Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)

Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.

FreeReviewedSigma · High · v2
Product
windows
Service
microsoft-servicebus-client
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2021-04-12
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows activity associated with Hybrid Connection Manager by matching specific service-related Event IDs (40300, 40301, 40302) and keyword strings tied to Hybrid Connection configuration. Attackers may use this mechanism to enable persistent connectivity through Azure Relay/Service Bus style endpoints, making servicebus-related indicators valuable for early detection. It relies on Windows service event telemetry and correlates the events with text artifacts such as 'HybridConnection', 'sb://', and 'servicebus.windows.net'.

Related detections8 linkedT1554 — drag to rearrange
Malicious Backdoored liblzma XZ Utils Library File via file_event
Suspicious Root Filesystem Remount as Writable on Appliance via Mount (via process_creation)
Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
Windows TanStack Supply-Chain File Creation Indicators via router_init.js and router_runtime.js
Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Linux setcap sets cap_setuid on a binary via setcap utility
Windows Security Event 4697: HybridConnectionManager Service Installation
Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Pivot detection · T1554 · 8 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.