Azure WireServer Unusual Process Connection


Description

Identifies shells, LOLBins, GTFOBins, and scripting runtimes connecting to the Azure WireServer / HostGAPlugin address 168.63.129.16 on ports 80 or 32526. The guest agent uses this fabric endpoint for GoalState, certificates, and vmSettings. Adversaries with code execution on an Azure VM (including via Run Command) use curl, PowerShell, openssl, bun, or similar tools to enumerate versions, pull transport certificates, and read HostGAPlugin /vmSettings. Azure guest-agent binaries and system python used by waagent are excluded. Descendants of the guest agent are not excluded: Run Command payloads execute in that tree.

Query · kuery

event.category: network and host.os.type: (linux or windows) and
 destination.ip: "168.63.129.16" and destination.port: (80 or 32526) and
 (
   process.name: (
     bash or dash or sh or tcsh or csh or zsh or ksh or fish or mksh or busybox or
     bun or bun.exe or node or node.exe or nodejs or deno or deno.exe or
     java or java.exe or javaw or javaw.exe or
     curl or curl.exe or wget or wget.exe or
     powershell.exe or pwsh.exe or pwsh or cmd.exe or
     certutil.exe or bitsadmin.exe or mshta.exe or rundll32.exe or
     wscript.exe or cscript.exe or regsvr32.exe or
     openssl or openssl.exe or nc or ncat or netcat or socat or
     python.exe or pythonw.exe or perl or perl.exe or ruby or ruby.exe or
     php or php.exe or lua or lua.exe
   ) or
   process.executable: (
     ./* or /tmp/* or /var/tmp/* or /dev/shm/* or /run/* or /var/run/* or
     /home/*/* or /root/* or *\:\\Users\\* or *\:\\ProgramData\\*
   )
 ) and
 not process.executable: (
   /usr/sbin/waagent or /usr/bin/waagent or /usr/bin/python3* or
   /usr/lib/systemd/systemd-resolved or /lib/systemd/systemd-resolved or
   *\:\\WindowsAzure\\Packages\\* or *\:\\WindowsAzure\\GuestAgent*\\* or
   *\:\\WindowsAzure\\SecAgent\\*
 )

Known false positives

  • Custom inventory or health scripts that call WireServer with curl or PowerShell. Validate the command line and exclude the specific signed binary or scheduled task after review.
  • Break-glass troubleshooting by administrators using curl against 168.63.129.16. Confirm the change window and exclude the admin host or user if the activity is authorized.

Analyst notes

Investigating Azure WireServer Unusual Process Connection

168.63.129.16 is the Azure host-only WireServer (TCP 80) and HostGAPlugin (TCP 32526) address. Elastic Defend network events record the destination IP, port, and initiating process. They do not include the HTTP path; pair this alert with Network Packet Capture HTTP events when available (comp=certificates, /vmSettings, /versions).

Do not treat "child of waagent / WindowsAzureGuestAgent" as benign. Azure Run Command and Custom Script Extension launch attacker scripts as descendants of those agents. Exclude only the agent binaries themselves, which this query already omits by matching curl, PowerShell, and similar tools.

process.Ext.ancestry is often empty on these network events, so EQL descendant of is not reliable here.

Possible investigation steps

  • Review process.name, process.executable, and process.command_line on nearby process start events. Look for comp=certificates, 32526, vmSettings, LinuxTransport, or openssl cms -decrypt.
  • Note destination.port: 32526 from curl or PowerShell is uncommon for legitimate guest-agent traffic (agents use WaAppAgent.exe, WindowsAzureGuestAgent.exe, CollectGuestLogs.exe, or /usr/bin/python3.10 / waagent).
  • Correlate with 169.254.169.254 IMDS access from the same process, especially /metadata/v1/instanceinfo (no Metadata header) or /metadata/identity/oauth2/token.
  • Check Azure Activity Logs for runCommand/action or extensions/write against this VM.
  • Search StorageRead platform logs for subsequent SAS GetBlob of vmsettings or cse objects.

