Azure-Network-Security
Resources for improving Customer Experience with Azure Network Security
File Explorer
Download Latest Version (.zip)- detectionsValidations.yaml
- documentsLinkValidator.yaml
- jsonFileValidator.yaml
- kqlValidations.yaml
- workbooksValidations.yaml
- yamlFileValidator.yaml
- bug_report.md
- feature_request.md
- codeql-analysis.yml
- codeql.yml
- devskim.yml
- greetings.yml
- super-linter.yml
- trafficcounter.yml
- dependabot.yml
- badlink.md
- documentsLinkValidator.Test.ts
- nodoclinks.md
- validlink.md
- idChangeValidatorTest.yaml
- invalidFile.json
- jsonFileValidator.test.ts
- validFile.json
- AzureDevOpsAuditing.json
- AzureDiagnostics.json
- CarbonBlackEvents_CL.json
- CarbonBlackNotifications_CL.json
- ChatEvents.json
- eset_CL.json
- GitHubAudit.json
- GitHubRepo.json
- InfobloxNIOS.json
- MeetingEvents.json
- Okta_CL.json
- ProofPointTAPClicksPermitted_CL.json
- ProofPointTAPMessagesDelivered_CL.json
- PulseConnectSecure.json
- QualysHostDetection_CL.json
- SophosXGFirewall.json
- SymantecProxySG.json
- SymantecVIP.json
- TeamsData.json
- ZoomLogs.json
- CustomTablesSchemasLoader.cs
- DetectionsYamlFilesTestData.cs
- Kqlvalidations.Tests.csproj
- KqlValidationTests.cs
- nuget.config
- SkipValidationsTemplates.json
- TemplatesToSkipValidationReader.cs
- TheoryData.cs
- duplicateKeyWorkbooksMetadata.json
- illegalPropertyWorkbooksMetadata.json
- missingBlackPreviewImageWorkbooksMetadata.json
- missingRequiredPropertyWorkbooksMetadata.json
- missingWhitePreviewImageWorkbooksMetadata.json
- noColorPreviewImagesWorkbooksMetadata.json
- nonPngPreviewImagesWorkbooksMetadata.json
- validWorkbooksMetadata.json
- workbooksMetadataValidator.test.ts
- invalidFile.yaml
- validFile.yaml
- yamlFileValidator.test.ts
- changedFilesValidator.ts
- exitCode.ts
- gitWrapper.ts
- logger.ts
- stringExtenssions.ts
- jsonFileValidator.ts
- ReadMe.md
- yamlFileValidator.ts
- launch.json
- settings.json
- Detection - Bastion Brute Force.json
- README.md
- azure-bastion-diagnostic-policy.json
- README.md
- README.md
- DDoSMitigationStarted.json
- README.md
- Enrich-DDoSAlert.json
- README.md
- Prerequisites.sh
- README.md
- syn-flood.py
- Check-DDoSProtection.ps1
- README.md
- PIP DDoS Diag Logging.json
- README.md
- PublicIPenableResourcelogsDDOS.json
- README.MD
- Public IPs Associated with Azure Firewall Should Have DDoS Protection Enabled.json
- README.md
- PublicIPsShouldBeProtectedWithIpProtection.json
- README.md
- Public Ips With A Specified Tag Should Have DDoS Protection Enabled.json
- README.md
- Public IPs with a specified tag will be added to a specified DDoS Plan.json
- README.md
- AzPolicyDenyDDoSPlanCreation.png
- AzurePolicyRuleDenyDDoSPlan.json
- README.md
- README.md
- VNet-DDoSEnable-Tags.json
- VNet-DDoSEnable.json
- Public IPs Associated with Azure Application Gateway Should Have DDoS Protection Enabled.json
- README.md
- DDoSLogs.json
- README.md
- Enable-DDoSLogs.ps1
- README.md
- README.md
- README.md
- Queries for DDoS Mitigation Trend
- README.md
