Analytics BIOC
Informational
✕
A Service Principal was removed from Azure
A service principal was removed from Azure. This indicates a change in access permissions and may indicate malicious activity.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Cloud Compute Infrastructure: Delete Cloud Instance (T1578.003)
Attacker's goals:
Evade defensive measures by deleting a possibly malicious service principal.
Investigative actions:
Check the Azure Active Directory audit logs for the details of the removed service principal.* Check the Azure role assignments to identify which resources were impacted by the removal of the service principal.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days