Query Details

Entra Trace Azure AD Graph User Agent Matches

Query

let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
AADGraphActivityLogs
| where UserAgent in~ (UniqueUserAgents)
| extend ObjectId = coalesce(ServicePrincipalId, UserId)
| summarize TotalEvents = count(), UniqueObject = dcount(ObjectId), UniqueUsers = dcount(UserId), UniqueServicePrincipals = dcount(ServicePrincipalId) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1

About this query

Explanation

This query is designed to identify potentially suspicious activity in Azure Active Directory (Azure AD) by examining the UserAgent strings of requests made to the legacy Azure AD Graph API. Here's a simplified breakdown of what the query does:

  1. Data Source: It pulls a list of known UserAgent strings associated with offensive tools from an external CSV file hosted on GitHub. This list is dynamically updated, so the query always uses the latest data.

  2. Purpose: The goal is to detect if any of these known UserAgent strings appear in the Azure AD Graph activity logs. These strings are indicative of tools that might be used for unauthorized discovery of accounts, groups, and permissions in the cloud environment.

  3. Process:

    • It first retrieves and filters unique UserAgent strings from the external list.
    • It then checks the Azure AD Graph activity logs to see if any of these UserAgent strings are present.
    • For each matching UserAgent, it counts the total number of events and the number of unique users and service principals involved.
  4. Output: The query provides a summary of the findings, showing the UserAgent strings that matched, along with counts of related events and unique identifiers.

  5. Risk and Investigation: A match suggests potential use of offensive tools but is not definitive proof of malicious activity. It serves as a lead for further investigation, where you should examine the details of the requests, such as the identities involved, IP addresses, and request details, to determine if the activity is legitimate or part of an authorized security assessment.