Product
medium
advisory
Azure VM Extension Deployment by Interactive User
2 rules 3 TTPsSuccessful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal can lead to arbitrary code execution, backdoor account creation, credential harvesting, and persistence on Azure-hosted virtual machines.
Azure Virtual Machines +4
azure
vm-extension
persistence
cloud
threat-detection
2r
3t
low
advisory
Suspicious Whoami Process Activity
2 rules 2 TTPsThis rule detects suspicious use of whoami.exe to display user, group, and privileges information for the user who is currently logged on to the local system, potentially indicating post-compromise discovery activity.
Microsoft Monitoring Agent +1
discovery
windows
threat-detection
2r
2t