Analytics BIOC Informational

Azure Storage Account key generated

Azure storage access keys rotation, might affect services/applications depended on the key set.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal Application Access Token (T1528)
Detector tags: Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Exfiltrate information or damage critical services.

Investigative actions:

Check what actions were made by the users a few hours prior/after to the generation operation. Which actions were taken using the newly generated access keys.

Test period:
N/A (single event)
Deduplication:
1 Day