Forum Discussion

GaryBushey's avatar
GaryBushey
Bronze Contributor
Apr 15, 2021
Solved

Where does the MaliciousIP field come from in this query?

This is the query for the Potential Malicious Events map on the Azure Sentinel homepage.   union isfuzzy=true (W3CIISLog | extend TrafficDirection = "InboundOrUnknown", Country=RemoteIPCountry, L...
  • JBUB_Accelerynt's avatar
    Apr 16, 2021
    We have looked into this somewhat as well. If you pull up the log table for something like CommonSecurityLog/Zscaler/WindowsFireWall) you will see that MaliciousIP (and Mal Lat/Long/Country) are already in those tables. You will need to make sure those boxes are checked in the Columns Drop down in the results. When you do see them almost all of them are empty. It seems that those boxes DO get filled in as the logs come in and match a corresponding Malicious entity that exists in the tables of ThreatIntelligenceIndicators or are a part of the Threat Intel Data Connector, or even part of the "under the hood" threat intel that MSFT provides. I think there is a bit of "under the hood" stuff going on as logs come in, which makes this different than say a lookback on DNS requests compared to Domains in the TIindicators.

    I have not checked if the MalciousIP table columns exist before Threat Intel is turned on - but might fun to check when spinning up your next instance.

Resources