Query Details

Entra Trace Microsoft Graph User Agent Matches

Query

let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
MicrosoftGraphActivityLogs
| where UserAgent in~ (UniqueUserAgents)
| extend ObjectId = coalesce(ServicePrincipalId, UserId)
| summarize TotalEvents = count(), UniqueObject = dcount(ObjectId), UniqueUsers = dcount(UserId), UniqueServicePrincipals = dcount(ServicePrincipalId) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1

About this query

Explanation

This query is designed to identify potentially suspicious activities involving Microsoft Graph API requests by examining the UserAgent strings. Here's a simplified breakdown:

  1. Purpose: The query aims to detect Microsoft Graph API requests that might be using UserAgent strings associated with known offensive tools. These tools could be used for unauthorized access or reconnaissance in cloud environments.

  2. Data Source: It uses a list of UserAgent strings from a CSV file hosted on GitHub, which is part of the EntraTrace project. This list is dynamically retrieved each time the query runs, ensuring it uses the most up-to-date information.

  3. Process:

    • The query first loads the UserAgent strings from the CSV file.
    • It then filters the Microsoft Graph activity logs to find entries where the UserAgent matches any from the list.
    • For these matches, it calculates the total number of events and counts unique objects, users, and service principals associated with each UserAgent.
  4. Output: The query provides a summary of the potentially suspicious activities, including the number of events and unique identifiers involved, which can help in further investigation.

  5. Risk and Action: While the query highlights possible use of offensive tools, it doesn't confirm malicious intent. Analysts should review the details of the requests, such as identities, IP addresses, and permissions, to determine if the activity is legitimate or requires further action.