- Get-AllDdosProtectedIPs.ps1
- README.md
- DDoS Plan Link PS Script.ps1
- Readme.md
- Get-AzDDOSProtectedIPs.ps1
- README.md
- AzureDDoSWorkbook_ARM.json
- AzureDDoSWorkbookV2_ARM.json
- GalleryTemplate.json
- GalleryTemplateV2.json
- README.md
- README.md
- AbnormalDenyRate.json
- README.md
- AbnormalPortToProtocol.json
- README.md
- DistributedLowRateDDoS_Classic.json
- DistributedLowRateDDoS_ResourceSpecific.json
- README.md
- FirstTimeSrcIpToDst.json
- README.md
- FirstTimeSrcIpToDstWithPort.json
- README.md
- MultipleSourceSameTI.json
- README.md
- PortScan.json
- README.md
- PortSweep.json
- README.md
- README.md
- SourceAbnormallyConnectsToMultipleDsts.json
- README.md
- UncommonPortToIp.json
- README.md
- UncommonPortToOrganization.json
- DDoS attack detected.kql
- Elevation of Privilege attempt detected.kql
- High severity malicious activity detected.kql
- Medium severity malicious activity detected.kql
- README.md
- Web Application attack detected.kql
- Detection - Brute Force through IDPS Logs.json
- README.md
- Detection - Analytic rule query for ClOp
- Detection - Analytic rule query for Coinminer
- Detection - Analytic rule query for Sunburst
- JS Challenge for Bot Traffic Thresholds.json
- ReadMe
- AzPIPtoAssetQuerydeploy.json
- README.md
- Query - AZFW Ruleset Change Tracking.txt
- README.md
- IDPSSignature
- README.md
- PortsonNSGsQueryDeploy.json
- README.md
- README.md
- backup-azfw-template-v3.json
- Deploy-FWBackup.ps1
- README.md
- Playbook - Add to IP Group with REST API.json
- README.md
- Detection - Analytic rule query for Cl0p.json
- Detection - Analytic rule query for Coinminer.json
- Detection - Analytic rule query for Sunburst.json
- README.md
- AZFW Diag Logging.json
- README.md
- azurepolicy.json
- README.md
- InetTrafficGoThroughAzFirewall.json
- README.MD
- Azure Firewall Policy Analytics Should be Enabled.json
- README.md
- Azure Firewall Should have DNS Proxy Enabled.json
- README.md
- AzureFirewallShouldOnlyAllowEncryptedTraffinInTheEnvironment.json
- README.md
- DeployAzFirewallacrossmultipleavailzones.json
- README.md
- EnableIDPSsignatureRules.json
- README.MD
- EnableIDPSInAzureFirewallPremiumPolicy-Full.json
- README.md
- Enable PAC file configuration while using Explicit Proxy on Azure Firewall.json
- README.md
- EnableThreatIntelligenceinAzureFirewallPolicy-Full.json
- README.md
- Azure Policy - Enforce Explicit Proxy Configuration for Firewall Policies.json
- README.md
- Enforce Management Interface for Azure Firewall.json
- README.md
- Ensure Resource Specific Logs are Enabled on Azure Firewall.json
- README.md
- FirewallConfigurevalidcert.json
- README.MD
- FirewallPolicyenableTLSinspection.json
- README.MD
- MigratefromAzureFirewallClassicRulestoFirewallPolicy-Full.json
- README.md
- Deploy AZFW in VHub.json
- README.md
- README.MD
- SubscriptionsshoulduseAzFirewall.json
- README.md
- UpgradeAzFirewallStandardtoPrem.json
- README.md
- VNET with specific Tag must have Azure Firewall deployed.json
- FirewallLogs.json
- README.md
