Base64 encoded IPv4 address in request url

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query detects Base64-encoded IPv4 addresses in outbound request URLs. It uses pre-computed base64 offsets for IPv4 sequences, eliminating the need for decoding. After identifying a candidate,the query extracts the plaintext IPv4 address pattern.

Attribute Value
Type Hunting Query
Solution Network Threat Protection Essentials
ID 39156a1d-c9e3-439e-967b-be7dcba918d9
Tactics CommandAndControl
Techniques T1071.001
Required Connectors Zscaler, Fortinet, CheckPoint, PaloAltoNetworks
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Network Threat Protection Essentials