Analytics BIOC
Informational
✕
Azure storage account cross-tenant object replication was enabled
Azure cross-tenant object replication in a storage account was enabled.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Stealth Tactics Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:
Enable unauthorized data transfer to an external or attacker-controlled environment. Establish a persistent channel for ongoing data exfiltration. Conceal malicious activity by utilizing legitimate cross-tenant object replication functionality.
Investigative actions:
Confirm that the identity intended to enable cross-tenant replication. Follow further actions done by the identity. Monitor the storage account for other suspicious activities.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Azure storage account cross-tenant object replication was enabled for the first time in a subscription Low (parent: Informational)