- Enable-FirewallLogs.ps1
- README.md
- README.md
- AllowDNSoverHTTPS.json
- AllowGithubRepo.json
- README.md
- AllowAllWeb.json
- README.md
- README.MD
- Runbook.txt
- ipsconfig.json
- ipssigs.ps1
- ipssigupdate.ps1
- README.md
- classic_network_collection.json
- main.tf
- providers.tf
- README.md
- main.tf
- policy_network_collection.json
- providers.tf
- README.md
- ip_groups_only.json
- main.tf
- providers.tf
- README.md
- main.tf
- policy_network_collection.json
- providers.tf
- README.md
- full_list.csv
- ipg_part_1.csv
- ipg_part_2.csv
- ipg_part_3.csv
- splitCSV.ps1
- template_ip_group.csv
- ip_group_input_example.json
- ip_group_template.json
- main.tf
- outputs.tf
- vars.tf
- main.tf
- outputs.tf
- vars.tf
- ip_group_template.json
- main.tf
- outputs.tf
- vars.tf
- main.tf
- outputs.tf
- vars.tf
- main.tf
- outputs.tf
- policy_template_network.json
- vars.tf
- classic_network_collection.json
- main.tf
- outputs.tf
- vars.tf
- main.tf
- outputs.tf
- vars.tf
- azure-firewall-ipgroup.auto.tfvars.sample
- main.tf
- vars.tf
- chkp2azfw.py
- index.json
- Network-Management server.json
- README.md
- Standard_objects.json
- template.json
- read_fortigate_config.py
- readme.md
- pa2azfw.py
- readme.md
- MigrateSecureHub.md
- README.md
- AzFW-AKS-sync.png
- README.md
- UpdateFirewallPolicy.ps1
- architecture-with-custom-dns-forwader.png
- architecture-without-custom-dns-forwader.png
- dnat-rules.png
- dns-proxy-with-custom-dns-forwarder.png
- dns-proxy-without-custom-dns-forwarder.png
- dns-settings.png
- internet-rules.png
- nslookup.png
- resource-group.png
- route-table.png
- vnet-to-vnet.png
- configure-custom-dns-forwarder.sh
- test-dns-and-private-endpoints.sh
- azuredeploy.json
- azuredeploy.parameters.json
- metadata.json
- README.md
- fwBasicTemplate.bicep
- fwBasicMain.bicep
- readme.md
- FwBasicTFMain.tf
- readme.md
- DedicatedPeVnet.tf
- HubAndSpoke.tf
- readme.md
- SingleVnet.tf
- azuredeploy.json
- o365_rules.py
- readme.md
- azuredeploy.json
- readme.md
- README.md
- Template.json
- azuredeploy.json
- README.md
- addnspic.png
- urls.png
- azuredeploy.json
- README.md
- PrivateIpDnatArmTemplateV2.json
- readme.md
- win-vm-2.ps1
- win-vm-3.ps1
- README.md
- azuredeploy.json
- README.MD
- Azure Firewall_ARM.json
- Azure Firewall_Gallery.json
- Azure Firewall_ResourceSpecific_ARM.json
- Azure Firewall_ResourceSpecific_Gallery.json
- README.md
- armTemplate.json
- netsec.gif
- ReadMe.md
- README.md
- afd-rate-limit-1.png
- afd-rate-limit-2.png
- afd-rate-limit-3.png
- afd-redirect-1.png
- afd-redirect-2.png
- afd-redirect-3.png
- Azfw-east-west-1.jpg
- Azfw-east-west-1.png
- Azfw-east-west-2.png
- Azfw-east-west-3.png
- Azfw-latency-flow-logs-1.png
- Azfw-latency-flow-logs-2.png
- Azfw-latency-flow-logs-3.png
- Azfw-latency-flow-logs-4.png
- Azfw-latency-flow-logs-5.png
- Azfw-outbound-internet-1.png
- Azfw-outbound-internet-2.png
- Azfw-outbound-internet-3.png
- Azfw-resource-specific-logs-1.png
- Azfw-resource-specific-logs-2.png
- ddos-logs-metrics-1.png
