Analytics BIOC Informational

Unusual resource access by Azure application

An Azure application had interacted with an unusual resource using the Microsoft Graph API.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:

Abuse applications to gain access to the Azure tenant.

Investigative actions:

Verify whether the application is intended to use the resource in question. Investigate any unusual activity originating from the application.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • Suspicious resource access by Azure application Low (parent: Informational)