Azure Defender PoC Series – Azure Defender for DNS

Published Jul 29 2021 10:16 AM 4,949 Views

Introduction

This article is a continuation of Azure Defender PoC Series which provides you guidelines on how to perform a proof of concept for a specific Azure Defender plan. For a more holistic approach where you need to validate Azure Security Center and Azure Defender, please read How to Effectively Perform an Azure Security Center PoC article. 

 

Azure Defender provides advanced threat detection and security alerts for all kinds of workloads, like Virtual Machines, SQL databases, Storage, Containers, Kubernetes, Key Vault, Web applications, Open-source relational databases. Recently we expanded the protection to two new plans, Azure Defender for DNS and ARM with the help of which you can enhance the resiliency against attacks.

 

To understand how helps your organization, make sure to read out this article. Azure Defender for DNS provides an additional layer of protection for your cloud resources by continuously monitoring all DNS queries from your Azure resources and runs advanced security analytics to alert you when suspicious activity is detected. To read more about how Azure Defender for DNS protects against issues, please read our official documentation.

 

Planning

With Azure Defender for DNS, we are looking at all the azure resources in an environment that’s connected to the Azure DNS, we are monitoring all the DNS queries that your resources are performing and detecting threats based on these queries so by doing so, we are actually protecting a variety of Azure resources that’s connected to this layer.

 

As part of your Azure Defender for DNS PoC you need to identify the use case scenarios that you want to validate. Common scenarios like, you may want to be notified when a DNS attack happens in your environment, DNS tunneling is another type of attack which is trying to exfiltrate sensitive data from your Azure resources, another type of attack is DNS cache poisoning for example, when an attacker is trying to redirect your communication to a malicious website. These attacks utilize DNS mechanism to attack the resource.

 

Azure Defender for DNS doesn’t use any agents. To protect your DNS layer, you need to enable Azure Defender for DNS for each of your subscriptions to protect the entire Azure subscription with Azure Defender.

Picture2.png

 

Preparation

You need at least Security Admin role to enable Azure Defender for DNS. For more information about roles and privileges, visit this article. If you are conducting this PoC in partnership with the SOC Team, make sure they are familiar with the alerts that may appear once you enable this plan. Review this article that gives you guidelines on how to respond to Azure Defender for DNS alerts Alerts Reference Guide. You can view list of all Azure DNS alerts from this article.

 

As of this blog writing, Azure Defender for DNS pricing model would be $0.70/1M Queries. Please visit our Pricing page to calculate the estimation of price in your environment.

 

From the readiness perspective, make sure to review the following resources to better understand Azure Defender for DNS

Implementation and Validation

To test and validate the Security alerts for Azure Defender for DNS follow the steps from this great article to trigger a test alert. For a complete list of all analytics available for Azure Defender for DNS, read this documentation.

 

Whether an alert is generated by Azure Defender for DNS or received by Azure Defender from a different Microsoft security solution (MDE for example), you can also export it. To export your alerts to Azure Sentinel, any third-party SIEM, or any other external tool, follow the instructions in Exporting alerts to a SIEM. To investigate Azure Defender alerts using Azure Sentinel, make sure to check out this blog to understand how they operate in a better together scenario.

 

If you find an alert not relevant, you can manually dismiss it. Alternatively, you can also use suppression rules feature to automatically dismiss similar alerts in the future. Follow our documentation if you’re looking to learn more about Suppression of alerts.

 

Make sure to check out our Azure Security Center Github repository which gives you access to numerous sample security playbooks that will help you automate in remediating a recommendation.

 

Conclusion

By the end of this PoC you should be able to determine the value proposition of Azure Defender for DNS and the importance to have this level of threat detection to your workloads.

 

Stay tuned for more Azure Defender PoC Series!

 

Reviewer

Special Thanks to Yuri Diogenes & Tal Rosler for reviewing this article.

 

1 Comment
Occasional Visitor

will this replace Azure Monitor DNS Analytics?

