Skip to content
Threat Feed

Tag

Azure

194 briefs RSS
medium advisory

Suspicious Child Process Execution via Azure VM CustomScript Extension

Attackers with access to an Azure subscription or VM management plane can leverage the Azure VM CustomScript extension to execute arbitrary code with SYSTEM privileges on Windows virtual machines, leading to various malicious activities such as reconnaissance, malware deployment, and persistence.

Azure Virtual Machines CustomScript Extension windows execution cloud-to-host azure lolbin
1r 4t
critical advisory

Critical Azure AD Improper Authentication Vulnerability (CVE-2026-45480)

A critical improper authentication vulnerability, CVE-2026-45480, in Microsoft Azure Active Directory allows an unauthorized attacker to bypass authentication mechanisms and elevate privileges over a network, potentially leading to full administrative control of Azure AD and associated resources.

Azure Active Directory azure active-directory cve critical-vulnerability privilege-escalation authentication-bypass
2r 2t
medium advisory

Azure VM Managed Run Command Abuse for Execution and Persistence

Adversaries can abuse the Azure VM Managed Run Command feature (MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE) to achieve code execution as System or root and establish persistence on Azure Virtual Machines or Virtual Machine Scale Sets by an unusual identity, potentially evading detections focused solely on action-based Run Commands.

Azure Virtual Machines +2 cloud azure execution persistence defense-evasion vm iac
2r 1t
high advisory

Azure VM Extension CRUD from Unusual Source ASN

Threat actors are performing create, read, update, or delete (CRUD) operations against Azure VM or VM Scale Set extensions (e.g., CustomScript, DSC) from an anomalous source Autonomous System (AS) number, enabling high-privilege code execution and persistence on guest operating systems (SYSTEM on Windows, root on Linux) by abusing compromised Azure identities.

Azure VM +4 cloud endpoint azure azure-activity-logs threat-detection execution persistence
2r 2t
medium threat

Azure VM Serial Console Exploitation for Lateral Movement

Adversaries with privileged Azure RBAC roles are exploiting the Azure VM Serial Console to gain SYSTEM/root access on virtual machines, bypassing network controls like NSGs and JIT policies, with detections focusing on unusual user and source network combinations.

Azure Virtual Machine +1 cloud azure lateral-movement defense-evasion initial-access vm
3r 2t
medium advisory

Entra ID OAuth Application Redirect URI Modified

Adversaries are modifying OAuth application redirect URIs (ReplyUrls) in Microsoft Entra ID to intercept OAuth authorization codes and steal tokens, granting unauthorized access without new application registration or user consent.

Entra ID +1 cloud identity azure persistence credential-access token-theft microsoft-entra-id
2r 2t
medium advisory

Microsoft Entra ID Guest Account Promoted to Member

A sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.

Microsoft Entra ID cloud identity persistence azure microsoft-entra-id
1r 1t
high advisory

Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence

An attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.

Microsoft Entra ID cloud identity azure entra-id mfa-bypass persistence lateral-movement initial-access
3r 2t
medium advisory

Azure Run Command Correlated with Process Execution

This rule detects the abuse of Azure Virtual Machine Run Command to execute scripts remotely, correlating Azure Activity Log events with endpoint process starts, identifying instances where adversaries use Run Command to run scripts as SYSTEM or root.

Azure +1 cloud endpoint execution powershell
2r 2t
medium advisory

Azure Run Command Script Child Process

This rule identifies suspicious process start events where the parent process matches Azure Virtual Machine Run Command execution patterns on Windows (PowerShell with `-ExecutionPolicy Unrestricted` and `script?.ps1`) or Linux (waagent running `script.sh` under `/var/lib/waagent/run-command/`), exposing on-guest payloads.

Azure Virtual Machines cloud endpoint azure execution azure-run-command
2r 3t
high advisory

Entra ID Microsoft Authentication Broker Sign-In with Non-Standard User Agent

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker authenticates using a non-standard user agent, inconsistent with common browser, mobile, or Windows platforms, potentially indicating adversary-in-the-middle or OAuth phishing attacks.

Entra ID cloud identity azure entra_id initial_access
2r 3t
high advisory

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.

Microsoft Entra ID cloud identity azure entra_id sign-in_logs threat_detection initial_access persistence +1
2r 3t
medium advisory

Azure VM Extension Deployment by Interactive User

Successful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal can lead to arbitrary code execution, backdoor account creation, credential harvesting, and persistence on Azure-hosted virtual machines.

Azure Virtual Machines +4 azure vm-extension persistence cloud threat-detection
2r 3t
critical advisory

CVE-2026-40412: Unrestricted File Upload in Azure Orbital Spatio Leads to Remote Code Execution

CVE-2026-40412 is a critical vulnerability in Azure Orbital Spatio that allows an unauthenticated attacker to execute arbitrary code over a network by uploading a file with a dangerous type.

Azure Orbital Spatio cve rce file-upload azure cloud
2r 1t 1c
critical advisory

CVE-2026-40411: Azure Virtual Network Gateway Improper Input Validation RCE

CVE-2026-40411 describes an improper input validation vulnerability in Azure Virtual Network Gateway that allows an authorized attacker to execute code over a network.

Azure Virtual Network Gateway azure rce vulnerability
2r 1t 1c
high advisory

CVE-2026-35430 - Azure PIM Authorization Bypass via User-Controlled Key

CVE-2026-35430 allows an authorized attacker to elevate privileges over a network in Azure Privileged Identity Management (PIM) through a user-controlled key.

Azure Privileged Identity Management privilege escalation azure
2r 1t 1c
high advisory

CVE-2026-23663: Azure Entra ID Improper Privilege Management Vulnerability

CVE-2026-23663 is a privilege escalation vulnerability in Azure Entra ID that allows an unauthorized attacker to elevate privileges over a network.

Azure Entra ID privilege-escalation cloud azure
2r 1t 1c
high advisory

Microsoft Entra ID and Azure Resource Manager Vulnerabilities Allow Privilege Escalation

An anonymous, remote attacker can exploit multiple unspecified vulnerabilities in Microsoft Entra ID and Microsoft Azure Resource Manager to escalate privileges.

Azure Resource Manager +1 privilege-escalation cloud azure
2r 1t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

This rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.

Entra ID +1 cloud identity api azure oauth session hijacking
2r 2t
high advisory

M365 or Entra ID Identity Sign-in from a Suspicious Source

This rule correlates Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address, indicating potential initial access by adversaries triggering network security alerts before accessing cloud resources.

Microsoft 365 +1 cloud saas azure entra_id microsoft_365 initial_access
2r 1t
high advisory

Microsoft Azure Portal Windows Admin Center Vulnerability Allows Privilege Escalation

A local attacker can exploit a vulnerability in Microsoft Azure Portal Windows Admin Center to gain administrator rights, potentially leading to unauthorized access and control over Azure resources.

