Skip to content
Threat Feed

Product

Azure Key Vault

6 briefs RSS
high threat

Storm-3168 Cloud Attack Campaign

Storm-3168 (linked to JADEPUFFER) leverages compromised Azure service principals to execute automated resource destruction and credential exfiltration through AI-orchestrated cloud API manipulation.

Azure App Service +6 Storm-3168 cloud-security identity-theft azure ransomware
1r 3t
high advisory

Cross-Environment Secret Harvesting via Cloud APIs

Adversaries are utilizing compromised credentials and stolen session tokens to perform rapid, automated secret harvesting across AWS, GCP, Azure, and Kubernetes environments from singular source IP addresses.

AWS Secrets Manager +3 credential-access cloud identity-theft
1t
medium advisory

Azure Key Vault Excessive Secret or Key Retrieval

Detects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.

Azure Key Vault azure keyvault credential-access threat-detection
2r 2t
high advisory

Multiple Cloud Secrets Accessed by Source Address

A single source IP accessing secret-management APIs across multiple cloud providers (AWS, GCP, Azure) and Kubernetes clusters within a short timeframe indicates credential theft or token replay for secret harvesting.

AWS Secrets Manager +3 cloud credential-access kubernetes
2r 1t
medium advisory

Azure Key Vault Unusual Secret Key Usage

Detects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.

Azure Key Vault azure keyvault credential-access
2r 1t
low advisory

Azure Key Vault Modified by Unusual User

This rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.

Azure Key Vault azure keyvault configuration-audit impact defense-evasion
2r 2t