LoFP LoFP / legitimate use of azure hybrid connection manager and the azure service bus service

Techniques

Sample rules

DNS HybridConnectionManager Service Bus

Description

Detects Azure Hybrid Connection Manager services querying the Azure service bus service

Detection logic

condition: selection
selection:
  Image|contains: HybridConnectionManager
  QueryName|contains: servicebus.windows.net