Potential beaconing detected (ASIM Web Session)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies beaconing patterns from web traffic logs based on recurrent timedelta patterns. Reference Blog: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586

Attribute Value
Type Hunting Query
Solution Web Session Essentials
ID 6338ca43-ae7c-4a91-9fe4-0f1ad4edf4a5
Tactics CommandAndControl
Techniques T1071, T1571
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Web Session Essentials