kevmap

Log sources › azure:activity

azure:activity

Inverted view: what can be detected if this is the log you have. IaaS, Identity Provider, Windows

9
channels
9
analytics
9
techniques
1
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Azure CLI Operation: Microsoft.Graph/users/read DC0013 User Account Metadata AN1088 1
CollectGuestLogs: Unexpected collection of guest logs by Azure VM Agent outside normal maintenance windows DC0055 File Access AN0708 1
MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE DC0081 Instance Deletion AN0234 1
MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE DC0076 Instance Creation AN1242 1
Microsoft.Compute/virtualMachines/runCommand/action: Abnormal initiation of Azure RunCommand jobs or PowerShell/Bash payloads DC0029 Script Execution AN1502 1
Microsoft.Compute/virtualMachines/write: imageReference publisher NOT IN allowlist OR plan is new/unknown DC0076 Instance Creation AN0692 1
Update conditionalAccessPolicy DC0066 Active Directory Object Modification AN0088 1
networkInsightsLogs DC0085 Network Traffic Content AN0908 1
operationName: Write, Access Review, RoleAssignment DC0069 Cloud Service Modification AN0215 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1049 System Network Connections Discoverydiscovery91
T1059.009 Cloud APIexecution30
T1087.004 Cloud Accountdiscovery30
T1204.003 Malicious Imageexecution00
T1556.009 Conditional Access Policiesdefense impairment, persistence, credential access00
T1578.002 Create Cloud Instancedefense impairment00
T1578.003 Delete Cloud Instancedefense impairment10
T1651 Cloud Administration Commandexecution00
T1654 Log Enumerationdiscovery00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-41328Fortinet FortiOS T1049 Mapped