False positive analysis

  • In-house monitoring that wraps curl to WireServer. Exclude by process.executable or a signed parent after validating the script contents.
  • Do not exclude all children of the guest agent; that hides Run Command abuse.

Response and remediation

  • Isolate the VM, rotate its managed identity and any SAS recovered from vmSettings, and review extension protectedSettings for injected configuration.
  • Remove unauthorized Run Command resources and Custom Script extensions.
  • Consider Azure Metadata Security Protocol (audit/enforce) to restrict which processes may call WireServer.
Raw source Azure WireServer Unusual Process Connection · Elastic TOML
Esc
Published by elastic/detection-rules ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[metadata]
creation_date = "2026/08/17"
integration = ["endpoint"]
maturity = "production"
updated_date = "2026/09/18"

[rule]
author = ["Elastic"]
description = """
Identifies shells, LOLBins, GTFOBins, and scripting runtimes connecting to the Azure WireServer / HostGAPlugin address
168.63.129.16 on ports 80 or 32526. The guest agent uses this fabric endpoint for GoalState, certificates, and
vmSettings. Adversaries with code execution on an Azure VM (including via Run Command) use curl, PowerShell, openssl,
bun, or similar tools to enumerate versions, pull transport certificates, and read HostGAPlugin /vmSettings. Azure
guest-agent binaries and system python used by waagent are excluded. Descendants of the guest agent are not excluded:
Run Command payloads execute in that tree.
"""
false_positives = [
    """
    Custom inventory or health scripts that call WireServer with curl or PowerShell. Validate the command line and
    exclude the specific signed binary or scheduled task after review.
    """,
    """
    Break-glass troubleshooting by administrators using curl against 168.63.129.16. Confirm the change window and
    exclude the admin host or user if the activity is authorized.
    """,
]
from = "now-9m"
index = ["logs-endpoint.events.network-*"]
language = "kuery"
license = "Elastic License v2"
name = "Azure WireServer Unusual Process Connection"
note = """## Triage and analysis

### Investigating Azure WireServer Unusual Process Connection

`168.63.129.16` is the Azure host-only WireServer (TCP 80) and HostGAPlugin (TCP 32526) address. Elastic Defend
network events record the destination IP, port, and initiating process. They do not include the HTTP path; pair this
alert with Network Packet Capture HTTP events when available (`comp=certificates`, `/vmSettings`, `/versions`).

Do not treat "child of waagent / WindowsAzureGuestAgent" as benign. Azure Run Command and Custom Script Extension
launch attacker scripts as descendants of those agents. Exclude only the agent binaries themselves, which this query
already omits by matching curl, PowerShell, and similar tools.

`process.Ext.ancestry` is often empty on these network events, so EQL `descendant of` is not reliable here.

### Possible investigation steps

- Review `process.name`, `process.executable`, and `process.command_line` on nearby process start events. Look for
  `comp=certificates`, `32526`, `vmSettings`, `LinuxTransport`, or `openssl cms -decrypt`.
- Note `destination.port`: 32526 from curl or PowerShell is uncommon for legitimate guest-agent traffic (agents use
  `WaAppAgent.exe`, `WindowsAzureGuestAgent.exe`, `CollectGuestLogs.exe`, or `/usr/bin/python3.10` / waagent).
- Correlate with `169.254.169.254` IMDS access from the same process, especially `/metadata/v1/instanceinfo` (no
  Metadata header) or `/metadata/identity/oauth2/token`.
- Check Azure Activity Logs for `runCommand/action` or extensions/write against this VM.
- Search StorageRead platform logs for subsequent SAS GetBlob of vmsettings or cse objects.

### False positive analysis

- In-house monitoring that wraps curl to WireServer. Exclude by `process.executable` or a signed parent after
  validating the script contents.
- Do not exclude all children of the guest agent; that hides Run Command abuse.