Azure Portal Windows Admin Center azure privilege-escalation windows
2r 1t
high threat

Fox Tempest Malware-Signing-as-a-Service Disrupted

Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation run by Fox Tempest that abused the Azure Artifact Signing service to generate fraudulent code-signing certificates, enabling malware to bypass security controls.

Azure Artifact Signing +4 Fox Tempest code-signing malware-signing supply-chain azure
2r 2t 1i
critical advisory

Coder Azure Instance Identity PKCS#7 Signature Bypass Leads to Unauthenticated Agent Token Theft (CVE-2026-46354)

Coder is vulnerable to a PKCS#7 signature bypass in Azure instance identity (CVE-2026-46354), allowing unauthenticated agent token theft via a forged vmId, enabling access to Git SSH private keys, OAuth access tokens, and workspace secrets.

Coder v2 +4 pkcs7 azure instance identity signature bypass unauthenticated access credential theft cve-2026-46354 coder
3r 3t
high threat

Fox Tempest Malware-Signing-as-a-Service Disrupted by Microsoft

Microsoft disrupted Fox Tempest, a threat actor running a malware-signing-as-a-service (MSaaS) that abuses Microsoft Artifact Signing to generate short-lived code-signing certificates used to sign malware disguised as legitimate software, delivering ransomware and various information stealers to victims across multiple sectors.

Microsoft Artifact Signing +1 Fox Tempest malware-signing azure defense-evasion ransomware
2r 2t
high advisory

CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability

CVE-2026-42822 is an elevation of privilege vulnerability in Azure Local Disconnected Operations (ALDO) due to improper authentication, allowing unauthorized network attackers to escalate privileges.

Azure Local Disconnected Operations privilege-escalation azure cloud
1r 1t
medium advisory

Entra ID Register Device with Unusual User Agent (Azure AD Join)

Detects suspicious Microsoft Entra ID audit events for device registration where details indicate an Azure AD join and the user agent is not a standard registration client, potentially indicating scripted registration, third-party tooling, or malicious device registration for persistence or token abuse.

Entra ID azure entra_id persistence
2r 1t
high threat

Entra ID OAuth Device Code Phishing via AiTM

Detects successful Microsoft Entra ID sign-ins using the OAuth device code authentication protocol with the Microsoft Authentication Broker client requesting first-party Office API resources, indicative of adversary-in-the-middle (AiTM) phishing attacks such as Tycoon 2FA.

Entra ID +3 Tycoon2FA cloud identity azure entra_id phishing
2r 3t
medium advisory

Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource

Detects successful Microsoft Entra ID sign-ins where the client application is the Microsoft Authentication Broker (MAB) and the requested resource identifier is outside a short list of commonly observed first-party targets, potentially indicating abuse to obtain tokens for unexpected APIs or enterprise applications.

Entra ID cloud identity azure entra_id microsoft_entra_id sign_in_logs threat_detection initial_access
2r 2t
medium advisory

Microsoft Graph Multi-Category Reconnaissance Burst

The rule detects Microsoft Graph activity from delegated user tokens where a single user session and source IP rapidly touches multiple high-value Graph paths indicative of reconnaissance, suggesting a broad enumeration playbook.

Microsoft Graph cloud identity api azure microsoft-entra-id microsoft-graph threat-detection discovery
2r 2t
high advisory

Multiple Vulnerabilities in Microsoft Azure and Windows Admin Center

Multiple vulnerabilities in Microsoft Azure and Windows Admin Center allow an attacker to escalate privileges, spoof information, and bypass security measures.

Azure +1 windows privilege-escalation defense-evasion
2r 2t
high advisory

CVE-2026-40381: Azure Connected Machine Agent Improper Access Control Vulnerability

CVE-2026-40381 is a vulnerability in the Azure Connected Machine Agent that allows an authorized attacker to elevate privileges locally due to improper access control.

Azure Connected Machine Agent privilege-escalation azure access-control
2r 1t 1c
high threat

CVE-2026-32204: Azure Monitor Agent Privilege Escalation via External File Path Control

CVE-2026-32204 is a privilege escalation vulnerability in Azure Monitor Agent that allows an authorized attacker with local access to elevate privileges by manipulating file names or paths.

Azure Monitor Agent privilege-escalation cve azure
2r 1t 1c
critical advisory

CVE-2026-33117: Azure SDK Improper Authentication Vulnerability

CVE-2026-33117 is a critical vulnerability in the Azure SDK that allows an unauthorized attacker to bypass a security feature over a network due to improper authentication.

Azure SDK cve authentication bypass azure sdk cloud
2r 1t 1c
medium advisory

Multiple Vulnerabilities in Microsoft Azure

Multiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.

Azure +2 vulnerability
2r 3c
high advisory

CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability

A server-side request forgery vulnerability in Azure Notification Service allows an authorized attacker to elevate privileges over a network, leading to privilege escalation.

Azure Monitor Action Group Notification System ssrf privilege-escalation azure
2r 1t
high advisory

CVE-2026-35435 Azure AI Foundry Elevation of Privilege Vulnerability

CVE-2026-35435 is an elevation of privilege vulnerability in Azure AI Foundry M365 that allows an unauthorized attacker to elevate privileges over a network due to improper access control in published agents.

Azure AI Foundry azure privilege-escalation cloud
2r 1t
critical advisory

CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE-2026-33844 is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra due to improper input validation, allowing an authorized network attacker to execute code.

Azure Managed Instance for Apache Cassandra rce vulnerability azure
2r 1t
critical advisory

CVE-2026-33109 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE-2026-33109 is a remote code execution vulnerability in Microsoft's Azure Managed Instance for Apache Cassandra due to improper access control, allowing an authorized attacker to execute code over a network.

Azure Managed Instance for Apache Cassandra cve rce azure cassandra
2r 1t
medium advisory

CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability

CVE-2026-32207 is a cross-site scripting vulnerability in Azure Machine Learning, allowing an unauthorized attacker to perform spoofing over a network.

Azure Machine Learning xss spoofing azure
2r 1t
high advisory

OpenTelemetry Collector Azure Auth Extension Authentication Bypass

A server-side authentication bypass vulnerability exists in opentelemetry-collector-contrib's azureauthextension versions 0.124.0 through 0.150.0, allowing attackers with a valid Azure access token to authenticate to any OpenTelemetry receiver that uses `auth: azure_auth` due to improper JWT validation.

opentelemetry-collector-contrib +3 authentication-bypass opentelemetry azure jwt
2r 1t
high advisory

Entra ID Excessive Account Lockouts Detected

A high volume of failed Microsoft Entra ID sign-in attempts resulting in account lockouts indicates potential brute-force attacks, such as password spraying or credential stuffing, targeting user accounts.

