Entra Trace Azure AD Graph User Agent Matches
Query
let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
AADGraphActivityLogs
| where UserAgent in~ (UniqueUserAgents)
| extend ObjectId = coalesce(ServicePrincipalId, UserId)
| summarize TotalEvents = count(), UniqueObject = dcount(ObjectId), UniqueUsers = dcount(UserId), UniqueServicePrincipals = dcount(ServicePrincipalId) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1About this query
Explanation
This query is designed to identify potentially suspicious activity in Azure Active Directory (Azure AD) by examining the UserAgent strings of requests made to the legacy Azure AD Graph API. Here's a simplified breakdown of what the query does:
-
Data Source: It pulls a list of known
UserAgentstrings associated with offensive tools from an external CSV file hosted on GitHub. This list is dynamically updated, so the query always uses the latest data. -
Purpose: The goal is to detect if any of these known
UserAgentstrings appear in the Azure AD Graph activity logs. These strings are indicative of tools that might be used for unauthorized discovery of accounts, groups, and permissions in the cloud environment. -
Process:
- It first retrieves and filters unique
UserAgentstrings from the external list. - It then checks the Azure AD Graph activity logs to see if any of these
UserAgentstrings are present. - For each matching
UserAgent, it counts the total number of events and the number of unique users and service principals involved.
- It first retrieves and filters unique
-
Output: The query provides a summary of the findings, showing the
UserAgentstrings that matched, along with counts of related events and unique identifiers. -
Risk and Investigation: A match suggests potential use of offensive tools but is not definitive proof of malicious activity. It serves as a lead for further investigation, where you should examine the details of the requests, such as the identities involved, IP addresses, and request details, to determine if the activity is legitimate or part of an authorized security assessment.