Analytics Informational

Azure enumeration activity using Microsoft Graph API

The Microsoft Graph API was used to enumerate an Azure tenant.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:

Map the Azure tenant and detect potential resources to abuse.

Investigative actions:

Check the identity's role designation in the organization. Identify which available resources were discovered. Investigate if the discovered resources were used to extract sensitive information or perform other attacks in the cloud environment.

Test period:
10 Minutes
Deduplication:
5 Days
1 variation:
  • Azure sensitive resources enumeration activity using Microsoft Graph API Informational