Entra ID azure entra_id credential_access brute_force
2r 3t
high advisory

Azure Monitor Agent Improper Input Validation Vulnerability (CVE-2026-32168)

CVE-2026-32168 is an improper input validation vulnerability in Azure Monitor Agent that allows a locally authorized attacker to elevate privileges.

azure privilege escalation vulnerability cve-2026-32168
2r 1t 1c
high advisory

Azure Monitor Agent Deserialization Vulnerability (CVE-2026-32192) Allows Local Privilege Escalation

CVE-2026-32192 allows a locally authorized attacker to escalate privileges on a host running the Azure Monitor Agent via deserialization of untrusted data.

cve-2026-32192 azure monitor agent privilege escalation deserialization
2r 1t 1c
medium advisory

Entra ID ADRS Token Request by Microsoft Authentication Broker

Detects suspicious OAuth 2.0 token requests where the Microsoft Authentication Broker requests access to the Device Registration Service on behalf of a user principal, potentially indicating an attempt to abuse device registration for unauthorized persistence.

azure entra_id persistence oauth
2r 2t 1i
medium threat

Azure Service Principal Sign-In Followed by Arc Cluster Credential Access

Detects a service principal authenticating to Azure AD followed by listing credentials for an Azure Arc-connected Kubernetes cluster, indicating potential adversary activity with stolen service principal secrets to establish a proxy tunnel into Kubernetes clusters.

exploited azure azure-arc credential-access initial-access
2r 3t
critical advisory

CVE-2026-33105 - Microsoft Azure Kubernetes Service Privilege Escalation

CVE-2026-33105 is a critical vulnerability in Microsoft Azure Kubernetes Service that allows an unauthorized attacker to elevate privileges over a network due to improper authorization.

azure kubernetes privilege-escalation
2r 1t 1c
critical advisory

Azure Databricks SSRF Vulnerability (CVE-2026-33107) Allows Privilege Escalation

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-33107, exists in Azure Databricks, allowing an unauthorized attacker to elevate privileges over a network.

ssrf azure databricks privilege-escalation
2r 1t 1c
high advisory

Azure SRE Agent Improper Authentication Vulnerability (CVE-2026-32173)

An improper authentication vulnerability (CVE-2026-32173) in the Azure SRE Agent allows an unauthorized attacker to disclose sensitive information over the network, potentially leading to data breaches or further compromise.

azure sre authentication information-disclosure
2r 1t 1c
critical advisory

Azure MCP Server Missing Authentication Vulnerability (CVE-2026-32211)

CVE-2026-32211 is a critical vulnerability in Azure MCP Server due to missing authentication for a critical function, allowing an unauthorized attacker to disclose information over the network.

azure information-disclosure vulnerability
2r 1t 1c
low advisory

Unusual City for Azure Activity Logs Event

A machine learning job detected Azure Activity Logs activity that, while not inherently suspicious or abnormal, is sourcing from a geolocation (city) that is unusual for the event action, indicating potential compromised credentials.

azure cloud anomaly-detection
2r 3t
high advisory

Entra ID Federated Identity Credential Issuer Modified

Modification of the issuer URL of a federated identity credential in Entra ID can allow an attacker to authenticate as the application's service principal, granting persistent access to Azure resources by pointing to an attacker-controlled identity provider and bypassing normal authentication.

azure entra_id federated_identity persistence privilege_escalation
2r 2t
medium advisory

Azure Service Principal Sign-In Followed by Arc Cluster Credential Access

Detects a service principal authenticating to Microsoft Entra ID and then listing credentials for an Azure Arc-connected Kubernetes cluster within a short time window, indicating potential unauthorized access to Kubernetes clusters via stolen service principal secrets.

azure azure-arc credential-access initial-access
2r 2t
medium advisory

Azure Entra ID MFA TOTP Brute Force Attempted

Identifies brute force attempts against Azure Entra multi-factor authentication (MFA) Time-based One-Time Password (TOTP) verification codes, characterized by high-frequency failed attempts for a single user across numerous distinct sessions, potentially indicating programmatic attempts to bypass MFA.

Azure Entra ID azure entra_id mfa totp brute_force credential_access
3r 1t
medium advisory

Entra ID Sign-in Brute Force Attempt Against Microsoft 365

A high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.

Microsoft 365 +4 azure entra-id microsoft-365 brute-force credential-access
2r 1t
medium advisory

Entra ID Device Code Authentication Abuse via Malicious Broker Client

Adversaries are abusing Entra ID device code authentication using a malicious broker client to bypass MFA and gain unauthorized access to Azure resources by compromising Primary Refresh Tokens (PRTs).

Azure +1 entra-id device-code-authentication prt
2r 2t 4i
medium advisory

Entra ID OAuth Device Code Grant by Unusual User

An attacker uses device code authentication in Entra ID to phish users and steal access tokens, leading to unauthorized access and potential defense evasion.

Entra ID azure entra-id device-code phishing
2r 3t
medium advisory

Unauthorized Modification of Azure Conditional Access Policy

An unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.

Azure Active Directory azure conditional-access policy-modification attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 +1
2r 2t
high advisory

Azure Compute Restore Point Collections Mass Deletion

A single user deleting multiple Azure Restore Point Collections in a short time period can indicate a ransomware attack or destructive operation, preventing victim recovery by inhibiting system recovery.

Azure cloud ransomware impact
2r 1t
medium advisory

Azure AD Certificate-Based Authentication Enabled

Enabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.

Azure Active Directory azure certificate-based-authentication persistence privilege-escalation
2r 1t
high advisory

Azure Sign-In Log Bypass Vulnerabilities

A recently disclosed vulnerability allows attackers to bypass Azure sign-in logs, potentially masking malicious activity within cloud environments.

Azure sign-in bypass cloud security vulnerability
2r 2t 1i
high advisory

Azure Identity Protection Suspicious Browser Activity

A suspicious browser activity alert indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser, potentially indicating compromised credentials or other malicious activity.

Azure identity-protection suspicious-browser
2r 6t
medium advisory

Azure Firewall Rule Collection Modification or Deletion

An attacker may modify or delete Azure Firewall rule collections (Application, NAT, and Network) to impair defenses and potentially enable malicious traffic.

Azure Firewall azure firewall defense-impairment
2r 2t
low advisory

Entra ID Service Principal Creation for Persistence

An adversary may create a new service principal in Microsoft Entra ID to establish persistence and potentially impersonate legitimate services or applications, blending in with normal activity.

Microsoft Entra ID +1 azure entra_id service_principal persistence
2r 1t
high advisory

Entra ID Privilege Escalation to User Access Administrator

A user has elevated their access to User Access Administrator for their Azure Resources, potentially leading to privilege escalation and unauthorized access; this activity is flagged only if the user hasn't performed it in the last 14 days.

