Analytics BIOC
Informational
✕
Azure Automation Webhook creation
Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Attacker's goals:
Persistence using a valid account.
Investigative actions:
Check the identity actions prior/after the webhook creation.* Find which Runbook was executed using the webhook.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day