Analytics BIOC
Informational
✕
Removal of an Azure Owner from an Application or Service Principal
An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal (T1070)
Attacker's goals:
Remove owners from applications for full control of the application or service principal. Manipulate or delete data stored in the Azure environment.
Investigative actions:
Check the Azure Activity Log to identify which user removed the Azure Owner.* Check the Azure Role Assignments to identify the current Azure Owners.* Check the Application or Service Principal to identify if any changes have been made.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Removal of an Azure AD privileged user from an Application or Service Principal Low (parent: Informational)