Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Azure virtual machine commands execution Informational Cloud 2 variations

    An Azure virtual machine executed PowerShell commands with System privileges.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Hours
    ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
    ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Remote Services: Cloud Services (T1021.007)
    Required data: Azure Audit Log
    Attacker's goals: Execute arbitrary code inside a VM without needing SSH/RDP or any open inbound network path.
    Investigative actions: Identify the target VM resource and the subscription / resource group it belongs to. Retrieve the script payload sent via Run Command. Verify whether the calling identity is normally entitled to perform VM Run Command on this VM. Check for related anomalies on the same identity.

    Variations

    Unusual Azure VM remote command execution

    Low overridden

    An Azure virtual machine executed PowerShell commands with System privileges. overridden

    First Azure VM remote command execution on this VM

    Informational overridden

    An Azure virtual machine executed PowerShell commands with System privileges. overridden