Azure Firewall IDPS investigation

Yang, Steven 151 Reputation points
2023-08-23T22:35:05.5966667+00:00

Is there recommendations from Microsoft on how to go about investigating alerts from Azure firewall IDPS signatures?

For example, is there more information about signatureid=2007880? how it would be a Trojan attack? and how do i go about validating it.

Signatureid: 2007880

Description: USER_AGENTS User-Agent (single dash)

Group:A Network Trojan was detected

Best,

Steven

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
741 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 49,281 Reputation points Microsoft Employee
    2023-08-28T07:07:11.1166667+00:00

    @Yang, Steven

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to know more information about the IDPS Signature that was triggered.

    The only information available with respect to a Rule signature is it's "Description" and "Group".

    To investigate further on it, you must make use of the

    • Source IP
    • Destination IP &
    • Destination Port

    You should then check which source is the malicious actor and what destination VM and port is the malicious actor targeting.

    If this is some application, you must verify it's behavior from the OS level.

    This can be done by collecting a packet capture and see what application/service is initiating this malicious traffic.

    Should you feel this is a legitimate traffic, then you can use the Bypass List feature of IDPS to allow only this traffic flow

    Refer : https://learn.microsoft.com/en-us/azure/firewall/premium-features#idps-signature-rules

    Kindly let us know if this helps or you need further assistance on this issue.

    Thanks,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.