Analytics BIOC
Informational
✕
Azure Storage Account key generated
Azure storage access keys rotation, might affect services/applications depended on the key set.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal Application Access Token (T1528)
Detector tags: Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:
Exfiltrate information or damage critical services.
Investigative actions:
Check what actions were made by the users a few hours prior/after to the generation operation. Which actions were taken using the newly generated access keys.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day