Microsoft Azure +1 azure entra_id privilege_escalation
2r 2t
high advisory

Entra ID Concurrent Sign-in with Suspicious Properties

This rule identifies concurrent Azure sign-in events for the same user from multiple sources, where at least one authentication event exhibits suspicious properties associated with DeviceCode and OAuth phishing, potentially indicating refresh token theft.

Azure Entra ID +2 azure entra-id credential-access phishing
2r 4t
high advisory

Azure AD Sign-In with Unfamiliar Properties

This alert detects Azure AD sign-ins with properties unfamiliar to the user, indicating potential account compromise or unauthorized access.

Azure Active Directory azure identity_protection sign-in account_compromise risk_detection
2r 4t
low advisory

Entra ID External Guest User Invitation

Detection of external guest user invitations in Entra ID, which can be abused for unauthorized access and persistence by creating overlooked accounts.

Entra ID +1 cloud azure initial-access persistence
2r 2t
high threat

Azure AD FullAccessAsApp Permission Assignment

Detection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.

Office 365 Exchange Online +1 NOBELIUM Group azure azuread office365 persistence nobelium
2r 2t
high advisory

Azure AD Device Registration Policy Changes Detected

Monitoring changes to the device registration policy can detect potential privilege escalation or defense impairment attempts by malicious actors aiming to weaken security controls related to device management in Azure Active Directory.

Azure Active Directory azure device-registration policy-change
2r 1t
low advisory

Azure Automation Runbook Created or Modified

An adversary may create or modify an Azure Automation runbook to execute malicious code and maintain persistence in their target's environment, detected through Azure activity logs.

Azure Automation azure automation runbook execution persistence
2r 2t
high advisory

Multiple Entra ID Protection Alerts Indicate Potential Account Compromise

Multiple Microsoft Entra ID Protection alerts associated with a single user in a short timeframe may indicate an ongoing attack or compromised account, stemming from suspicious sign-in activity such as anomalous IP addresses or risky sign-ins.

Microsoft Entra ID cloud azure entra_id identity_protection
2r 3t
medium advisory

Azure Compute VM Command Execution Detected

Successful execution of commands on Azure Virtual Machines, specifically the MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION operation, may indicate unauthorized activity or lateral movement attempts.

Azure Virtual Machines +1 azure execution cloud vm
2r 1t
medium advisory

Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service

A threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.

Azure Active Directory +1 cloud azure adfs defense-impairment
2r 1t
high advisory

Entra ID Protection Alert Followed by Device Registration

Detection of a Microsoft Entra ID protection alert followed by a new device registration attempt by the same user, potentially indicating account compromise and unauthorized device registration for persistence.

Microsoft Entra ID +1 azure entra_id persistence device_registration
2r 2t
medium advisory

Azure Blob Storage Permissions Modified for Defense Evasion

An adversary may modify Azure Blob Storage permissions to weaken security controls, leading to potential data exposure or loss; this rule detects such modifications by monitoring Azure activity logs for specific operations related to permission changes on blobs.

Azure Blob Storage azure cloud defense_evasion
2r 1t
medium advisory

Azure Authentication Method Change Detection

An attacker may add an authentication method to a compromised Azure account for persistent access, which can be detected by monitoring changes to authentication methods in Azure audit logs.

Azure persistence privilege-escalation
2r 3t
high advisory

Azure Privileged Identity Management (PIM) Invalid License Detection

Detection of unauthorized access or privilege escalation attempts within Azure environments due to invalid or missing Microsoft Entra Premium P2 or Microsoft Entra ID Governance licenses for Privileged Identity Management (PIM).

Azure pim privileged-identity-management invalid-license
2r 1t
medium threat

Entra ID Unusual ROPC Login Attempt

Detects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.

exploited Microsoft Entra ID azure entra-id ropc initial-access
2r 2t
medium advisory

Azure VNet Full Network Packet Capture Enabled

Detection of Azure Network Watcher's Packet Capture feature being enabled, potentially indicating malicious network sniffing for credential access and discovery of sensitive data in unencrypted traffic.

Azure +1 network-sniffing credential-access
3r 2t
low advisory

Azure Automation Runbook Deleted

Detection of Azure Automation runbook deletion, potentially indicating defense evasion or disruption of automated business processes by an adversary removing malicious or critical runbooks.

Azure Automation cloud azure defense-evasion impact
2r 2t
medium advisory

Azure Kubernetes Events Deleted

Adversaries may delete events in Azure Kubernetes to evade detection, which this rule detects via the MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EVENTS.K8S.IO/EVENTS/DELETE operation.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 1t
high advisory

Entra ID Protection Detects User Risk

Entra ID Protection detects user risk activity such as anonymized IP addresses, unlikely travel, password spray, and other suspicious behaviors indicating potential initial access attempts and compromised accounts within cloud environments.

Entra ID azure entra-id risk-detection initial-access
3r 4t
medium advisory

Azure Storage Account Deletion Detection

This brief detects the deletion of Azure Storage Accounts which can indicate malicious activity like data destruction, denial of service, or covering tracks after data exfiltration by adversaries.

Azure Storage Account azure storage deletion impact
2r 2t
medium advisory

Microsoft Graph API Email Access by Unusual Client and User

Detects anomalous access to email resources via Microsoft Graph API, potentially indicating a compromised OAuth refresh token or Primary Refresh Token (PRT) being used by an attacker.

Microsoft 365 +1 azure graphapi email oauth credentialtheft
2r 1t
medium threat

Unusual Azure Storage Account Key Access by Privileged User

Detects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.

Microsoft Azure +1 Storm-0501 azure storage account credential access ransomware
2r 2t
medium advisory

Unauthorized Removal of Azure Conditional Access Policy

An unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.

Azure Active Directory azure conditional-access privilege-escalation credential-access persistence defense-impairment
2r 3t
medium advisory

Entra ID Service Principal Sign-in from Unusual ASN

Detection of Entra ID service principal sign-ins originating from a previously unseen combination of workload identity and source autonomous system number (ASN), potentially indicating compromised credentials or malicious activity.

Entra ID azure entra-id service-principal initial-access
2r 2t
low advisory

Azure Front Door WAF Policy Deletion Detection

Detection of Azure Front Door Web Application Firewall (WAF) policy deletion, which can indicate an attacker's attempt to evade defenses by removing a security layer protecting web applications.

Azure Front Door WAF azure waf defense_evasion
2r 1t
medium advisory

Azure Resource Group Deletion Detected

This rule detects the deletion of a resource group in Azure. Deleting a resource group permanently removes all resources within it, which adversaries may use to evade defenses or destroy data.

Microsoft Azure azure resource-group deletion impact
2r 5t
high advisory

Azure Service Principal Authentication from Multiple Countries

Detects Azure service principals authenticating from multiple countries within a short time, indicating potentially compromised credentials being used from different geographic locations.

