Query Details

Entra Trace Sign In User Agent Matches

Query

let EntraTraceUserAgents = externaldata(Toolname:string,UserAgent:string)["https://raw.githubusercontent.com/Bert-JanP/EntraTrace/refs/heads/main/Indicator%20Lists/UserAgents.csv"] with (format="csv",ignoreFirstRecord=true);
let UniqueUserAgents = EntraTraceUserAgents
| distinct UserAgent;
union isfuzzy=true SigninLogs, AADNonInteractiveUserSignInLogs
| where UserAgent in~ (UniqueUserAgents)
| summarize TotalEvents = count(), TotalSuccessfulSignIns = countif(ResultType == "0"), TotalFailedSignIns = countif(ResultType != "0"), UniqueUsers = dcount(UserPrincipalName) by UserAgent
| join kind=leftouter EntraTraceUserAgents on UserAgent
| project-away *1

About this query

Explanation

This query is designed to identify potentially suspicious sign-in activities in Microsoft Entra ID (formerly Azure Active Directory) by matching the UserAgent strings from sign-in events against a list of known offensive tool profiles. Here's a simplified breakdown of what the query does:

  1. Data Source: It uses an external CSV file from the EntraTrace GitHub repository, which contains UserAgent strings associated with offensive tools. This file is dynamically retrieved each time the query runs, ensuring it uses the most up-to-date information.

  2. Unique UserAgents: The query extracts distinct UserAgent strings from this list to identify which ones are being used in sign-in attempts.

  3. Sign-In Event Analysis:

    • It checks sign-in events in Microsoft Entra ID to see if any of the UserAgent strings from the offensive tools list are present.
    • It counts the total number of sign-in events, successful sign-ins, failed sign-ins, and unique users associated with each UserAgent.
  4. Join and Filter: The query joins the sign-in data with the offensive tool profiles to provide context about which tool might be associated with the UserAgent.

  5. Output: The result shows the number of events, successful and failed sign-ins, and unique users for each UserAgent that matches the offensive tool list, helping security analysts identify and investigate potentially unauthorized or suspicious activities.

The query is useful for detecting activities like password spraying or unauthorized access attempts, but it requires further investigation to confirm whether the activity is malicious or part of a legitimate security assessment.