Entra Trace Microsoft Graph User Agent Matches
Query
let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
MicrosoftGraphActivityLogs
| where UserAgent in~ (UniqueUserAgents)
| extend ObjectId = coalesce(ServicePrincipalId, UserId)
| summarize TotalEvents = count(), UniqueObject = dcount(ObjectId), UniqueUsers = dcount(UserId), UniqueServicePrincipals = dcount(ServicePrincipalId) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1About this query
Explanation
This query is designed to identify potentially suspicious activities involving Microsoft Graph API requests by examining the UserAgent strings. Here's a simplified breakdown:
-
Purpose: The query aims to detect Microsoft Graph API requests that might be using
UserAgentstrings associated with known offensive tools. These tools could be used for unauthorized access or reconnaissance in cloud environments. -
Data Source: It uses a list of
UserAgentstrings from a CSV file hosted on GitHub, which is part of the EntraTrace project. This list is dynamically retrieved each time the query runs, ensuring it uses the most up-to-date information. -
Process:
- The query first loads the
UserAgentstrings from the CSV file. - It then filters the Microsoft Graph activity logs to find entries where the
UserAgentmatches any from the list. - For these matches, it calculates the total number of events and counts unique objects, users, and service principals associated with each
UserAgent.
- The query first loads the
-
Output: The query provides a summary of the potentially suspicious activities, including the number of events and unique identifiers involved, which can help in further investigation.
-
Risk and Action: While the query highlights possible use of offensive tools, it doesn't confirm malicious intent. Analysts should review the details of the requests, such as identities, IP addresses, and permissions, to determine if the activity is legitimate or requires further action.