Entra Trace Sign In User Agent Matches
Query
let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
union isfuzzy=true SigninLogs, AADNonInteractiveUserSignInLogs
| where UserAgent in~ (UniqueUserAgents)
| summarize TotalEvents = count(), TotalSuccessfulSignIns = countif(ResultType == "0"), TotalFailedSignIns = countif(ResultType != "0"), UniqueUsers = dcount(UserPrincipalName) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1About this query
Explanation
This query is designed to identify potentially suspicious sign-in activities in Microsoft Entra ID (formerly Azure Active Directory) by matching the UserAgent strings from sign-in events against a list of known offensive tool profiles. Here's a simplified breakdown of what the query does:
-
Data Source: It uses an external CSV file from the EntraTrace GitHub repository, which contains
UserAgentstrings associated with offensive tools. This file is dynamically retrieved each time the query runs, ensuring it uses the most up-to-date information. -
Unique UserAgents: The query extracts distinct
UserAgentstrings from this list to identify which ones are being used in sign-in attempts. -
Sign-In Event Analysis:
- It checks sign-in events in Microsoft Entra ID to see if any of the
UserAgentstrings from the offensive tools list are present. - It counts the total number of sign-in events, successful sign-ins, failed sign-ins, and unique users associated with each
UserAgent.
- It checks sign-in events in Microsoft Entra ID to see if any of the
-
Join and Filter: The query joins the sign-in data with the offensive tool profiles to provide context about which tool might be associated with the
UserAgent. -
Output: The result shows the number of events, successful and failed sign-ins, and unique users for each
UserAgentthat matches the offensive tool list, helping security analysts identify and investigate potentially unauthorized or suspicious activities.
The query is useful for detecting activities like password spraying or unauthorized access attempts, but it requires further investigation to confirm whether the activity is malicious or part of a legitimate security assessment.