Azure +1 cloud service principal initial access credential compromise
2r 1t
medium advisory

Azure Diagnostic Settings Deletion for Defense Evasion

Adversaries may delete Azure diagnostic settings to evade defenses by hindering detection and analysis, which this detection identifies by monitoring Azure activity logs for successful deletion operations.

Azure defense_evasion cloud
2r 2t
high advisory

Azure AD Service Principal Created

The creation of a Service Principal in an Azure AD environment is detected, which can be used by adversaries to establish persistence and bypass multi-factor authentication.

Azure Active Directory azure cloud persistence service-principal
2r 1t
medium advisory

Entra ID MFA Disabled for User

Detection of multi-factor authentication (MFA) being disabled for an Entra ID user account, potentially weakening account security and leading to compromise.

Entra ID azure entra_id mfa persistence credential_access defense_evasion
2r 3t
medium advisory

Azure Event Hub Deletion for Defense Evasion

Detection of Azure Event Hub deletion, indicative of defense evasion by adversaries seeking to disrupt data flow and evade detection by erasing log evidence.

Azure Event Hub cloud azure defense-evasion
2r 2t
medium advisory

Suspicious Azure Automation Account Creation

An adversary may create an Azure Automation account to maintain persistence in the target environment by automating malicious tasks.

Azure Automation azure persistence cloud
2r 2t
low advisory

Azure Storage Account Key Regeneration

Detection of Azure Storage Account key regeneration events, which can signify potential credential access or persistence attempts by adversaries aiming to gain unauthorized access or disrupt services.

Azure Storage Account azure credential-access storage-account
2r 2t
high advisory

Entra ID: Global Administrator Role Assigned to PIM User

An adversary may add an account to the Global Administrator role within Azure AD Privileged Identity Management (PIM) to establish persistence and gain privileged access.

Azure Active Directory +1 azure entra_id persistence privilege_escalation
2r 2t
high advisory

Azure PIM Account Stale Sign-in Alert

Detection of stale accounts in Azure Privileged Identity Management (PIM) through the 'staleSignInAlertIncident' event, indicating potential compromised or unused privileged accounts.

Azure Privileged Identity Management azure pim stale_account
2r 1t
medium advisory

Azure Firewall Modification or Deletion Detected

An Azure firewall was created, modified, or deleted, potentially indicating malicious activity aimed at impairing network defenses.

Azure firewall defense-evasion
2r 1t
medium advisory

Azure AD Bitlocker Key Retrieval

An adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.

Azure Active Directory azure bitlocker key-retrieval persistence privilege-escalation
2r 3t
high advisory

Azure PIM Elevation Approved or Denied

Detection of Azure Privileged Identity Management (PIM) elevation approvals or denials, which, if unexpected, may indicate unauthorized privilege escalation or malicious activity within an Azure environment.

Azure pim privilege-escalation persistence
2r 3t
medium advisory

Entra ID Illicit Consent Grant via Registered Application

Attackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.

Microsoft Entra ID azure entra-id oauth illicit-consent
2r 3t
high advisory

Azure PIM Role Activation Without MFA

Detection of Azure Privileged Identity Management (PIM) roles being activated without requiring multi-factor authentication, potentially leading to unauthorized privilege escalation and persistence.

Azure pim mfa privilege-escalation
2r 1t
high advisory

M365 or Entra ID Identity Sign-in from a Suspicious Source

Correlates successful Entra ID or Microsoft 365 sign-in events with network security alerts based on the source IP address, indicating potential initial access from suspicious sources.

Microsoft 365 +1 cloud azure m365 entra-id initial-access
2r 1t
high advisory

Azure AD Account Concurrent Sessions from Different IPs

Detection of Azure AD accounts with concurrent sessions originating from multiple unique IP addresses within a 5-minute window, potentially indicating session hijacking and unauthorized access.

Azure Active Directory azure azuread compromised-account
2r 1t
high advisory

Detect Application AppID URI Configuration Changes in Azure

Detection of configuration changes to an application's AppID URI in Azure, potentially indicating malicious activity related to initial access, persistence, credential access, privilege escalation, or stealth.

Azure Active Directory azure appid uri application serviceprincipal credential-access privilege-escalation
2r 2t
medium advisory

Malicious Azure Kubernetes Admission Controller Configuration

An adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.

Azure Kubernetes Service +1 azure kubernetes admission-controller persistence privilege-escalation credential-access
2r 4t
medium advisory

Detection of Azure Application Deletion

This alert identifies when an application is deleted within an Azure environment, which could indicate malicious activity or unintended misconfiguration leading to service disruption.

Azure application deletion impact t1489
2r 1t
medium advisory

Entra ID User Sign-in with Unusual Client Application

Adversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.

Entra ID +1 azure entra-id initial-access oauth
2r 3t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
medium advisory

Azure Network Watcher Deletion for Defense Evasion

An adversary may delete an Azure Network Watcher to impair defenses by disabling network monitoring and logging capabilities, as detected by monitoring Azure activity logs for Network Watcher deletion events.

Azure Network Watcher cloud azure defense-evasion
2r 2t
medium advisory

Azure Key Vault Excessive Secret or Key Retrieval

Detects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.

Azure Key Vault azure keyvault credential-access threat-detection
2r 2t
medium advisory

Azure AD User Password Reset Detection

Detects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.

Azure Active Directory azure password-reset privilege-escalation initial-access persistence credential-access stealth
2r 1t
medium advisory

Azure AD Guest to Member User Type Conversion

An adversary may convert a guest user account to a member account in Azure Active Directory to elevate privileges and gain persistent access to resources.

Azure Active Directory privilege-escalation azure entra guest-account
2r 1t
high advisory

Excessive Global Administrator Accounts in Azure PIM

Detection of an excessive number of Global Administrator accounts assigned within an Azure tenant, indicating potential privilege escalation or compromised accounts.

Azure pim global_admin privilege_escalation
2r 3t
medium advisory

Entra ID Service Principal Sign-in from Unusual Source ASN

Detects Entra ID service principal sign-ins from a source ASN that is unusual based on a history window, potentially indicating compromised credentials or a rogue application.

Microsoft Entra ID azure entra_id service_principal initial_access
2r 2t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

Detects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.

Microsoft Entra ID +2 azure entra_id oauth graph_api token_replay session_hijacking initial_access defense_evasion
2r 2t
high advisory

Detection of Privileged Identity Management (PIM) Settings Modifications

Detects unauthorized or malicious modifications to Privileged Identity Management (PIM) settings within Azure environments, potentially leading to privilege escalation, persistence, and stealthy access by attackers.

Azure Active Directory azure pim privilege-escalation persistence
2r 4t
medium advisory

Detection of Azure Service Principal Creation

Detects the creation of a service principal in Azure, which could indicate potential attacker activity for lateral movement or persistence.

Azure cloud service principal persistence lateral movement
3r 1t
medium advisory

Azure AD Hybrid Health AD FS Service Deletion for Defense Evasion

Threat actors may delete Azure AD Hybrid Health AD FS service instances after using them to spoof AD FS signing logs for defense evasion.

