Detection rules › Kusto

Cisco Umbrella - Empty User Agent Detected

Severity
medium
Time window
15m
Source
github.com/Azure/Azure-Sentinel

'Rule helps to detect empty and unusual user agent indicating web browsing activity by an unusual process other than a web browser.'

MITRE ATT&CK coverage

TacticTechniques
Command & ControlNo specific technique

Rule body

id: 2b328487-162d-4034-b472-59f1d53684a1
name: Cisco Umbrella - Empty User Agent Detected
description: |
  'Rule helps to detect empty and unusual user agent indicating web browsing activity by an unusual process other than a web browser.'
severity: Medium
requiredDataConnectors:
  - connectorId: CiscoUmbrellaDataConnector
    dataTypes:
      - Cisco_Umbrella_proxy_CL
queryFrequency: 15m
queryPeriod: 15m
triggerOperator: gt
triggerThreshold: 0
tactics:
  - CommandAndControl
query: |
  let timeframe = 15m;
  Cisco_Umbrella
  | where EventType == "proxylogs"
  | where TimeGenerated > ago(timeframe)
  | where HttpUserAgentOriginal == ''
  | extend Message = "Empty User Agent"
  | project Message, SrcIpAddr, DstIpAddr, UrlOriginal, TimeGenerated
entityMappings:
  - entityType: URL
    fieldMappings:
      - identifier: Url
        columnName: UrlOriginal
  - entityType: IP
    fieldMappings:
      - identifier: Address
        columnName: SrcIpAddr
version: 1.1.2
kind: Scheduled

Stages and Predicates

Stage 0: let

let timeframe = 15m;

Stage 1: source

Cisco_Umbrella

Stage 2: where

| where EventType == "proxylogs"

Stage 3: where

| where TimeGenerated > ago(timeframe)

Stage 4: where

| where HttpUserAgentOriginal == ''

Stage 5: extend

| extend Message = "Empty User Agent"

Stage 6: project

| project Message, SrcIpAddr, DstIpAddr, UrlOriginal, TimeGenerated

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
DstIpAddrproject
Messageproject
SrcIpAddrproject
TimeGeneratedproject
UrlOriginalproject