An Azure Key Vault key was modified
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)
Severity
Informational
Description
An Azure Key Vault key was modified.
Attacker's Goals
Gain access to sensitive data stored in the Azure Key Vault.
Investigative actions
Check the Azure Key Vault configuration to identify what changes were made.
PreviousAn Azure identity performed multiple actions that were denied
NextAn Azure Key Vault was modified
Was this helpful?
