Analytics BIOC Informational

Azure storage account cross-tenant object replication was enabled

Azure cross-tenant object replication in a storage account was enabled.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Stealth Tactics Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:

Enable unauthorized data transfer to an external or attacker-controlled environment. Establish a persistent channel for ongoing data exfiltration. Conceal malicious activity by utilizing legitimate cross-tenant object replication functionality.

Investigative actions:

Confirm that the identity intended to enable cross-tenant replication. Follow further actions done by the identity. Monitor the storage account for other suspicious activities.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Azure storage account cross-tenant object replication was enabled for the first time in a subscription Low (parent: Informational)