Analytics BIOC Informational

An Azure Key Vault was modified

Azure Key Vault has been modified or deleted by an Identity. This could be an indication of unauthorized access or malicious activity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Attacker's goals:

* Gain access to sensitive data stored in the Azure Key Vault.

Investigative actions:

Check the Azure Key Vault configuration to identify what changes were made.

Test period:
N/A (single event)
Deduplication:
5 Days