- ddos-logs-metrics-2.png
- ddos-logs-metrics-3.png
- ddos-logs-metrics-4.png
- ddos-logs-metrics-5.png
- ddos-logs-metrics-6.png
- ddos-sentinel-1.png
- ddos-sentinel-2.png
- ddos-sentinel-3.png
- ddos-sentinel-4.png
- ddos-setup-1.png
- ddos-setup-2.png
- ddos-setup-3.png
- ddos-setup-4.png
- ddos-setup-5.png
- ddos-setup-6.png
- ddos-setup-7.png
- ddos-setup-8.png
- js-challenge-1.png
- js-challenge-2.png
- js-challenge-3.png
- js-challenge-4.png
- js-challenge-5.png
- js-challenge-6.png
- mozilla-user-agent-1.png
- mozilla-user-agent-2.png
- mozilla-user-agent-3.png
- ninja-cat-logo-1.png
- ninja-cat-logo-2.png
- README.md
- sql-injection-1.png
- sql-injection-2.png
- sql-injection-3.png
- sql-injection-4.png
- sql-injection-5.png
- sql-injection-6.png
- sql-injection-7.png
- waf-diag-metrics-1.png
- waf-diag-metrics-2.png
- labdeployment.json
- Resource.md
- Azure Application Gateway WAF.md
- Azure DDoS Protection.md
- Azure Firewall.md
- Azure Front Door WAF.md
- README.md
- AlertBody.cs
- LogsBody.cs
- ProcessAFDAlerts.cs
- README.md
- CustomRulesAFD.json
- CustomRulesAppGW.json
- README.md
- AFD-WAF-Detection Based on Captcha Bot Traffic Thresholds.kql
- Application Gateway WAF Detection for Protocol Attacks [HTTP] - Azure Diagnostics.json
- Azure Front Door WAF Detection for Protocol Attacks [HTTP] - Azure Diagnostics.json
- Code-Injection-AFD-WAF.json
- Code-Injection-AppGW-WAF-CRS3-2.json
- Detection-based-on-JSChallenge-for-Bot-Traffic-Thresholds.json
- Hunting Queries for Top IPs and Rule IDs for Azure WAF
- Malicious-Bots-Detection-Query
- Path-Traversal-AFD-WAF.json
- Path-Traversal-AppGW-CRS3-2.json
- Readme.md
- Resource Specific - App GW WAF Malicious WAF Session.csl
- Resource Specific - AppGW WAF Scanner Detections.csl
- Resource Specific Application Gateway WAF - Malicious-Bots-Detection-Query.csl
- Resource-Specific - Application Gateway WAF Detection for Protocol Attacks [HTTP].json
- Resource-Specific-Code-Injection-AppGW-WAF-DRS.csl
- Resource-Specific-Path-Traversal-AppGW-DRS.csl
- Resource-Specific-SQLi-Detection-APPGW-WAF.csl
- Resource-Specific-XSS-Detection-AppGW-WAF.csl
- Scanner-Detections-AppGw.json
- SQLi-Detection-APPGW-WAF.json
- Time Series IP Anomaly Detection for Azure Application Gateway WAF Resource Specific Logs.csl
- Time Series IP Anomaly Detection for Azure WAF.json
- XSS-Detection-AppGW-WAF.json
- README.md
- template.json
- README.md
- template.json
- templateV2.json
- AFD-WAF Diag Logging.json
- AppGW-WAF Diag Logging.json
- README.md
- AzureAppGWandAzureFDShouldBeDeployedWithWAF.json
- README.md
- Application Gateway WAF policies should be attached to Application Gateways.json
- README.md
- Policy - Application Gateway WAF should have HTTP DDoS Ruleset enabled.json
- README.md
- Audit legacy or deprecated WAF rulesets on Application Gateway and Front Door.json
- README.md
- Azure Front Door WAF policies should be attached to security policies.json
- README.md
- AzureWAFGeoMatchCustomRulesShouldSpecifyTheZZLocation.json
- README.md
