Analytics BIOC Informational

A Service Principal was removed from Azure

A service principal was removed from Azure. This indicates a change in access permissions and may indicate malicious activity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Cloud Compute Infrastructure: Delete Cloud Instance (T1578.003)
Attacker's goals:

Evade defensive measures by deleting a possibly malicious service principal.

Investigative actions:

Check the Azure Active Directory audit logs for the details of the removed service principal.* Check the Azure role assignments to identify which resources were impacted by the removal of the service principal.

Test period:
N/A (single event)
Deduplication:
5 Days