Elastic medium stable kql
Azure VNet Full Network Packet Capture Enabled
Identifies potential full network packet capture in Azure. Packet Capture is an Azure Network Watcher feature that can be used to inspect network traffic. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
Detection Logic
data_stream.dataset:azure.activitylogs and azure.activitylogs.operation_name:
(
MICROSOFT.NETWORK/*/STARTPACKETCAPTURE/ACTION or
MICROSOFT.NETWORK/*/VPNCONNECTIONS/STARTPACKETCAPTURE/ACTION or
MICROSOFT.NETWORK/*/PACKETCAPTURES/WRITE
) and
event.outcome:(Success or success) False Positives
- ⚠ Full Network Packet Capture may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Full Network Packet Capture from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Field Validations
Loading…
Comments (0)
Loading comments...