Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1578 ✕
Download CSV Show ATT&CK heatmapA Service Principal was removed from Azure Informational Cloud
A service principal was removed from Azure. This indicates a change in access permissions and may indicate malicious activity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Modify Cloud Compute Infrastructure: Delete Cloud Instance (T1578.003)Required data: Azure Audit LogAttacker's goals: Evade defensive measures by deleting a possibly malicious service principal.Investigative actions: Check the Azure Active Directory audit logs for the details of the removed service principal.* Check the Azure role assignments to identify which resources were impacted by the removal of the service principal.