Alerts related to data source "Azure Audit Log".
A cloud identity created or modified a security group
A cloud identity executed an API call from an unusual country
A cloud identity had escalated its permissions
A cloud identity invoked IAM related persistence operations
A cloud identity performed multiple unusual activities
A cloud instance was stopped
A cloud storage configuration was modified
A cloud storage object was copied to a foreign cloud account
A container registry was created or deleted
A Kubernetes API operation was successfully invoked by an anonymous user
A Kubernetes cluster role binding was created or deleted
A Kubernetes cluster role was created
A Kubernetes cluster was created or deleted
A Kubernetes ConfigMap was created or deleted
A Kubernetes Cronjob was created
A Kubernetes DaemonSet was created
A Kubernetes dashboard service account was used outside the cluster
A Kubernetes deployment was created
A Kubernetes ephemeral container was created
A Kubernetes namespace was created or deleted
A Kubernetes node service account activity from external IP
A Kubernetes Pod was created with a sidecar container
A Kubernetes Pod was deleted
A Kubernetes ReplicaSet was created
A Kubernetes role binding was created or deleted
A Kubernetes secret was created or deleted
A Kubernetes service account executed an unusual API call
A Kubernetes service account has enumerated its permissions
A Kubernetes service account was created or deleted
A Kubernetes service was created or deleted
A Kubernetes StatefulSet was created
A new Azure email domain verification was requested
A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment
A Service Principal was created in Azure
A Service Principal was removed from Azure
AI model discovery
AI safeguards deletion attempt
AI safeguards were modified
Allocation of multiple cloud compute resources
An Azure application reached a throttling API rate
An Azure DNS Zone was modified
An Azure Firewall policy deletion
An Azure Firewall rule collection group was modified or deleted
An Azure firewall rule group was modified
An Azure Firewall was modified
An Azure identity performed multiple actions that were denied
An Azure Key Vault key was modified
An Azure Key Vault was modified
An Azure Kubernetes Cluster was created or deleted
An Azure Kubernetes Role or Cluster-Role was modified
An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted
An Azure Kubernetes Service Account was modified or deleted
An Azure Network Security Group was modified
An Azure Point-to-Site VPN was modified
An Azure SQL database was exported from a production subscription
An Azure Suppression Rule was created
An Azure virtual network Device was modified
An Azure virtual network was modified
An Azure VM snapshot SAS URL was generated
An Azure VM snapshot SAS URL was generated for export from a production subscription
An Azure VPN Connection was modified
An identity accessed a backup cloud storage
An identity accessed a cloud storage for the first time
An identity accessed Azure Kubernetes Secrets
An identity initiated a download of multiple cloud objects
An identity performed a suspicious download of multiple cloud storage objects
An identity was granted permissions to manage user access to Azure resources
An operation was performed by an identity from a domain that was not seen in the organization
An unusual read activity of cloud object
Attempted Azure application access from unknown tenant
Authentication method was added to Azure account
Azure application removed
Azure Automation Account Creation
Azure Automation Runbook Creation/Modification
Azure Automation Runbook Deletion
Azure Automation Webhook creation
Azure Blob Container Access Level Modification
Azure conditional access policy creation or modification
Azure device code authentication flow used
Azure diagnostic configuration deletion
Azure enumeration activity using Microsoft Graph API
Azure Event Hub Authorization rule creation/modification
Azure Event Hub Deletion
Azure group creation/deletion
Azure Key Vault modification
Azure Key Vault Secrets were modified
Azure Kubernetes events were deleted
Azure mailbox rule creation
Azure Monitor alert rule deleted
Azure Network Watcher Deletion
Azure permission delegation granted
Azure Resource Group Deletion
Azure route table creation or modification
Azure Service principal/Application creation
Azure storage account blob anonymous access is enabled
Azure storage account cross-tenant object replication was enabled
Azure Storage Account key generated
Azure storage account was publicly shared
Azure user creation/deletion
Azure user password reset
Azure virtual machine commands execution
Azure VM extension abuse attempt
Billing admin role was removed
Cloud activity from a high-risk IP address
Cloud compute serial console access
Cloud email infrastructure enumeration activity
Cloud email service activity
Cloud identity reached a throttling API rate
Cloud instance creation attempt
Cloud instance deletion attempt
Cloud penetration testing tool activity
Cloud resource logging was disabled
Cloud snapshot created or modified
Cloud storage automatic backup disabled
Cloud storage delete protection disabled
Cloud user performed multiple actions that were denied
Compute activity in dormant cloud region
Credentials were added to Azure application
Data exfiltration from cloud database
Deletion of multiple cloud resources
Denied API call by a Kubernetes service account
External user invitation to Azure tenant
Granting Access to an Account
Impossible travel by a cloud identity
Kubernetes admission controller activity
Kubernetes cluster events deletion
Kubernetes enumeration activity
Kubernetes network policy modification
Kubernetes Pod Created with host Inter Process Communications (IPC) namespace
Kubernetes Pod created with host process ID (PID) namespace
Kubernetes Pod Created With Sensitive Volume
Kubernetes pod creation from unknown container image registry
Kubernetes pod creation with host network
Kubernetes Privileged Pod Creation
Kubernetes secrets enumeration for the first time
Kubernetes service account activity outside the cluster
Kubernetes vulnerability scanning tool usage
Mailbox enumeration activity by Azure application
Microsoft 365 storage services exfiltration activity
Microsoft OneDrive enumeration activity
Microsoft OneNote enumeration activity
Microsoft SharePoint enumeration activity
Microsoft Teams enumeration activity
Modification or Deletion of an Azure Application Gateway Detected
Multi region enumeration activity
Multiple cloud snapshots export
Multiple failed logins from a single IP
Multiple risk indicators for a cloud identity
Network sniffing detected in Cloud environment
Object versioning was disabled
OneDrive file download
OneDrive file upload
OneDrive folder creation
Owner was added to Azure application
PIM privilege member removal
Potential denial of wallet abusing AI services
Privileged role used by Azure application
Remote usage of an Azure Managed Identity token
Remote usage of an Azure Service Principal token
Removal of an Azure Owner from an Application or Service Principal
Soft delete of cloud storage configuration was disabled
Storage enumeration activity
Suspicious activity indicating a potential abuse of a cloud-native email service
Suspicious AI Dataset Download
Suspicious AI Dataset Label Modification
Suspicious API call from a Tor exit node
Suspicious Azure enumeration activity
Suspicious cloud compute instance SSH keys modification attempt
Suspicious heavy allocation of compute resources - possible mining activity
Suspicious identity downloaded multiple objects from a bucket
Suspicious ML Model Download
Suspicious secrets dump activity
Uncommon Azure Cosmos DB master key read by identity
Uncommon increase in Azure Microsoft Graph API request sizes
Unusual access to Microsoft 365 storage services
Unusual AI dataset modification
Unusual certificate management activity
Unusual cross projects activity
Unusual exec into a Kubernetes Pod
Unusual key management activity
Unusual Kubernetes secret access
Unusual resource access by Azure application
Unusual resource modification by newly seen IAM user
Unusual secret management activity
Unusual user-agent for a cloud identity
Was this helpful?