Actor
high
threat
Azure RBAC Privilege Escalation via Built-In Administrator Role Assignment
1 rule 2 TTPsThreat actors are observed abusing Azure Role-Based Access Control (RBAC) to gain unauthorized administrative privileges and achieve persistence by assigning high-privilege built-in roles to actor-controlled accounts.
Azure
Storm-0501
cloud-security
privilege-escalation
persistence
1r
2t
medium
threat
Unusual Azure Storage Account Key Access by Privileged User
2 rules 2 TTPsDetects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.
Microsoft Azure +1
Storm-0501
azure
storage account
credential access
ransomware
2r
2t