Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1552 ✕

Download CSV Show ATT&CK heatmap
  • Remote usage of an Azure Managed Identity token Low Cloud 4 variations

    An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)
    Required data: Azure Audit Log
    Detector tags: Cloud Serverless Function Credentials Theft Analytics
    Attacker's goals: Exfiltrate valid token and abuse it remotely.
    Investigative actions: Verify whether the Managed Identity should be used remotely. Check what API calls were executed by the Managed Identity. Check if the relevant compute service is compromised.

    Variations

    Remote usage of an Azure Function App's Managed Identity token

    Medium overridden

    An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden

    Remote usage of an Azure Automation Account's Managed Identity token

    Medium overridden

    An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden

    Remote usage of an Azure Managed Identity token from an unusual ASN

    High overridden

    An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden

    Remote usage of an Azure Managed Identity token from an unusual IP

    Medium overridden

    An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden