Analytics BIOC Informational

Azure Key Vault Secrets were modified

Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Attacker's goals:

Gain access to confidential data stored in the Azure Key Vault.

Investigative actions:

Investigate what Azure Key Vault Secrets were modified or deleted.* Check for any suspicious activity initiated by the identity.

Test period:
N/A (single event)
Deduplication:
5 Days