Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: Microsoft Azure

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
171781313
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Cloud Data Protectionazure-blob-read
azure-blob-activity1
azure-blob-activity2

azure-blob-write
azure-blob-activity1
azure-blob-activity2

azure-container-acl
azure-blob-activity1
azure-blob-activity2

azure-disk-write
azure-disks-write

azure-snapshot-write
azure-snapshots-write

azure-storage-list
azure-blob-activity1
azure-blob-activity2
T1078.004 - Valid Accounts: Cloud Accounts
T1204 - User Execution
T1580 - T1580
TA0009 - TA0009
  • 5 Rules
  • 5 Models
Compromised Credentialsazure-blob-read
azure-blob-activity1
azure-blob-activity2

azure-blob-write
azure-blob-activity1
azure-blob-activity2

azure-container-acl
azure-blob-activity1
azure-blob-activity2

azure-disk-write
azure-disks-write

azure-image-write
azure-images-write

azure-instance-creds-write
azure-sshpublickeys-write

azure-instance-write
azure-virtualmachines-write

azure-keyvault-read
azure-keyvault-activity

azure-keyvault-write
azure-keyvault-activity

azure-role-assign
azure-roleassignments-write

azure-role-write
azure-roledefiniton-write

azure-snapshot-write
azure-snapshots-write

azure-storage-list
azure-blob-activity1
azure-blob-activity2
T1078.004 - Valid Accounts: Cloud Accounts
T1535 - Unused/Unsupported Cloud Regions
  • 5 Rules
  • 5 Models
Cryptominingazure-instance-write
azure-virtualmachines-write
T1496 - Resource Hijacking
  • 1 Rules
  • 1 Models
Malwareazure-blob-write
azure-blob-activity1
azure-blob-activity2

azure-image-write
azure-images-write

azure-instance-write
azure-virtualmachines-write
T1204 - User Execution
T1204.003 - T1204.003
  • 4 Rules
  • 4 Models
Privilege Escalationazure-role-assign
azure-roleassignments-write

azure-role-write
azure-roledefiniton-write
TA0004 - TA0004
  • 2 Rules
  • 2 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Valid Accounts: Cloud Accounts

User Execution

Valid Accounts

Valid Accounts

Valid Accounts

Unused/Unsupported Cloud Regions

Resource Hijacking