Elastic medium stable kql
Azure Compute VM Command Executed
Identifies synchronous command execution on a virtual machine (VM) or virtual machine scale set (VMSS) in Azure via the action-based Run Command ("runCommand/action"). A Virtual Machine Contributor role lets you manage virtual machines, but not access them, nor access the virtual network or storage account they’re connected to. However, commands can be run on the VM via the Run Command feature, which execute as System (Windows) or root (Linux). Other roles, such as certain Administrator roles, may be able to execute commands on a VM as well.
Detection Logic
data_stream.dataset:azure.activitylogs and
azure.activitylogs.operation_name:(
"MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION" or
"MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/VIRTUALMACHINES/RUNCOMMAND/ACTION"
) and event.outcome:(Success or success) and
azure.activitylogs.identity.authorization.evidence.principal_id: * and
source.as.number: * and
azure.resource.name: * False Positives
- ⚠ Command execution on a virtual machine may be done by a system or network administrator. Verify whether the username, hostname, and/or resource name should be making changes in your environment. Command execution from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Field Validations
Loading…
Comments (0)
Loading comments...