This detection identifies Mirai botnet activity by monitoring for network scans targeting IoT devices with default credentials or weak security configurations that often lead to DDoS attacks. Proactively hunting for these indicators in Azure Sentinel is critical to rapidly identify and isolate compromised IoT assets before they are recruited into a large-scale botnet capable of overwhelming enterprise networks.
Malware Family: Mirai Total IOCs: 2 IOC Types: ip:port
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 217[.]60[.]195[.]187:80 | botnet_cc | 2026-08-08 | 75% |
| ip:port | 94[.]154[.]43[.]12:32 | botnet_cc | 2026-08-08 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Mirai
let malicious_ips = dynamic(["94.154.43.12", "217.60.195.187"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["94.154.43.12", "217.60.195.187"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: Mirai IOCs detection rule, including suggested filters or exclusions tailored for a legitimate enterprise environment:
Scenario: Automated IoT Firmware Update Scans
cisco.com, ubnt.com) and the user agent string contains “Firmware-Update-Agent”.Scenario: Scheduled Network Discovery Jobs via Nmap/Zabbix
svc-nmap-discovery, zabbix-proxy-01) during defined maintenance windows (e.g., 02:00–04:00 UTC). Implement a filter that ignores alerts if the source