### Response and remediation

- Isolate the VM, rotate its managed identity and any SAS recovered from vmSettings, and review extension
  protectedSettings for injected configuration.
- Remove unauthorized Run Command resources and Custom Script extensions.
- Consider Azure Metadata Security Protocol (audit/enforce) to restrict which processes may call WireServer.
"""
references = [
    "https://www.netspi.com/blog/technical-blog/cloud-pentesting/decrypting-vm-extension-settings-with-azure-wireserver/",
    "https://cybercx.com.au/blog/azure-ssrf-metadata/",
    "https://cloud.google.com/blog/topics/threat-intelligence/escalating-privileges-azure-kubernetes-services",
    "https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16",
]
risk_score = 47
rule_id = "2dba3edf-1e23-4ead-a76f-458ef2060d24"
severity = "medium"
tags = [
    "Domain: Endpoint",
    "Domain: Cloud",
    "OS: Linux",
    "OS: Windows",
    "Platform: Azure",
    "Platform: Windows",
    "Use Case: Threat Detection",
    "Tactic: Credential Access",
    "Tactic: Discovery",
    "Data Source: Elastic Defend",
    "Resources: Investigation Guide",
    "Rule Type: New Terms",
    "Platform: Linux",
]
timestamp_override = "event.ingested"
type = "new_terms"

query = '''
event.category: network and host.os.type: (linux or windows) and
 destination.ip: "168.63.129.16" and destination.port: (80 or 32526) and
 (
   process.name: (
     bash or dash or sh or tcsh or csh or zsh or ksh or fish or mksh or busybox or
     bun or bun.exe or node or node.exe or nodejs or deno or deno.exe or
     java or java.exe or javaw or javaw.exe or
     curl or curl.exe or wget or wget.exe or
     powershell.exe or pwsh.exe or pwsh or cmd.exe or
     certutil.exe or bitsadmin.exe or mshta.exe or rundll32.exe or
     wscript.exe or cscript.exe or regsvr32.exe or
     openssl or openssl.exe or nc or ncat or netcat or socat or
     python.exe or pythonw.exe or perl or perl.exe or ruby or ruby.exe or
     php or php.exe or lua or lua.exe
   ) or
   process.executable: (
     ./* or /tmp/* or /var/tmp/* or /dev/shm/* or /run/* or /var/run/* or
     /home/*/* or /root/* or *\:\\Users\\* or *\:\\ProgramData\\*
   )
 ) and
 not process.executable: (
   /usr/sbin/waagent or /usr/bin/waagent or /usr/bin/python3* or
   /usr/lib/systemd/systemd-resolved or /lib/systemd/systemd-resolved or
   *\:\\WindowsAzure\\Packages\\* or *\:\\WindowsAzure\\GuestAgent*\\* or
   *\:\\WindowsAzure\\SecAgent\\*
 )
'''


[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1552"
name = "Unsecured Credentials"
reference = "https://attack.mitre.org/techniques/T1552/"
[[rule.threat.technique.subtechnique]]
id = "T1552.005"
name = "Cloud Instance Metadata API"
reference = "https://attack.mitre.org/techniques/T1552/005/"



[rule.threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"
[[rule.threat]]
framework = "MITRE ATT&CK"
[[rule.threat.technique]]
id = "T1082"
name = "System Information Discovery"
reference = "https://attack.mitre.org/techniques/T1082/"

[[rule.threat.technique]]
id = "T1580"
name = "Cloud Infrastructure Discovery"
reference = "https://attack.mitre.org/techniques/T1580/"


[rule.threat.tactic]
id = "TA0007"
name = "Discovery"
reference = "https://attack.mitre.org/tactics/TA0007/"

[rule.new_terms]
field = "new_terms_fields"
value = ["host.id", "process.executable"]
[[rule.new_terms.history_window_start]]
field = "history_window_start"
value = "now-7d"


Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.