Browse Rules

Search and filter across all detection sources

165 rules

wazuh informational xml

Azure: Log analytics activity

Azure: Log analytics activity

sagan critical other

[CISCO-SCA] Azure Activity Log Watchlist Hit

[CISCO-SCA] Azure Activity Log Watchlist Hit

sagan critical other

[CISCO-SCA] Azure Activity Log IP Watchlist Hit

[CISCO-SCA] Azure Activity Log IP Watchlist Hit

anvilogic high spl

Azure Suspicious Logins [splunk-azure]

This use case looks for logins from multiple src_ip, states, or regions. -- Threat Actor Association: LUCR-3

anvilogic high spl

Azure Blob Container Access Level Modification [splunk-azure]

Identifies for changes to container access levels in Azure.

anvilogic high spl

Azure Suspicious Login Failures [splunk-azure]

This use case looks for login failures on a user coming from multiple locations/ips. -- Threat Actor Association: LUCR-3

elastic low eql

Rare Azure Activity Logs Event Failures

A machine learning job detected an unusual failure in an Azure Activity Logs message. These can be byproducts of attempted or successful persistence, privilege escalation, defense evasion, discovery, lateral movement, or collection.

anvilogic high spl

Azure Modify Storage Settings [splunk-azure]

Microsoft Azure Storage provides REST operations for working with Table/Blob/File service resources. Adversaries could modify things such as storage logging and metrics collection.

anvilogic high spl

Azure Command Execution on Virtual Machine [splunk-azure]

Identifies command execution on a virtual machine (VM) in Azure. -- Threat Actor Association: Storm-1283

sentinel high kql

High severity malicious activity detected

Identifies high severity malicious activity in Azure Firewall IDPS logs.

sentinel medium kql

Medium severity malicious activity detected

Identifies medium severity malicious activity in Azure Firewall IDPS logs.

chronicle medium yara-l

Entra ID Admin Login Activity to Uncommon MS Cloud Apps

Detects Azure AD admin login activity to apps other than a defined list of first party MS Cloud Apps. Note that Azure Active Directory PowerShell and custom Azure apps are not in this list by default

chronicle low yara-l

Entra ID Login Activity to Uncommon MS Cloud Apps

This rule detects Azure AD login activity to apps other than a defined list of first party MS Cloud Apps. Note that Azure Active Directory PowerShell and custom Azure apps are not in this list by default

elastic low eql

Spike in Azure Activity Logs Failed Messages

A machine learning job detected a significant spike in the rate of a particular failure in the Azure Activity Logs messages. Spikes in failed messages may accompany attempts at privilege escalation, lateral movement, or discovery.

anvilogic high spl

Azure Elevate to User Access Administrator [splunk-azure]

In order to have full access, the attacker needs to elevate his privileges to Azure User Access Administrator.

anvilogic low spl

Azure List Storage [splunk-azure]

This use case looks for ListBlobs, ListShares, ListFiles, or ListContainers operations in order to identify potential storage enumeration.

anvilogic medium spl

Azure Anonymous Storage Authentication [splunk-azure]

Storage Analytics log provides you much better visibility on what has happened with your storage account. This use case looks for authentication types that indicate anonymous access.

anvilogic high spl

Azure Brute Force Signin [splunk-azure]

This use case looks for potential brute force attacks on users. Look for a specific number of login failures followed by success. -- Threat Actor Association: LUCR-3

chronicle medium yara-l

O365 Login Activity To Azure AD PowerShell App

Logins to Azure AD PowerShell app can have legitimate purposes, but are also abused to gain access to user information. Programmatic access to Entra ID (Azure AD) should generally be through apps, so reviewing these activities is needed.

chronicle medium yara-l

O365 Persistent Login Activity To Azure AD PowerShell App

Continual logins to Azure AD PowerShell app are not a security best practice, if this is observed, additional investigation is needed

chronicle medium yara-l

O365 Login Activity To Uncommon Microsoft Cloud Apps

This rule detects O365 login activity to apps other than a defined list of first party MS Cloud Apps. Note that Azure Active Directory PowerShell and custom Azure apps are not in this list by default

anvilogic high spl

Azure Create or Modify Resource Group [splunk-azure]

Each resource that you create inside Azure must belong to a resource group. It is a logical container that groups multiple resources together. This use case looks for resource group creations or modifications.

anvilogic low spl

Azure Information Gathering [splunk-azure]

An adversary could run multiple commands in order to find all the necessary information regarding users, accounts, service principals, groups etc.

anvilogic high spl

Azure Update MFA [splunk-azure]

Identify when a user has had their security info updated. - Threat Actor Association: APT29, LUCR-3, Scattered Spider (aka. 0ktapus, UNC3944)

elastic low eql

Unusual Azure Activity Logs Event for a User

A machine learning job detected Azure Activity Logs activity that, while not inherently suspicious or abnormal, is sourcing from user context that does not normally use the event action. This can be the result of compromised credentials or keys as someone uses a valid account to persist, move laterally, or exfiltrate data.