Log sources › azure:audit
azure:audit
Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite
11
channels
10
analytics
10
techniques
12
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Add delegated admin / Assign admin roles / Update application consent |
DC0088 Logon Session Metadata | AN1347 | 1 |
Add member to role |
DC0010 User Account Modification | AN0899 | 1 |
Add service principal credentials, app password added, app role assignment |
DC0010 User Account Modification | AN1469 | 1 |
Add user |
DC0014 User Account Creation | AN0899 AN1079 AN1607 | 3 |
App registrations or consent grants by abnormal users or at unusual times |
DC0038 Application Log Content | AN1425 | 1 |
Consent to application: OAuth application consent granted to service principal |
DC0069 Cloud Service Modification | AN1487 | 1 |
ListApplications, ListServicePrincipals: Large-scale queries against identity or application objects |
DC0083 Cloud Service Enumeration | AN1128 | 1 |
New device object creation |
DC0087 Active Directory Object Creation | AN0103 | 1 |
Operation IN ("Add device", "Add registered users to device", "Add registered owner to device") |
DC0010 User Account Modification | AN0103 | 1 |
Rename user |
DC0010 User Account Modification | AN1079 | 1 |
operation contains 'Get*Password*Policy' OR 'List*Authentication*Policy' OR 'Get-ADDefaultDomainPasswordPolicy' |
DC0013 User Account Metadata | AN0459 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.010 Masquerade Account Name | stealth | 0 | 0 |
| T1098.001 Additional Cloud Credentials | persistence, privilege escalation | 3 | 0 |
| T1098.005 Device Registration | persistence, privilege escalation | 1 | 0 |
| T1136 Create Account | persistence | 3 | 10 |
| T1136.003 Cloud Account | persistence | 3 | 0 |
| T1199 Trusted Relationship | initial access | 2 | 1 |
| T1201 Password Policy Discovery | discovery | 6 | 0 |
| T1526 Cloud Service Discovery | discovery | 3 | 0 |
| T1528 Steal Application Access Token | credential access | 14 | 1 |
| T1671 Cloud Application Integration | persistence | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2021-34473 | Microsoft Exchange Server | T1136 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1136 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1136 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1136 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1136 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1136 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1136 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1136 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1136 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1199 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1136 | Mapped |