Windows Network Connections to azurefd.net Excluding Common Browsers and Known Front Door Hostnames

Flags Windows connections to azurefd.net that aren’t from common browsers/search or known benign Azure Front Door domains.

FreeReviewedSigma · Medium · v1
Product
windows
Category
network_connection
Author
Isaac Dunham (SigmaHQ), DRL 1.1
Published
2024-11-07
Updated
2026-07-30

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows network connections whose destination hostname contains azurefd.net while excluding traffic from common web browsers and Windows search service, and excluding several known benign Azure Front Door endpoints. Because Azure Front Door can be abused as a proxy or redirector, unexpected use outside an established baseline may indicate cloud-based command-and-control activity. The detection relies on network connection telemetry (destination hostname) and the process image initiating the connection, with allowlisting for specific Azure Front Door hostnames.

Related detections4 linkedT1102.002 — drag to rearrange
Suspicious Project CAV3RN logAzure.txt Configuration Drop (via file_event)
Windows GitHub Self-Hosted Runner Execution via Runner.Worker and Runner.Listener
Suspicious Telegram API proxy access without Telegram User-Agent
Suspicious DNS queries to api.telegram.org for Telegram Bot API traffic
Windows Network Connections to azurefd.net Excluding Common Browsers and Known Front Door Hostnames
Pivot detection · T1102.002 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.