For the complete documentation index, see llms.txt. This page is also available as Markdown.

An Azure VM snapshot SAS URL was generated

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Azure Audit Log

Detection Modules

Cloud

Detector Tags

Data Detection & Response, Cloud Data Asset Exfiltration

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Informational

Description

An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot.

Attacker's Goals

Exfiltrate the VM disk image to access sensitive data stored on the disk.

Investigative actions

  • Verify if the identity is authorized to generate SAS URLs for VM snapshots.

  • Check if the snapshot export aligns with scheduled maintenance or backup procedures.

  • Review further actions performed by the identity to see if the snapshot was downloaded or accessed.

  • Check whether the identity has generated SAS URLs for other Azure VM snapshots.

Variations

An identity generated a SAS URL for an Azure VM snapshot with unusual characteristics

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Low

Description

An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot.

Attacker's Goals

Exfiltrate the VM disk image to access sensitive data stored on the disk.

Investigative actions

  • Verify if the identity is authorized to generate SAS URLs for VM snapshots.

  • Check if the snapshot export aligns with scheduled maintenance or backup procedures.

  • Review further actions performed by the identity to see if the snapshot was downloaded or accessed.

  • Check whether the identity has generated SAS URLs for other Azure VM snapshots.

Was this helpful?