kevmap

Log sources › azure:audit

azure:audit

Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite

11
channels
10
analytics
10
techniques
12
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Add delegated admin / Assign admin roles / Update application consent DC0088 Logon Session Metadata AN1347 1
Add member to role DC0010 User Account Modification AN0899 1
Add service principal credentials, app password added, app role assignment DC0010 User Account Modification AN1469 1
Add user DC0014 User Account Creation AN0899 AN1079 AN1607 3
App registrations or consent grants by abnormal users or at unusual times DC0038 Application Log Content AN1425 1
Consent to application: OAuth application consent granted to service principal DC0069 Cloud Service Modification AN1487 1
ListApplications, ListServicePrincipals: Large-scale queries against identity or application objects DC0083 Cloud Service Enumeration AN1128 1
New device object creation DC0087 Active Directory Object Creation AN0103 1
Operation IN ("Add device", "Add registered users to device", "Add registered owner to device") DC0010 User Account Modification AN0103 1
Rename user DC0010 User Account Modification AN1079 1
operation contains 'Get*Password*Policy' OR 'List*Authentication*Policy' OR 'Get-ADDefaultDomainPasswordPolicy' DC0013 User Account Metadata AN0459 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1036.010 Masquerade Account Namestealth00
T1098.001 Additional Cloud Credentialspersistence, privilege escalation30
T1098.005 Device Registrationpersistence, privilege escalation10
T1136 Create Accountpersistence310
T1136.003 Cloud Accountpersistence30
T1199 Trusted Relationshipinitial access21
T1201 Password Policy Discoverydiscovery60
T1526 Cloud Service Discoverydiscovery30
T1528 Steal Application Access Tokencredential access141
T1671 Cloud Application Integrationpersistence00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-34473Microsoft Exchange Server T1136 Mapped
CVE-2021-40539Zoho ManageEngine T1136 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1136 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1136 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1136 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1136 Mapped
CVE-2023-28252Microsoft Windows T1136 Mapped
CVE-2023-34362Progress MOVEit Transfer T1136 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1136 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped
CVE-2024-53704SonicWall SonicOS T1199 Mapped
CVE-2025-31161CrushFTP CrushFTP T1136 Mapped