An Azure SQL database was exported from a production subscription
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Data Detection & Response, Cloud Data Asset Exfiltration
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
An Azure SQL database export was initiated. The database was exported from a production subscription.
Attacker's Goals
Exfiltrate data to an unknown bucket.
Investigative actions
Check the legitimacy of the referenced destination bucket.
Review further logs for the source SQL instance.
Review further actions performed by the identity.
Was this helpful?