%3CLINGO-SUB%20id%3D%22lingo-sub-2595277%22%20slang%3D%22en-US%22%3EAzure%20Defender%20PoC%20Series%20%E2%80%93%20Azure%20Defender%20for%20DNS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2595277%22%20slang%3D%22en-US%22%3E%3CH2%20id%3D%22toc-hId--405893968%22%20id%3D%22toc-hId--405865043%22%20id%3D%22toc-hId--405865043%22%3E%3CSTRONG%3EIntroduction%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3EThis%20article%20is%20a%20continuation%20of%20Azure%20Defender%20PoC%20Series%20which%20provides%20you%20guidelines%20on%20how%20to%20perform%20a%20proof%20of%20concept%20for%20a%20specific%20Azure%20Defender%20plan.%20For%20a%20more%20holistic%20approach%20where%20you%20need%20to%20validate%20Azure%20Security%20Center%20and%20Azure%20Defender%2C%20please%20read%E2%80%AF%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fhow-to-effectively-perform-an-azure-security-center-poc%2Fba-p%2F516874%22%20target%3D%22_blank%22%3EHow%20to%20Effectively%20Perform%20an%20Azure%20Security%20Center%20PoC%3C%2FA%3E%E2%80%AFarticle.%3CSPAN%20data-ccp-props%3D%22%7B%26quot%3B134233117%26quot%3B%3Atrue%2C%26quot%3B134233118%26quot%3B%3Atrue%2C%26quot%3B201341983%26quot%3B%3A0%2C%26quot%3B335559740%26quot%3B%3A240%7D%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Defender%20provides%20advanced%20threat%20detection%20and%20security%20alerts%20for%20all%20kinds%20of%20workloads%2C%20like%20Virtual%20Machines%2C%20SQL%20databases%2C%20Storage%2C%20Containers%2C%20Kubernetes%2C%20Key%20Vault%2C%20Web%20applications%2C%20Open-source%20relational%20databases.%20Recently%20we%20expanded%20the%20protection%20to%20two%20new%20plans%2C%20Azure%20Defender%20for%20DNS%20and%20ARM%20with%20the%20help%20of%20which%20you%20can%20enhance%20the%20resiliency%20against%20attacks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20understand%20how%20helps%20your%20organization%2C%20make%20sure%20to%20read%20out%20this%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdns%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Earticle%3C%2FA%3E.%20Azure%20Defender%20for%20DNS%20provides%20an%20additional%20layer%20of%20protection%20for%20your%20cloud%20resources%20by%20continuously%20monitoring%20all%20DNS%20queries%20from%20your%20Azure%20resources%20and%20runs%20advanced%20security%20analytics%20to%20alert%20you%20when%20suspicious%20activity%20is%20detected.%20To%20read%20more%20about%20how%20Azure%20Defender%20for%20DNS%20protects%20against%20issues%2C%20please%20read%20our%20official%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-dns-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-2081618865%22%20id%3D%22toc-hId-2081647790%22%20id%3D%22toc-hId-2081647790%22%3E%3CSTRONG%3EPlanning%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3EWith%20Azure%20Defender%20for%20DNS%2C%20we%20are%20looking%20at%20all%20the%20azure%20resources%20in%20an%20environment%20that%E2%80%99s%20connected%20to%20the%20Azure%20DNS%2C%20we%20are%20monitoring%20all%20the%20DNS%20queries%20that%20your%20resources%20are%20performing%20and%20detecting%20threats%20based%20on%20these%20queries%20so%20by%20doing%20so%2C%20we%20are%20actually%20protecting%20a%20variety%20of%20Azure%20resources%20that%E2%80%99s%20connected%20to%20this%20layer.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20part%20of%20your%20Azure%20Defender%20for%20DNS%20PoC%20you%20need%20to%20identify%20the%20use%20case%20scenarios%20that%20you%20want%20to%20validate.%20Common%20scenarios%20like%2C%20you%20may%20want%20to%20be%20notified%20when%20a%20DNS%20attack%20happens%20in%20your%20environment%2C%20DNS%20tunneling%20is%20another%20type%20of%20attack%20which%20is%20trying%20to%20exfiltrate%20sensitive%20data%20from%20your%20Azure%20resources%2C%20another%20type%20of%20attack%20is%20DNS%20cache%20poisoning%20for%20example%2C%20when%20an%20attacker%20is%20trying%20to%20redirect%20your%20communication%20to%20a%20malicious%20website.%20These%20attacks%20utilize%20DNS%20mechanism%20to%20attack%20the%20resource.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Defender%20for%20DNS%20doesn%E2%80%99t%20use%20any%20agents.%20To%20protect%20your%20DNS%20layer%2C%20you%20need%20to%20enable%20Azure%20Defender%20for%20DNS%20for%20each%20of%20your%20subscriptions%20to%20protect%20the%20entire%20Azure%20subscription%20with%20Azure%20Defender.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Picture2.png%22%20style%3D%22width%3A%20624px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F299235i76BD3095BCD68D14%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Picture2.png%22%20alt%3D%22Picture2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-274164402%22%20id%3D%22toc-hId-274193327%22%20id%3D%22toc-hId-274193327%22%3E%3CSTRONG%3EPreparation%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3EYou%20need%20at%20least%20Security%20Admin%20role%20to%20enable%20Azure%20Defender%20for%20DNS.%20For%20more%20information%20about%20roles%20and%20privileges%2C%20visit%20this%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-permissions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Earticle%3C%2FA%3E.%20If%20you%20are%20conducting%20this%20PoC%20in%20partnership%20with%20the%20SOC%20Team%2C%20make%20sure%20they%20are%20familiar%20with%20the%20alerts%20that%20may%20appear%20once%20you%20enable%20this%20plan.%20Review%20this%20article%20that%20gives%20you%20guidelines%20on%20how%20to%20respond%20to%20Azure%20Defender%20for%20DNS%20alerts%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-dns-usage%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlerts%20Reference%20Guide%3C%2FA%3E.