⚠️ Tailscale (CCF)
⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Solutions Index
| Attribute |
Value |
| Publisher |
Tailscale (CCF) |
| Support Tier |
Community |
| Support Link |
https://github.com/Azure/Azure-Sentinel/issues |
| Categories |
Networking,Security - Network,Identity |
| Version |
3.0.0 |
| Author |
noodlemctwoodle - ccfconnectors.county118@passmail.com |
| First Published |
2026-05-19 |
| Last Updated |
2026-05-19 |
| Solution Folder |
Tailscale (CCF) |
The Tailscale solution for Microsoft Sentinel ingests Tailscale identity, device, configuration, audit and (Premium) network-flow telemetry via OAuth2-secured APIs. Built on the Codeless Connector Framework (CCF) - no Function App or container required.
Data connectors in this solution (install the one matching your Tailscale plan):
- Tailscale Standard (CCF) - Configuration audit, devices, users, keys, webhooks, DNS, settings. Use on Personal (Free), Starter and Premium tailnets.
- Tailscale Premium (CCF) - Everything in Standard plus network flow logs and posture integrations. Use on Premium and Enterprise tailnets for full coverage.
Pre-requisites:
- Sign in to Tailscale OAuth settings
- Create an OAuth client with the scopes for your tier (see the README in this solution).
- Copy the client ID and client secret (secret shown once).
- Note your tailnet name (e.g.
tailb094d7.ts.net) from the Keys page.
Contents
Data Connectors
This solution provides 2 data connector(s):
Tables Used
This solution uses 9 table(s):
| Table |
Used By Connectors |
Used By Content |
Tailscale_Audit_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Analytics, Hunting, Workbooks |
Tailscale_Devices_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Analytics, Hunting, Workbooks |
Tailscale_Dns_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Workbooks |
Tailscale_Keys_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Hunting, Workbooks |
Tailscale_Network_CL |
Tailscale Premium (CCF) |
Analytics, Hunting, Workbooks |
Tailscale_PostureIntegrations_CL |
Tailscale Premium (CCF) |
Hunting, Workbooks |
Tailscale_Settings_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Workbooks |
Tailscale_Users_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
Analytics, Hunting, Workbooks |
Tailscale_Webhooks_CL |
Tailscale Premium (CCF), Tailscale Standard (CCF) |
- |
Content Items
This solution includes 50 content item(s):
| Content Type |
Count |
| Analytic Rules |
24 |
| Hunting Queries |
22 |
| Workbooks |
2 |
| Parsers |
2 |
Analytic Rules
| Name |
Severity |
Tactics |
Tables Used |
| Tailscale Premium: DERP relay traffic surge |
Low |
CommandAndControl |
Tailscale_Network_CL |
| Tailscale Premium: Large outbound transfer over tailnet |
Medium |
Exfiltration, Collection |
Tailscale_Network_CL |
| Tailscale Premium: Mass fan-out from single node |
High |
Discovery, LateralMovement |
Tailscale_Network_CL |
| Tailscale Premium: Network flow beaconing detected |
Medium |
CommandAndControl, Exfiltration |
Tailscale_Network_CL |
| Tailscale Premium: New posture integration added |
Medium |
Persistence |
Tailscale_Audit_CL |
| Tailscale Premium: Posture integration disabled or removed |
High |
DefenseEvasion, Persistence |
Tailscale_Audit_CL |
| Tailscale Premium: Subnet router throughput anomaly |
Low |
Exfiltration, CommandAndControl |
Tailscale_Network_CL |
| Tailscale Premium: Unexpected exit-node egress |
Medium |
CommandAndControl, Exfiltration |
Tailscale_Network_CL |
| Tailscale: Auth key created |
Low |
Persistence |
Tailscale_Audit_CL |
| Tailscale: DNS nameservers modified |
High |
DefenseEvasion, CommandAndControl |
Tailscale_Audit_CL |
| Tailscale: Device Tailscale SSH newly enabled |
Medium |
Persistence, LateralMovement |
Tailscale_Devices_CL |
| Tailscale: Device key expiring within 7 days |
Medium |
InitialAccess |
Tailscale_Devices_CL |
| Tailscale: Device started advertising subnet routes |
Medium |
LateralMovement, Persistence |
Tailscale_Devices_CL |
| Tailscale: Exit node advertised or approved |
Low |
CommandAndControl, Exfiltration |
Tailscale_Audit_CL |
| Tailscale: External (shared-in) device added |
Medium |
InitialAccess |
Tailscale_Devices_CL |
| Tailscale: MagicDNS disabled |
Medium |
DefenseEvasion |
Tailscale_Audit_CL |
| Tailscale: Mass credential revocation in short window |
High |
DefenseEvasion, Impact |
Tailscale_Audit_CL |
| Tailscale: New API access token or OAuth client created |
Medium |
Persistence, CredentialAccess |
Tailscale_Audit_CL |
| Tailscale: OAuth client or API key created with write scopes |
High |
Persistence, PrivilegeEscalation |
Tailscale_Audit_CL |
| Tailscale: Policy file (ACL) modified |
Medium |
DefenseEvasion, Persistence |
Tailscale_Audit_CL |
| Tailscale: Split-DNS configuration modified |
High |
DefenseEvasion, CommandAndControl |
Tailscale_Audit_CL |
| Tailscale: Tailnet lock validation failed |
High |
DefenseEvasion, InitialAccess |
Tailscale_Devices_CL |
| Tailscale: Unauthorized device connected to control plane |
High |
InitialAccess, Persistence |
Tailscale_Devices_CL |
| Tailscale: User role elevated to admin or owner |
High |
PrivilegeEscalation, Persistence |
