Back
Idf5567c93-91de-577a-b35e-c2807715493d
RulenameWhisper Security - Tor Exit Node Communication
DescriptionIdentifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations.
SeverityMedium
TacticsCommandAndControl
TechniquesT1090
Required data connectorsWhisperSecurityConnector
KindScheduled
Query frequency1h
Query period1d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml
Version1.0.0
Arm templatef5567c93-91de-577a-b35e-c2807715493d.json
Deploy To Azure
// MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy
// Tactic: Command and Control
// Detects communication with Tor exit nodes using Whisper threat intelligence
let timeRange = 1d;
let torIndicators = WhisperThreatIntel_CL
    | where TimeGenerated > ago(timeRange)
    | where isTor == true
    | project indicator, threatScore, threatLevel, feedNames, lastSeen;
let CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);
CommonSecurityLogSafe
    | where TimeGenerated > ago(timeRange)
    | where isnotempty(DestinationIP)
    | join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator
    | extend SourceIP = SourceIP, DestinationIP = DestinationIP
    | project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: Whisper Security - Tor Exit Node Communication
triggerOperator: gt
query: |
  // MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy
  // Tactic: Command and Control
  // Detects communication with Tor exit nodes using Whisper threat intelligence
  let timeRange = 1d;
  let torIndicators = WhisperThreatIntel_CL
      | where TimeGenerated > ago(timeRange)
      | where isTor == true
      | project indicator, threatScore, threatLevel, feedNames, lastSeen;
  let CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);
  CommonSecurityLogSafe
      | where TimeGenerated > ago(timeRange)
      | where isnotempty(DestinationIP)
      | join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator
      | extend SourceIP = SourceIP, DestinationIP = DestinationIP
      | project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames
queryFrequency: 1h
description: |
  Identifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations.
id: f5567c93-91de-577a-b35e-c2807715493d
triggerThreshold: 0
queryPeriod: 1d
version: 1.0.0
kind: Scheduled
customDetails:
  ThreatLevel: threatLevel
  ThreatScore: threatScore
  FeedNames: feedNames
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: WhisperSecurityConnector
  dataTypes:
  - WhisperThreatIntel_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml
relevantTechniques:
- T1090
tactics:
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: SourceIP
  entityType: IP
- fieldMappings:
  - identifier: Address
    columnName: DestinationIP
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/f5567c93-91de-577a-b35e-c2807715493d')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/f5567c93-91de-577a-b35e-c2807715493d')]",
      "properties": {
        "alertRuleTemplateName": "f5567c93-91de-577a-b35e-c2807715493d",
        "customDetails": {
          "FeedNames": "feedNames",
          "ThreatLevel": "threatLevel",
          "ThreatScore": "threatScore"
        },
        "description": "Identifies network traffic communicating with known Tor exit nodes. While Tor usage may be legitimate in some environments, unexpected Tor communication can indicate data exfiltration, C2 tunneling, or policy violations.\n",
        "displayName": "Whisper Security - Tor Exit Node Communication",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SourceIP",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "DestinationIP",
                "identifier": "Address"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Whisper/Analytic%20Rules/TorExitNodeCommunication.yaml",
        "query": "// MITRE ATT&CK: T1090.003 - Proxy: Multi-hop Proxy\n// Tactic: Command and Control\n// Detects communication with Tor exit nodes using Whisper threat intelligence\nlet timeRange = 1d;\nlet torIndicators = WhisperThreatIntel_CL\n    | where TimeGenerated > ago(timeRange)\n    | where isTor == true\n    | project indicator, threatScore, threatLevel, feedNames, lastSeen;\nlet CommonSecurityLogSafe = union isfuzzy=true CommonSecurityLog, (datatable(TimeGenerated:datetime, DestinationIP:string, SourceIP:string, DeviceProduct:string, DeviceAction:string, DeviceVendor:string, Activity:string)[]);\nCommonSecurityLogSafe\n    | where TimeGenerated > ago(timeRange)\n    | where isnotempty(DestinationIP)\n    | join kind=inner (torIndicators) on $left.DestinationIP == $right.indicator\n    | extend SourceIP = SourceIP, DestinationIP = DestinationIP\n    | project TimeGenerated, SourceIP, DestinationIP, DeviceProduct, DeviceAction, DeviceVendor, Activity, threatScore, threatLevel, feedNames\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "P1D",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl"
        ],
        "techniques": [
          "T1090"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}