Azure Active Directory attack.defense-impairment attack.t1578.003 azure
2r 1t
medium advisory

Azure Service Principal Removal Detection

Detection of a service principal removal in Azure, potentially indicating malicious activity or an attempt to remove evidence of a compromise.

Azure service principal stealth cloud
2r 1t
high advisory

Azure Application URI Configuration Modification

Detection of Azure application URI modifications that can be indicative of malicious activity, such as using dangling URIs, non-HTTPS URIs, wildcard domains, or URIs pointing to uncontrolled domains, potentially leading to initial access, stealth, persistence, credential access, and privilege escalation.

Azure Active Directory cloud azure application uri modification persistence credential-access privilege-escalation
3r 4t
medium advisory

User Removed from Group with Conditional Access Policy Modification Access

An attacker removes a user from a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, persistence, or defense evasion.

Azure Active Directory azure conditional-access privilege-escalation
2r 3t
medium advisory

Unusual Source IP for Azure Arc Cluster Credential Access

Detects when a service principal or user performs an Azure Arc cluster credential listing operation from a source IP not previously associated with that identity, potentially indicating compromised credentials.

Azure Arc +1 azure azure-arc credential-access
2r 2t
medium advisory

Unused Privileged Identity Management (PIM) Roles in Azure

Detection of assigned but unused privileged roles in Azure's Privileged Identity Management (PIM) service, indicating potential misconfiguration, license overuse, or dormant privileged access that could be exploited.

Azure pim privileged-identity-management role-based-access-control initial-access privilege-escalation
2r 1t
medium advisory

Unauthorized Guest User Invitation Attempt in Azure

Detection of a failed attempt to invite an external guest user by an Azure user lacking the necessary permissions, potentially indicating privilege escalation or malicious insider activity.

Azure privilege-escalation initial-access persistence stealth
2r 1t
medium advisory

Unauthorized Conditional Access Policy Creation in Azure AD

An unauthorized actor created a new Conditional Access policy in Azure AD, potentially leading to privilege escalation and unauthorized access.

Azure Active Directory azure conditional-access privilege-escalation attack.privilege-escalation attack.t1548
2r 1t
medium advisory

TeamFiltration Tool User-Agent Detected in Entra ID Sign-ins

The TeamFiltration tool, used for Entra ID and Microsoft 365 enumeration and password spraying, is detected via specific user-agent strings in sign-in logs.

Microsoft Entra ID +2 azure o365 teamfiltration credential-access
2r 7t 1i
high advisory

Suspicious Azure PowerShell Module Installation via PowerShell Script

Detection of Azure AD and cloud management modules installation via PowerShell Script Block Logging, potentially indicating reconnaissance, privilege escalation, or persistence operations by adversaries.

Azure Active Directory +4 azure powershell module-installation privilege-escalation persistence
2r 5t
high advisory

Privileged Identity Management (PIM) Alerting Disabled

An adversary disables Privileged Identity Management (PIM) alerts in Azure to evade detection and maintain persistent access with escalated privileges.

Azure pim alerts privilege-escalation persistence
2r 1t
high advisory

Office 365 MFA Bypass via Trusted IP Modification

An adversary modifies the trusted IP list in Office 365 to bypass multi-factor authentication (MFA) and gain unauthorized access to accounts.

Office 365 azure o365 mfa bypass defense-evasion
2r 1t
medium advisory

Mass Azure Compute Snapshot Deletion

The rule detects mass deletion of Azure disk snapshots, which could indicate an adversary attempting to inhibit system recovery capabilities, destroy backup evidence, or prepare for a ransomware attack.

Azure snapshot data-destruction impact
2r 2t
high threat

Malicious Use of Microsoft Intune Device Management Configuration Policies

Attackers can abuse Microsoft Intune device management configuration policies, typically used for legitimate remote device management, to disable defenses and evade detection on managed devices.

exploited Intune azure device_management policy defense_evasion
2r 3t
high advisory

Frequent Azure PIM Role Activation Detected

Detection of frequent role activation in Azure Privileged Identity Management (PIM) by the same user may indicate potential privilege escalation or account compromise.

Azure pim role-activation privilege-escalation
2r 3t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t
medium advisory

Entra ID Service Principal Credentials Created by Unusual User

Anomalous addition of credentials to an Entra ID service principal by a user not typically performing this action can indicate potential persistence and privilege escalation by an attacker.

Entra ID +1 azure entra_id service_principal persistence privilege_escalation
2r 2t
critical advisory

Entra ID Protection Admin Confirmed Compromise

An administrator's confirmation of a compromised user or sign-in in Microsoft Entra ID Protection signals a high-confidence account compromise requiring immediate investigation and remediation.

Microsoft Entra ID azure entra_id identity_protection compromised_account
3r 3t
high advisory

Entra ID Protection - Sign-in Risk Detection

This brief covers detection of sign-in risk events identified by Microsoft Entra ID Protection, including anonymized IP addresses, unlikely travel, and password spray attacks, which can indicate compromised accounts or malicious activity.

Microsoft Entra ID +1 azure entra-id identity-protection sign-in-risk initial-access
3r 4t
medium advisory

Entra ID Privileged Identity Management (PIM) Role Modified

Attackers may modify Entra ID Privileged Identity Management (PIM) roles to persist in the environment and weaken security controls, potentially leading to privilege escalation and unauthorized access.

Entra ID Privileged Identity Management azure persistence privileged-identity-management
2r 3t
low advisory

Entra ID PowerShell Sign-in

Detection of successful sign-ins using the Azure Active Directory PowerShell module to identify potentially unauthorized administrative actions in Entra ID.

Entra ID +1 azure entra-id powershell initial-access
2r 2t
medium advisory

Entra ID OAuth User Impersonation Scope for Unusual User and Client

Adversaries may abuse the user_impersonation OAuth scope in Entra ID to gain unauthorized access to user accounts, especially when combined with single-factor authentication and unbound sign-in sessions, potentially indicating account compromise for users not seen in the last 10 days.

Entra ID azure oauth user_impersonation initial_access defense_evasion
2r 3t
medium advisory

Entra ID External Authentication Methods (EAM) Modified

Modification of Entra ID external authentication methods (EAM) via the Microsoft Graph API can allow attackers to bypass multi-factor authentication (MFA) and establish persistence or gain unauthorized access via bring-your-own IdP (BYOIDP) methods.

Entra ID azure entra-id persistence authentication
2r 2t
high advisory

Entra ID Excessive Account Lockouts Detected

Adversaries may attempt to brute-force user accounts using password spraying or credential stuffing, leading to account lockouts by Entra ID Smart Lockout policies, which this rule detects by identifying a high count of failed Microsoft Entra ID sign-in attempts due to account lockouts (error code 50053).

