Product
medium
advisory
Monitoring Azure Run Command for Unauthorized Execution
1 rule 2 TTPsThis brief outlines detection strategies for unauthorized guest execution via the Azure Virtual Machine Run Command feature, which attackers may abuse to run arbitrary scripts without interactive access.
Azure Virtual Machine
azure
cloud
execution
detection-engineering
1r
2t
medium
threat
Azure VM Serial Console Exploitation for Lateral Movement
3 rules 2 TTPsAdversaries with privileged Azure RBAC roles are exploiting the Azure VM Serial Console to gain SYSTEM/root access on virtual machines, bypassing network controls like NSGs and JIT policies, with detections focusing on unusual user and source network combinations.
Azure Virtual Machine +1
cloud
azure
lateral-movement
defense-evasion
initial-access
vm
3r
2t