Analytics BIOC Low

Uncommon Azure Cosmos DB master key read by identity

A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials (T1552)
Attacker's goals:

Obtain Cosmos DB master keys to gain full access to the database, allowing data exfiltration, modification, or destruction.

Investigative actions:

Check the identity's actions before and after the key read operation. Verify whether the identity is authorized to access Cosmos DB master keys. Determine if the retrieved keys were used to access or modify data in the Cosmos DB account.

Test period:
N/A (single event)
Deduplication:
1 Day