit Node Communication |
| Description | Identifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations. |
| Severity | Medium |
| Tactics | CommandAndControl |
| Techniques | T1090 |
| Required data connectors | WhisperSecurityConnector |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1d |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml |
| Version | 1.0.0 |
| Arm template | f5567c93-91de-577a-b35e-c2807715493d.json |
// MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy
// Tactic: Command and Control
// Detects communication with Tor exit nodes using Whisper threat intelligence
let timeRange = 1d;
let torIndicators = WhisperThreatIntel_CL
| where TimeGenerated > ago(timeRange)
| where isTor == true
| project indicator, threatScore, threatLevel, feedNames, lastSeen;
let CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);
CommonSecurityLogSafe
| where TimeGenerated > ago(timeRange)
| where isnotempty(DestinationIP)
| join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator
| extend SourceIP = SourceIP, DestinationIP = DestinationIP
| project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames
incidentConfiguration:
groupingConfiguration:
lookbackDuration: PT5H
reopenClosedIncident: false
matchingMethod: AllEntities
enabled: true
createIncident: true
name: Whisper Security - Tor Exit Node Communication
triggerOperator: gt
query: |
// MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy
// Tactic: Command and Control
// Detects communication with Tor exit nodes using Whisper threat intelligence
let timeRange = 1d;
let torIndicators = WhisperThreatIntel_CL
| where TimeGenerated > ago(timeRange)
| where isTor == true
| project indicator, threatScore, threatLevel, feedNames, lastSeen;
let CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);
CommonSecurityLogSafe
| where TimeGenerated > ago(timeRange)
| where isnotempty(DestinationIP)
| join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator
| extend SourceIP = SourceIP, DestinationIP = DestinationIP
| project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames
queryFrequency: 1h
description: |
Identifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations.
id: f5567c93-91de-577a-b35e-c2807715493d
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.0
kind: Scheduled
customDetails:
ThreatLevel: threatLevel
ThreatScore: threatScore
FeedNames: feedNames
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: WhisperSecurityConnector
dataTypes:
- WhisperThreatIntel_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml
relevantTechniques:
- T1090
tactics:
- CommandAndControl
entityMappings:
- fieldMappings:
- identifier: Address
columnName: SourceIP
entityType: IP
- fieldMappings:
- identifier: Address
columnName: DestinationIP
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/f5567c93-91de-577a-b35e-c2807715493d')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/f5567c93-91de-577a-b35e-c2807715493d')]",
"properties": {
"alertRuleTemplateName": "f5567c93-91de-577a-b35e-c2807715493d",
"customDetails": {
"FeedNames": "feedNames",
"ThreatLevel": "threatLevel",
"ThreatScore": "threatScore"
},
"description": "Identifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations.\n",
"displayName": "Whisper Security - Tor Exit Node Communication",
"enabled": true,
"entityMappings": [
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SourceIP",
"identifier": "Address"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "DestinationIP",
"identifier": "Address"
}
]
}
],
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"lookbackDuration": "PT5H",
"matchingMethod": "AllEntities",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml",
"query": "// MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy\n// Tactic: Command and Control\n// Detects communication with Tor exit nodes using Whisper threat intelligence\nlet timeRange = 1d;\nlet torIndicators = WhisperThreatIntel_CL\n | where TimeGenerated > ago(timeRange)\n | where isTor == true\n | project indicator, threatScore, threatLevel, feedNames, lastSeen;\nlet CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);\nCommonSecurityLogSafe\n | where TimeGenerated > ago(timeRange)\n | where isnotempty(DestinationIP)\n | join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator\n | extend SourceIP = SourceIP, DestinationIP = DestinationIP\n | project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames\n",
"queryFrequency": "PT1H",
"queryPeriod": "P1D",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl"
],
"techniques": [
"T1090"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}