Zscaler

Telemetry Evidence

These values show how indexed rules identify Zscaler telemetry.

Kusto

  • Queried source table CommonSecurityLog (3 rules)
  • Queried source table ZPAEvent (10 rules)
  • Query discriminator DeviceVendor = Zscaler (2 rules)
  • Query discriminator DeviceVendor = ZScaler (1 rule)
  • Source collection Zscaler Internet Access (2 rules)

Panther

  • Log type Zscaler.ZIA.AdminAuditLog (10 rules)
  • Platform zscaler (10 rules)

YARA-L

  • Data source zscalar (3 rules)
  • Data source zscalar, crowdstrike (1 rule)
  • Data source zscalar, microsoft sysmon (2 rules)
  • Data source zscaler nss, crowdstrike (1 rule)

Detection Rules

Kusto #

Panther #

YARA-L #

Product-Filtered Rules

These rules use generic transport telemetry with a product-specific filter for Zscaler.

Kusto #

  • Beacon Traffic Based on Common User Agents Visiting Limited Number of Domains source medium: This query searches web proxy logs for a specific type of beaconing behavior by joining a number of sources together: - Traffic by actual web browsers - by looking at traffic generated by a UserAgent that looks like a browser and is used by multiple users to visit a large number of domains. - Users that make requests using one of these actual browsers, but only to a small set of domains, none of which are common domains. - The traffic is beacon-like; meaning that it occurs during many different hours of the day (i.e. periodic).T1071, T1071.001
  • Discord CDN Risky File Download source medium: 'Identifies callouts to Discord CDN addresses for risky file extensions. This detection will trigger when a callout for a risky file is made to a discord server that has only been seen once in your environment. Unique discord servers are identified using the server ID that is included in the request URL (DiscordServerId in query). Discord CDN has been used in multiple campaigns to download additional payloads'T1071, T1071.001
  • Request for single resource on domain source low: 'This will look for connections to a domain where only a single file is requested, this is unusual as most modern web applications require additional recources. This type of activity is often assocaited with malware beaconing or tracking URL's delivered in emails. Developed for Zscaler but applicable to any outbound web logging.'T1071, T1102

Compatible Rules

These rules declare Zscaler connector or schema compatibility without a product-specific query filter.

Kusto #