Entra ID cloud credential-access azure entra-id
2r 3t
high advisory

Entra ID Domain Federation Configuration Change

Adversaries with Global Administrator or Domain Administrator privileges may add a custom domain, verify ownership, and configure it to federate authentication with an attacker-controlled identity provider, allowing token forgery and bypassing MFA and conditional access policies for persistent, stealthy access to victim tenants.

Entra ID azure entra-id domain-federation privilege-escalation
3r 4t
low advisory

Entra ID Custom Domain Added or Verified

Detection of custom domain additions or verifications in Entra ID, a precursor to potentially malicious domain federation for Golden SAML attacks.

Microsoft Entra ID azure entra-id domain-federation golden-saml
2r 1t
medium advisory

Detection of Privileged Account Creation in Azure

Detects the creation of new privileged accounts in Azure environments, potentially indicating initial access, persistence, privilege escalation, or stealth activities by malicious actors.

Azure privileged-account initial-access persistence privilege-escalation
2r 3t
low advisory

Azure VNet Firewall Policy Deletion for Defense Evasion

An adversary may delete a firewall policy in Azure in an attempt to evade defenses, which can be detected by monitoring Azure activity logs for successful deletion operations of firewall policies.

Azure Firewall azure cloud defense-evasion
2r 1t
high advisory

Azure Subscription Permission Elevation via Activity Logs

An attacker elevates their Azure subscription permissions to manage all subscriptions, potentially leading to unauthorized access and control over the environment.

Azure privilege-escalation persistence initial-access stealth
2r 1t
medium advisory

Azure Storage Account Blob Public Access Enabled

Detection of Azure Storage Account Blob public access being enabled, potentially allowing external access to blob containers for data exfiltration, as abused by threat actors modifying storage account settings.

Azure Storage Account azure storage data_exfiltration cloud_security
2r 1t
high advisory

Azure Runbook Webhook Creation Detected

Detection of a new Azure Automation Runbook Webhook creation, potentially leading to unauthorized access and control over Azure resources by enabling unauthenticated URL triggers.

Azure Automation azure runbook webhook persistence
2r 1t
high advisory

Azure RBAC Built-In Administrator Role Assignment

Detection of a user being assigned a built-in administrator role in Azure RBAC, which can be abused for privilege escalation, lateral movement, or persistence.

Azure rbac privilege-escalation persistence
2r 2t
medium advisory

Azure Owner Removed from Application or Service Principal

An adversary may remove an owner from an Azure application or service principal to weaken access controls, persist in the environment, or escalate privileges.

Azure attack.stealth
2r 1t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Events Deleted

Adversaries may delete Kubernetes events in Azure Kubernetes Services (AKS) to evade detection by removing logs of state changes, container creations, image pulls, and pod scheduling.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 2t
medium advisory

Azure Key Vault Unusual Secret Key Usage

Detects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.

Azure Key Vault azure keyvault credential-access
2r 1t
low advisory

Azure Key Vault Modified by Unusual User

This rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.

Azure Key Vault azure keyvault configuration-audit impact defense-evasion
2r 2t
medium advisory

Azure Event Hub Authorization Rule Created or Updated

Creation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.

Azure Event Hub cloud azure persistence account-manipulation
2r 2t
medium advisory

Azure Compute Restore Point Collection Deleted by Unusual User

The deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.

Azure Compute cloud azure impact
2r 1t
high advisory

Azure Automation Runbook Creation for Persistence

This analytic detects the creation of a new Azure Automation Runbook within an Azure tenant using Azure Audit events, which adversaries with privileged access can abuse to maintain persistence, escalate privileges, or execute malicious code, potentially leading to unauthorized actions and compromise of the Azure environment.

Azure Automation azure persistence automation cloud
2r 1t
high advisory

Azure Automation Account Creation

Detect the creation of new Azure Automation accounts, which can be used by attackers for persistence, privilege escalation, and malicious runbook execution within Azure environments.

Azure Automation azure automation persistence
2r 1t
high threat

Azure AD Tenant Wide Admin Consent Granted

Detection of admin consent granted to an application within an Azure AD tenant which could lead to data exfiltration and persistence.

Azure AD NOBELIUM Group azure persistence cloud
2r 1t
high advisory

Azure AD Service Principal Authentication Monitoring

This analytic identifies authentication events of service principals in Azure Active Directory, monitoring sign-in frequency, timing, source IPs, and accessed resources to detect potential anomalies indicative of compromised credentials or malicious activities.

Azure Active Directory azure azuread serviceprincipal accounttakeover
2r 1t
medium advisory

Azure AD Risk-Based Consent Disabled

The analytic detects when the risk-based step-up consent security setting in Azure AD is disabled by monitoring Azure Active Directory logs for the 'Update authorization policy' operation and changes to the 'AllowUserConsentForRiskyApps' setting, potentially exposing organizations to OAuth phishing attacks.

Azure Active Directory azure oauth consent phishing
2r 1t
high advisory

Azure AD Privileged Authentication Administrator Role Assignment Detected

An adversary assigning the 'Privileged Authentication Administrator' role to an account in Azure AD could abuse the new privileges to reset authentication methods for privileged accounts, leading to account takeover and privilege escalation.

Azure Active Directory azure azuread privilege-escalation role-assignment
2r 2t
high advisory

Azure AD PIM Role Assignment Detected

Detection of an Azure AD Privileged Identity Management (PIM) role assignment, specifically identifying when a user is added as an eligible member, which could lead to unauthorized access and privilege escalation.

Azure Active Directory azure pim role assignment privilege escalation
2r 2t
high advisory

Azure AD PIM Role Activation Detection

Detection of Azure AD Privileged Identity Management (PIM) role activation, indicating potential privilege escalation or unauthorized access.

Azure Active Directory +1 azure pim privilege-escalation persistence
2r 2t
high advisory

Azure AD OAuth Application Consent Granted by User

Detection of Azure AD OAuth application consent granted by a user, potentially leading to unauthorized access and data compromise.

Azure AD azure oauth consent application t1528
2r 2t
high advisory

Azure AD New MFA Method Registered For User

An adversary may register a new MFA method in Azure AD on a compromised account to maintain persistence and bypass existing security controls.

Azure AD azure mfa persistence account-takeover
2r 2t
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
high advisory

Azure AD Brute Force Attack Detected

An IP address with 20 or more failed authentication attempts to an Azure AD tenant within 10 minutes, indicative of a brute force attack targeting user accounts in Azure Active Directory.

Azure Active Directory azure brute-force credential-access
2r 2t
medium advisory

Unusual Microsoft Graph Email Access via OAuth Application

An adversary might use a phished OAuth refresh token or Primary Refresh Token (PRT) with a first-party application to access email resources via Microsoft Graph API, particularly focusing on unusual application and user combinations.

