Analytics BIOC
Informational
✕
Azure Key Vault modification
Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials (T1552)
Attacker's goals:
Exfiltrate information, persistence on existing users or damage critical accounts.
Investigative actions:
Check the identity actions before or after the Key Vault modification. Find which credentials were modified and their usage.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours