A Service Principal was created in Azure
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001), Privilege Escalation (TA0004)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource.
Attacker's Goals
Access user data.* Gain control of the Azure environment.
Investigative actions
Check the Service Principal to ensure it has the correct access rights.* Review the Azure Activity Log to determine the source of the Service Principal creation.
Was this helpful?
