Skip to content

Commit 0443917

Browse files
Create Malicious-Bots-Detection-Query for Azure WAF.json
1 parent c672e51 commit 0443917

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
AzureDiagnostics
2+
| where Category in ("ApplicationGatewayFirewallLog", "FrontDoorWebApplicationFirewallLog")
3+
| where details_data_s matches regex "(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)"
4+
or Message matches regex "(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)"
5+
or details_message_s matches regex "(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)"
6+
or details_msg_s matches regex "(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)"
7+
or details_data_s matches regex "(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)"
8+
| extend CombinedDetails = strcat(details_data_s, " ", Message, " ", details_message_s, " ", details_msg_s)
9+
| summarize Count = count(), Details = make_list(CombinedDetails) by Threat = extract("(?i)(Emotet|Zeus|TrickBot|Satori|Gootkit|Qbot|Ramnit|Necurs|Andromeda|DarkComet|Hajime|Reaper|VPNFilter|Carbanak|Dridex|Kovter|ZLoader|Agent Tesla|FormBook|spider|robot|emotet|zeus|trickBot|satori|gootkit|qbot|ramnit|necurs|andromeda|darkComet|hajime|reaper|vpnfilter|carbanak|dridex|kovter|zloader|agent tesla|formbook|spider|robot)", 1, CombinedDetails)
10+
| project Threat, Count, Details
11+
| order by Count desc

0 commit comments

Comments
 (0)