Analytics BIOC Informational

Azure virtual machine commands execution

An Azure virtual machine executed PowerShell commands with System privileges.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Remote Services: Cloud Services (T1021.007)
Attacker's goals:

Execute arbitrary code inside a VM without needing SSH/RDP or any open inbound network path.

Investigative actions:

Identify the target VM resource and the subscription / resource group it belongs to. Retrieve the script payload sent via Run Command. Verify whether the calling identity is normally entitled to perform VM Run Command on this VM. Check for related anomalies on the same identity.

Test period:
N/A (single event)
Deduplication:
3 Hours
2 variations:
  • Unusual Azure VM remote command execution Low (parent: Informational)
  • First Azure VM remote command execution on this VM Informational