Suspicious Outbound HTTP UserAgent¶
This detection monitors the CommonSecurityLog (which adheres to the Common Event Format - CEF) for indications of malicious network activity. It flags outgoing HTTP requests originating from system utilities such as curl, wget, and PowerShell. These requests are often leveraged by attackers for data theft (exfiltration) or establishing command-and-control channels. Analysts should review the full user agent string and destination hostname, investigate the source IP and user context, and determine if the tool usage aligns with expected behavior. Correlate with other indicators such as unusual process execution, file access, or authentication anomalies. Escalate if the destination is unknown or suspicious.
Detection details
| Tactic | Technique | Author | Date |
|---|---|---|---|
| Exfiltration, Command and Control | T1041 (Exfiltration Over C2 Channel), T1071 (Application Layer Protocol) | Rory Wagner (Sleuthifer) | 2025-10-15 |
References
Notes
- UA_Check and SafeHosts require tuning for your specific environment setup and traffic. Remove the
summarizeline for more detailed event-level context.
Query¶
let UA_Check = dynamic([
'microsoft bits',
'certutil',
'powershell',
'python-requests',
'curl',
'wget',
'mshta',
'rclone'
]);
let SafeHosts = dynamic([
'aka.ms'
]);
CommonSecurityLog
| where isnotempty(AdditionalExtensions)
| extend kv_pairs = extract_all(@"(\w+)=(""[^""]*""|[^;]+)", AdditionalExtensions)
| extend
Agent = tostring(
extract(@"agent=(""[^""]*""|[^;]+)", 1, AdditionalExtensions)
),
HttpMethod = tostring(
extract(@"httpmethod=(""[^""]*""|[^;]+)", 1, AdditionalExtensions)
),
Start = tostring(
extract(@"start=(""[^""]*""|[^;]+)", 1, AdditionalExtensions)
),
Direction = tostring(
extract(@"direction=(""[^""]*""|[^;]+)", 1, AdditionalExtensions)
)
| where isnotempty(Agent)
| where Agent has_any (UA_Check)
| where Direction == 'outgoing'
| where DestinationHostName !in (SafeHosts)
| project-reorder TimeGenerated, Agent, Direction, HttpMethod, DestinationHostName
| summarize count() by DestinationHostName, Agent
| extend DetectionType = "Outgoing HTTP Requests from System Utilities"