Tailscale_Users_CL |
Hunting Queries
| Name |
Tactics |
Tables Used |
| Tailscale Premium: Beaconing candidates (regular periodic flows) |
CommandAndControl, Exfiltration |
Tailscale_Network_CL |
| Tailscale Premium: Cross-tag flow matrix |
LateralMovement, Discovery |
Tailscale_Network_CL |
| Tailscale Premium: Current posture integration inventory |
DefenseEvasion |
Tailscale_PostureIntegrations_CL |
| Tailscale Premium: Devices with persistent DERP relay usage |
CommandAndControl |
Tailscale_Network_CL |
| Tailscale Premium: Exit-node usage patterns |
CommandAndControl, Exfiltration |
Tailscale_Network_CL |
| Tailscale Premium: Network flows outside business hours |
Exfiltration, CommandAndControl |
Tailscale_Network_CL |
| Tailscale Premium: New src->dst node pairs (lateral movement candidates) |
LateralMovement, Discovery |
Tailscale_Network_CL |
| Tailscale Premium: Tagged services with broad inbound exposure |
LateralMovement, InitialAccess |
Tailscale_Network_CL |
| Tailscale Premium: Top talkers by bytes (virtual traffic) |
Exfiltration, Collection |
Tailscale_Network_CL |
| Tailscale Premium: Users generating traffic from multiple devices |
InitialAccess, Persistence |
Tailscale_Devices_CL
Tailscale_Network_CL |
| Tailscale: ACL policy churn |
DefenseEvasion, PrivilegeEscalation |
Tailscale_Audit_CL |
| Tailscale: Auth key sprawl |
Persistence, CredentialAccess |
Tailscale_Audit_CL |
| Tailscale: Auth keys with no expiry |
Persistence, CredentialAccess |
Tailscale_Keys_CL |
| Tailscale: Devices not seen in 30+ days |
Discovery |
Tailscale_Devices_CL |
| Tailscale: Devices with Tailscale SSH enabled |
LateralMovement, Persistence |
Tailscale_Devices_CL |
| Tailscale: Devices with outdated client version |
DefenseEvasion |
Tailscale_Devices_CL |
| Tailscale: External (shared-in) device inventory |
InitialAccess |
Tailscale_Devices_CL |
| Tailscale: First-seen actor making configuration changes |
InitialAccess, Persistence |
Tailscale_Audit_CL |
| Tailscale: Off-hours configuration changes |
InitialAccess, Persistence |
Tailscale_Audit_CL |
| Tailscale: Split-DNS per-domain change history |
DefenseEvasion, CommandAndControl |
Tailscale_Audit_CL |
| Tailscale: Subnet router CIDR exposure inventory |
LateralMovement |
Tailscale_Devices_CL |
| Tailscale: Users with zero devices |
InitialAccess |
Tailscale_Users_CL |
Workbooks
Parsers
Additional Documentation
📄 Source: Tailscale (CCF)/README.md
Microsoft Sentinel solution that ingests Tailscale identity, device, configuration, audit and (Premium) network-flow telemetry via the OAuth2-secured Tailscale API. Built on the Codeless Connector Framework (CCF) - no Function App or container required.
- 2 data connectors (Standard, Premium) - install whichever matches your Tailscale plan
- 24 analytic rules (16 Standard + 8 Premium-only)
- 22 hunting queries (12 Standard + 10 Premium-only)
- 2 workbooks (Standard Operations, Premium Operations)
- 2 ASIM NetworkSession parsers (
vimNetworkSessionTailscale + ASimNetworkSessionTailscale wrapper) - Premium only
- 9 custom tables ingested via 9-11 polling rules behind a single Connect button
Table of contents
- Pick your tier
- Pre-requisites
- Installation
- Verification
- Custom tables
- Analytic rules
- Hunting queries
- Workbooks
- Architecture notes
- Limitations
- Troubleshooting
- Support
- Acknowledgements
1. Pick your tier
Install one of the two connectors based on your Tailscale plan. The split mirrors what the Tailscale API actually exposes per tier - network flow logs are only available on Premium and Enterprise tailnets.
|
Tailscale Standard (CCF) |
Tailscale Premium (CCF) |
| Tailscale plan |
Personal (Free), Starter, Premium* |
Premium, Enterprise |
| Pollers behind one Connect |
9 |
11 |
| Custom tables created |
7 |
9 |
| Analytic rules wired |
16 |
24 (Standard 16 + Premium 8) |
| Hunting queries wired |
12 |
22 (Standard 12 + Premium 10) |
| Workbook |
Standard Operations |
Premium Operations |
| Network flow logs |
not exposed by API |
Tailscale_Network_CL |
| Posture integrations |
not exposed by API |
Tailscale_PostureIntegrations_CL |
| Required OAuth scopes |
logs:configuration:read, devices:read, users:read, keys:read, webhooks:read, dns:read, settings:read |
All of Standard plus logs:network:read, posture-integrations:read |
* Premium tailnets can use the Standard connector if you don't want network-flow data, but the Premium connector is the recommended path.
2. Pre-requisites
You need four things before clicking Connect:
- A Microsoft Sentinel-enabled Log Analytics workspace in any region.
- A Data Collection Endpoint (DCE) in the same region as the workspace. The Sentinel Content Hub installer creates one automatically if you don't already have a shared DCE.
- A Tailscale OAuth client generated at https://login.tailscale.com/admin/settings/oauth. Personal API tokens (
tskey-api-...) do not work - see Architecture notes for the reason.
[Content truncated...]
Release Notes
| Version |
Date Modified (DD-MM-YYYY) |
Change History |
| 3.0.0 |
19-05-2026 |
Initial Solution Release |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Solutions Index