Microsoft Graph API +2 azure graphapi oauth email
2r 2t
high advisory

Entra ID High Risk Sign-in Detected

This rule detects high-risk sign-ins in Microsoft Entra ID, as identified by Identity Protection, where the sign-in is flagged with a risk level of `high` during the authentication process, indicating a strong likelihood of account compromise.

Microsoft Entra ID azure entra_id initial_access high_risk_signin
2r 1t
medium advisory

Entra ID Application Credential Modification

An adversary may add unauthorized credentials to an Azure application, enabling persistent access, evading defenses, and escalating privileges by modifying certificates or secrets.

Azure +1 persistence entra_id account_manipulation
3r 2t
medium advisory

Azure AD User Consent Denied for OAuth Application

This analytic identifies instances where a user has denied consent to an OAuth application seeking permissions within the Azure AD environment, potentially indicating malicious OAuth application activity.

Azure AD azure oauth consent-phishing credential-access
2r 1t
high advisory

Azure AD Account Authentication from Multiple IPs

An Azure AD account successfully authenticating from multiple unique IP addresses within a 30-minute window, detected using Azure AD SignInLogs, which may indicate compromised credentials and unauthorized access to corporate resources.

Azure Active Directory azure credential-access compromised-account
1r 3t
high advisory

Azure Identity Protection Atypical Travel Anomaly

The Atypical Travel detection in Azure Identity Protection identifies potentially compromised user accounts by detecting geographically improbable sign-in activity, indicative of account compromise or misuse.

Azure Active Directory +1 azure identity-protection atypical-travel account-compromise credential-theft
2r 1t
medium advisory

Entra ID User Sign-in with Unusual Authentication Type

Detects rare authentication requirements for Azure Entra ID principal users, potentially indicating an adversary attempting to bypass conditional access policies and MFA using stolen credentials.

Azure Entra ID azure entra_id initial_access credential_access
2r 4t
high advisory

Azure AD Privileged Role Assignment

Detection of a user being added to a privileged role in Azure AD, potentially indicating privilege escalation or persistence by an attacker.

Azure Active Directory azure privileged-access role-assignment
2r 2t
medium advisory

Azure Storage Account Data Exfiltration via AzCopy and SAS Token Abuse

Successful GetBlob operations on Azure Storage Accounts using the AzCopy user agent with SAS token authentication can indicate data exfiltration by adversaries abusing compromised SAS tokens.

Azure Storage azure exfiltration cloud-storage azcopy
2r 2t
low advisory

Azure Kubernetes Services (AKS) Kubernetes Rolebindings Created

The creation of role binding or cluster role bindings in Azure Kubernetes Services (AKS) can indicate privilege escalation by an adversary creating a binding to the cluster-admin ClusterRole or other high-privilege roles.

Azure Kubernetes Services cloud azure kubernetes privilege-escalation
2r 3t
low advisory

Microsoft Graph API Request User Impersonation by Unusual Client

Detection of the first-time use of a Microsoft Graph API request by a specific client application ID, user principal object ID, and tenant ID, potentially indicating unauthorized access via phishing, token theft, or OAuth abuse.

Microsoft Graph API +1 cloud azure graphapi initial_access
2r 2t
low advisory

Entra ID User Sign-in with Unusual Non-Managed Device

Detects Microsoft Entra ID user sign-ins from devices not typically used or managed, indicating potential account compromise or unauthorized access via device registration for persistence.

Microsoft Entra ID azure entra-id persistence device-registration
2r 2t
medium advisory

Entra ID User Added as Service Principal Owner for Persistence

An adversary may add a user account as an owner for an Azure service principal to define what an application can do in the Azure AD tenant, potentially leading to persistence and privilege escalation.

Entra ID +1 azure service-principal persistence privilege-escalation
2r 4t
medium advisory

Entra ID High Risk User Sign-in Detection

This rule identifies high-risk Azure Active Directory (AD) sign-ins by leveraging Microsoft Identity Protection machine learning and heuristics, specifically focusing on events with a risk state of `confirmedCompromised` or `atRisk`, indicating potential initial access attempts.

Azure Active Directory azure initial-access cloud
2r 1t
medium advisory

Entra ID Conditional Access Policy (CAP) Modified

An adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.

Microsoft Entra ID azure entra_id conditional_access_policy persistence defense_evasion
2r 2t
high advisory

Azure PIM - Role Assignment Outside of Privileged Identity Management

Detection of privilege role assignments outside of Azure Privileged Identity Management (PIM) can indicate potential attacker activity related to initial access, stealth, persistence, or privilege escalation within the Azure environment.

Azure Active Directory azure pim role-assignment attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation
2r 4t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Pod Deletion

The deletion of Azure Kubernetes Pods can indicate malicious activity aimed at disrupting the environment's normal behavior.

Azure Kubernetes Services azure kubernetes impact cloud
2r 2t
medium advisory

Azure Domain Federation Settings Modified

An attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.

Azure Active Directory azure federation privilege-escalation persistence initial-access
2r 2t
medium advisory

Azure Blob Storage Container Access Level Modified

The rule identifies modifications to Azure Blob Storage container access levels, which, if unauthorized, may lead to data exposure and exfiltration.

Azure Blob Storage cloud azure asset-visibility discovery
2r 3t
low advisory

Azure Automation Webhook Created for Persistence

Adversaries may create Azure Automation webhooks to trigger malicious runbooks for persistence in cloud environments.

Azure Automation azure persistence cloud
2r 2t
low advisory

Azure Alert Suppression Rule Created or Modified

Detection of Azure alert suppression rule creation or modification events, which can be used by attackers to disable security alerts and evade detection.

Azure +1 defense-evasion cloud
2r 1t
high advisory

Azure AD Service Principal Privilege Escalation

An Azure Active Directory (Azure AD) Service Principal elevates its own privileges by adding itself to a new application role assignment, potentially leading to unauthorized access and control within the Azure environment.

Azure AD azure azure-ad service-principal privilege-escalation
2r 1t
high threat

Azure AD Service Principal Owner Added

Detection of a new owner being added to an Azure AD Service Principal, potentially indicating persistence or privilege escalation by an attacker exploiting the lack of multi-factor authentication on service principals.

Azure Active Directory NOBELIUM Group azure cloud persistence privilege-escalation
2r 1t
high advisory

Multiple Azure Storage Account Deletions by User

A single user or service principal deleting multiple Azure Storage Accounts within a short time period may indicate malicious activity such as data destruction, service disruption, or a ransomware attack.

Azure +1 cloud storage impact
2r 2t
high advisory

Azure AD Multi-Factor Authentication Disabled

Detection of attempts to disable multi-factor authentication (MFA) for an Azure AD user by identifying the 'Disable Strong Authentication' operation in Azure Active Directory AuditLogs, which allows adversaries to maintain persistence.

Azure Active Directory azure mfa persistence credential-access
2r 2t