Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapRemoval of an Azure Owner from an Application or Service Principal Informational Cloud 1 variation
An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Indicator Removal (T1070)Required data: Azure Audit LogAttacker's goals: Remove owners from applications for full control of the application or service principal. Manipulate or delete data stored in the Azure environment.Investigative actions: Check the Azure Activity Log to identify which user removed the Azure Owner.* Check the Azure Role Assignments to identify the current Azure Owners.* Check the Application or Service Principal to identify if any changes have been made.Variations
Removal of an Azure AD privileged user from an Application or Service Principal
Low overridden
An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. overridden