For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure Automation Webhook creation

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook.

Attacker's Goals

Persistence using a valid account.

Investigative actions

  • Check the identity actions prior/after the webhook creation.* Find which Runbook was executed using the webhook.

Was this helpful?