Potentially Suspicious Azure Front Door Connection
Description
Detects connections with Azure Front Door (known legitimate service that can be leveraged for C2) that fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)
Query · sigma
selection: DestinationHostname|contains: azurefd.net filter_main_web_browsers: Image|endswith: - brave.exe - chrome.exe - chromium.exe - firefox.exe - msedge.exe - msedgewebview2.exe - opera.exe - vivaldi.exe filter_main_common_talkers: Image|endswith: searchapp.exe filter_main_known_benign_domains: DestinationHostname|contains: - afdxtest.z01.azurefd.net - fp-afd.azurefd.net - fp-afdx-bpdee4gtg6frejfd.z01.azurefd.net - roxy.azurefd.net - powershellinfraartifacts-gkhedzdeaghdezhr.z01.azurefd.net - storage-explorer-publishing-feapcgfgbzc2cjek.b01.azurefd.net - graph.azurefd.net condition: selection and not 1 of filter_main_*
Known false positives
- Results are not inherently suspicious, but should be investigated during threat hunting for potential cloud C2.
- Organization-specific Azure Front Door endpoints