- BotProtection-Enabled-AFD-WAF.json
- README.md
- Bot Protection should be enabled for Application Gateway for Containers (AGC) WAF.json
- README.md
- BotProtection-Enabled-AppGW-WAF.json
- README.md
- Policy - Enable Geo Block Rules.json
- README.md
- EnableJSChallengeToProtectAgainstMaliciousAndUnwantedBots.json
- README.md
- EnableLogScrubbingRulesForAzureWAF.json
- README.md
- EnableRateLimitFrontDoorWAF.json
- README.MD
- Enable Rate Limit rule on Application Gateway WAF.json
- README.md
- EnsureRequestBodyInspection.json
- README.MD
- README.MD
- RequestBodyEnableFrontDoor.json
- MandatoryWAFPolicy.json
- README.md
- WAFModeRequirement.json
- Enforce Request Body Inspection, Max Request Body & File Upload Limits on Application Gateway WAF.json
- README.md
- Ensure Resource Specific Logs are Enabled on Application Gateway WAF.json
- README.md
- README.MD
- WAFspecifiedmodeAppGateway.json
- README.MD
- WAFspecifiedmodeFrontDoor.json
- README.md
- WAFLogs-AppGateway.json
- WAFLogs-FrontDoor.json
- Enable-WAFLogs.ps1
- README.md
- README.md
- README.md
- Postman-Cookie-Value.png
- Postman-Cookie.png
- Postman-DomainVariable.png
- Postman-Import-Complete.png
- Postman-Import-Step.png
- Postman-Import.png
- Postman-RequestSent.png
- AzureWAF-SensitiveData-ARM.json
- AzureWAF-SensitiveData-Bicep.bicep
- AzureWAF-SensitiveData-BicepParam.bicepparam
- ReadMe.md
- Azure WAF - Sensitive Fields.postman_collection.json
- ReadMe.md
- AzureWAF-Quick-Tune-AppGW.bicep
- AzureWAF-Quick-Tune-AppGW.bicepparam
- AzureWAF-Quick-Tune-AppGW.json
- ReadMe.md
- Azure WAF Tuning - Application Gateway.postman_collection.json
- ReadMe.md
- AzureWAF-Quick-Tune-AFD.bicep
- AzureWAF-Quick-Tune-AFD.json
- ReadMe.md
- Azure WAF Tuning - Front Door.postman_collection.json
- ReadMe.md
- ReadMe.md
- generate_waf_exclusion.py
- README.MD
- results.png
- resultspie.png
- azuredeploy.json
- README.md
- README.md
- WAF Quickstart Template v2.json
- azure-firewall-ipgroup.auto.tfvars.sample
- main.tf
- outputs.tf
- providers.tf
- Readme.md
- variables.tf
- AzNetSecdeploy_Juice-Shop_AZFW-Rules_Updated.json
- README.md
- New-WafExclusion.ps1
- waf-triage-workbook.json
- azuredeploy.json
- README.md
- AFDTriageGalleryTemplate.json
- AFDTriageworkbookARMTemplate.json
- README.md
- AGC WAF Triage Workbook.json
- README.md
- Azure APP GW WAF Monitor Workbook - Resource Specific - Gallery.json
- Azure App GW WAF Monitor Workbook - Resource Specific Logs - ARM.json
- README.md
- AppGw-WAF-triage-workbook-deployment-params.png
- README.md
- WAFTriageWorkbook_ARM.json
- README.md
- WAFWorkbook_ARM.json
- WAFWorkbook_Gallery.json
- WAFWorkbookV2_WithMetrics_ARM.json
- WAFWorkbookV2_WithMetrics_Gallery.json
- WAFWorkbookV3_WithJSChallenge_ARM.json
- WAFWorkbookV3_WithJSChallenge_Gallery.json
- README.MD
- Get-AzDNSUnhealthyRecords.ps1
- readme.md
- Get-DanglingDnsRecords.ps1
- WorkflowFunctions.ps1
- AzDanglingDomain.psd1
- AzDanglingDomain.psm1
- Readme.md
- Get-AzDNSDanglingNsRecords.ps1
- DDOSworkbookview.jpg
- README.md
