Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1070 ✕

Download CSV Show ATT&CK heatmap
  • Removal of an Azure Owner from an Application or Service Principal Informational Cloud 1 variation

    An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Indicator Removal (T1070)
    Required data: Azure Audit Log
    Attacker's goals: Remove owners from applications for full control of the application or service principal. Manipulate or delete data stored in the Azure environment.
    Investigative actions: Check the Azure Activity Log to identify which user removed the Azure Owner.* Check the Azure Role Assignments to identify the current Azure Owners.* Check the Application or Service Principal to identify if any changes have been made.

    Variations

    Removal of an Azure AD privileged user from an Application or Service Principal

    Low overridden

    An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. overridden