Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1599 ✕

Download CSV Show ATT&CK heatmap
  • Azure route table creation or modification Informational Cloud 1 variation

    An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005) Lateral Movement (TA0008)
    ATT&CK techniques: Modify Cloud Compute Infrastructure (T1578) Network Boundary Bridging (T1599) Remote Services: Cloud Services (T1021.007)
    Required data: Azure Audit Log
    Attacker's goals: Redirect or intercept network traffic, bypass security appliances (firewalls, NVAs), or enable lateral movement between Azure subnets.
    Investigative actions: Verify whether the identity should be making route table changes. Inspect the route's address prefix and next-hop -- a 0.0.0.0/0 route pointing at a Virtual Appliance or an internal IP is a strong tamper indicator. Examine other API calls made by the identity around the same time.

    Variations

    Unusual Azure route table creation or modification

    Low overridden

    An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. overridden