%20You%20can%20view%20list%20of%20all%20Azure%20DNS%20alerts%20from%20this%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-reference%23alerts-dns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Earticle%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20of%20this%20blog%20writing%2C%20Azure%20Defender%20for%20DNS%20pricing%20model%20would%20be%20%240.70%2F1M%20Queries.%20Please%20visit%20our%20Pricing%20page%20to%20calculate%20the%20estimation%20of%20price%20in%20your%20environment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20the%20readiness%20perspective%2C%20make%20sure%20to%20review%20the%20following%20resources%20to%20better%20understand%20Azure%20Defender%20for%20DNS%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DYVlW9udoYB0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20Defender%20for%20DNS%20%3A%20Azure%20Security%20Center%20in%20Field%20%2313%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-dns-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Defender%20for%20DNS%20Documentation%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-dns-usage%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EHow%20to%20respond%20to%20Azure%20Defender%20for%20DNS%20alerts%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH2%20id%3D%22toc-hId--1533290061%22%20id%3D%22toc-hId--1533261136%22%20id%3D%22toc-hId--1533261136%22%3E%3CSTRONG%3EImplementation%20and%20Validation%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3ETo%20test%20and%20validate%20the%20Security%20alerts%20for%20Azure%20Defender%20for%20DNS%20follow%20the%20steps%20from%26nbsp%3Bthis%20great%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fvalidating-azure-defender-for-dns-alerts%2Fba-p%2F2227845%22%20target%3D%22_blank%22%3Earticle%26nbsp%3B%3C%2FA%3Eto%20trigger%20a%20test%20alert.%20For%20a%20complete%20list%20of%20all%20analytics%20available%20for%20Azure%20Defender%20for%20DNS%2C%20read%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-reference%23alerts-dns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20documentation%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhether%20an%20alert%20is%20generated%20by%20Azure%20Defender%20for%20DNS%20or%20received%20by%20Azure%20Defender%20from%20a%20different%20Microsoft%20security%20solution%20(MDE%20for%20example)%2C%20you%20can%20also%20export%20it.%20To%20export%20your%20alerts%20to%20Azure%20Sentinel%2C%20any%20third-party%20SIEM%2C%20or%20any%20other%20external%20tool%2C%20follow%20the%20instructions%20in%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fexport-to-siem%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExporting%20alerts%20to%20a%20SIEM%3C%2FA%3E.%20To%20investigate%20Azure%20Defender%20alerts%20using%20Azure%20Sentinel%2C%20make%20sure%20to%20check%20out%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Finvestigate-azure-security-center-alerts-using-azure-sentinel%2Fba-p%2F1986759%22%20target%3D%22_blank%22%3Ethis%20blog%3C%2FA%3E%26nbsp%3Bto%20understand%20how%20they%20operate%20in%20a%20better%20together%20scenario.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20find%20an%20alert%20not%20relevant%2C%20you%20can%20manually%20dismiss%20it.%20Alternatively%2C%20you%20can%20also%20use%20suppression%20rules%20feature%20to%20automatically%20dismiss%20similar%20alerts%20in%20the%20future.%20Follow%20our%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-suppression-rules%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E%20if%20you%E2%80%99re%20looking%20to%20learn%20more%20about%20Suppression%20of%20alerts.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMake%20sure%20to%20check%20out%20our%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Security-Center%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Security%20Center%20Github%20repository%3C%2FA%3E%26nbsp%3Bwhich%20gives%20you%20access%20to%20numerous%20sample%20security%20playbooks%20that%20will%20help%20you%20automate%20in%20remediating%20a%20recommendation.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-954222772%22%20id%3D%22toc-hId-954251697%22%20id%3D%22toc-hId-954251697%22%3E%3CSTRONG%3EConclusion%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3EBy%20the%20end%20of%20this%20PoC%20you%20should%20be%20able%20to%20determine%20the%20value%20proposition%20of%20Azure%20Defender%20for%20DNS%20and%20the%20importance%20to%20have%20this%20level%20of%20threat%20detection%20to%20your%20workloads.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStay%20tuned%20for%20more%20Azure%20Defender%20PoC%20Series!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--853231691%22%20id%3D%22toc-hId--853202766%22%20id%3D%22toc-hId--853202766%22%3E%3CSTRONG%3EReviewer%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3ESpecial%20Thanks%20to%20Yuri%20Diogenes%20%26amp%3B%20Tal%20Rosler%20for%20reviewing%20this%20article.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2595277%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AzureDefenderPoCSeries.JPG%22%20style%3D%22width%3A%20545px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F299234i31E69D80088FD2E2%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22AzureDefenderPoCSeries.JPG%22%20alt%3D%22AzureDefenderPoCSeries.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2615365%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Defender%20PoC%20Series%20%E2%80%93%20Azure%20Defender%20for%20DNS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2615365%22%20slang%3D%22en-US%22%3E%3CP%3Ewill%20this%20replace%20Azure%20Monitor%20DNS%20Analytics%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Jul 29 2021 10:31 AM
www.000webhost.com