Where can I check to see the reason behind Azure Network Watcher Traffic Analytics label of MaliciousFlow?

Gregory Smith 41 Reputation points
2023-05-25T04:32:24.3633333+00:00

I have a flow labeled as MaliciousFlow, and I would like to find out more why it was labeled as such. I don't see how the traffic is particularly malicious other than it was probably on a blacklist at a point in time. But if I am going to tell my boss about it, then I will need some more information to try and block the traffic. Where do I find more information?

I see that in the schema it is defined as: "MaliciousFlow: One of the IP addresses belong to an Azure virtual network, while the other IP address is a public IP that isn't in Azure and is reported as malicious in the ASC feeds that traffic analytics consumes for the processing interval between “FlowIntervalStartTime_t” and “FlowIntervalEndTime_t”."

Is there someplace for me to look at this info? I can't find it.

I have checked the table "AzureNetworkAnalyticsIPDetails_CL" for more information, but it doesn't tell me more than the flow log.

Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
158 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,246 Reputation points Microsoft Employee
    2023-05-25T06:51:09.94+00:00

    @Gregory Smith

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you are using Traffic Analytics and an IP logged is flagged as malicious and you would like to know how and why Microsoft considers this as malicious.

    • Traffic analytics relies on Microsoft internal threat intelligence systems to deem an IP as malicious.
    • These systems leverage diverse telemetry sources like Microsoft products and services, the Microsoft Digital Crimes Unit (DCU), the Microsoft Security Response Center (MSRC), and external feeds and build a lot of intelligence on top of it.
    • Some of this data is Microsoft Internal.
    • Hence, you will not be able to manually check the IPs considered as malicious by Microsoft publicly.

    Now, if you or your organization own this IP and you believe IP is getting flagged malicious incorrectly by Microsoft, you should raise a support ticket to know the details on why and next steps on how to mitigate it.

    Please refer : How does traffic analytics decide that an IP is malicious?

    If you have a support plan please go ahead and file a support ticket.

    If not, do let us know and I shall try and help you get a one-time free technical support.

    I hope I was able to make things clear. I would highly appreciate if you could Accept the answer and Up-Vote for the same, which might be beneficial to other community members reading this thread.

    Should you have any further query do let me know, I would be more than happy to address them as always :)

    Cheers,

    Kapil


0 additional answers

Sort by: Most helpful