This hypothesis detects adversaries leveraging encrypted malicious URLs to bypass traditional inspection mechanisms and deliver payloads or redirect victims to phishing sites without triggering standard decryption alerts. A proactive hunt is essential in Azure Sentinel because encrypted traffic often obscures command-and-control communications, requiring specialized analysis of URLhaus intelligence feeds to identify high-severity threats that may otherwise remain invisible within the network perimeter.
Threat: encrypted Total URLs: 2 Active URLs: 2
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxps://drive.google.com/uc?export=download&id=1OUs4s8axg1VrXLEGkjjz9EB-4mCpnM0F | online | malware_download | 2026-07-24 |
hxxps://drive.google.com/uc?export=download&id=1A_G80DzjmvUicajtNsLlEzIaP0jSPEtV | online | malware_download | 2026-07-24 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: encrypted
let malicious_domains = dynamic(["drive.google.com"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["drive.google.com"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the URLhaus: encrypted Malicious URLs rule in an enterprise environment, along with suggested filters or exclusions:
Scenario: Automated SaaS Health Checks via Encrypted Probes
api.statuspage.io, healthcheck.pagerduty.com) using encrypted tunnels. These URLs often contain dynamic query parameters that can resemble malicious signatures, triggering the rule when the URLhaus feed flags them as “new” or “suspicious.”User-Agent string matches standard monitoring tool signatures (e.g., containing Datadog-APM, NewRelic).Scenario: Scheduled Cloud Backup Encryption Handshakes
/backup/v1/sync) and match against the known source IP of the backup appliance.**Scenario: CI/