- AzFwWorkbook.png
- README.md
- README.md
- README.md
- WAF-Workbook.png
- waf_monitor_workbook.png
- WAF_Workbook.png
- demo_image.png
- deploy-to-azure.svg
- firewall-secure-hub.png
- Net-Security-logo.png
- README.md
- watch-for-update.png
- PortsonNSGsQueryDeploy.json
- README.md
- PortsonLoadBalancersQueryDeploy.json
- README.md
- AzPIPtoAssetQuerydeploy.json
- README.md
- Netsec crossproduct source IP query
- README.md
- assignIpTags.ps1
- README.md
- AzFwForceTunnel.png
- AzFWv2.gif
- ConnectionV2.gif
- DefaultSite.png
- PeeringV1.gif
- VNGv1.gif
- azfwConnectionsLinkedTemplate.json
- azureLinkedTemplate.json
- diagnosticLinkedTemplate.json
- onPremLinkedTemplate.json
- azfwForceTunnelTemplate.json
- README.md
- SetupWinVM.ps1
- appplyConfigurations.json
- compilationJobs.json
- dscModules.json
- disable.json
- enable.json
- scheduler.json
- storageAccount.json
- diagSettings.json
- bastion.json
- firewall.json
- keyVault.json
- openssl.cnf
- vNets.json
- kaliVM.json
- vmCerts.json
- win11VM.json
- win2019VM.json
- appService.json
- frontdoor.json
- gateway.json
- AzNetSecdeploy.json
- network-security.template.yml
- network-security.variables.yml
- README.md
- AzNetSecdeploy.json
- README.md
- wafattacklabarch.png
- main.tf
- provider.tf
- README.md
- variables.tf
- main.tf
- provider.tf
- readme.md
- terraform.tfvars
- variables.tf
- AzNetSecdeploy_Juice-Shop_AZFW-Rules_Updated.json
- README.md
- recreate.png
- shop_screenshot.jpg
- add_to_cart.php
- connectdb.php
- delete_item.php
- helpers.php
- login.php
- logout.php
- recreate_and_seed_db.php
- show_table.php
- coffee_data.sql
- create_db.sql
- users.sql
- .gcloudignore
- .gitignore
- app.yaml
- composer.json
- composer.lock
- index.php
- Readme.md
- readme.md
- readme
- .gitignore
- azure-pipelines.yml
- CODE_OF_CONDUCT.md
- CODEOWNERS
- CONTRIBUTING.md
- LICENSE
- package-lock.json
- package.json
- README.md
- SECURITY.md
- tsconfig.json
# Installation Guide
1. Get the code
git clone https://github.com/Azure/Azure-Network-Security
Downloads the entire project code from GitHub to your computer.
cd Azure-Network-Security
Moves into the project folder you just downloaded.
2. Node.js
Easy RecommendedPrerequisites
npm install
Downloads and installs the libraries listed in package.json.
npm start
Starts the development/run server.
After running the command, open the address shown in the terminal (usually something like http://localhost:3000) in your browser.
3. PHP (Composer)
EasyPrerequisites
β οΈ This is a large repository, so this method may point to an internal sub-package rather than the actual core product. Check the full README as well.
cd Lab Templates/Lab Template - WAF for GCP Coffeeshop/sql-injection-demo
This project's files live in a subfolder, so move into it first.
composer install
Installs the PHP libraries listed in composer.json.
Run it with a built-in server like php -S localhost:8000, then open http://localhost:8000 in your browser.
// repository documentation
Was this content helpful?
(0 ratings)
