Azure Blob Container Access Level Modification
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
File and Directory Permissions Modification (T1222)
Severity
Informational
Description
Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed.
Attacker's Goals
Access restricted data.
Investigative actions
Check if and which data was exposed after the access level modification.
PreviousAzure Automation Webhook creation
NextAzure conditional access policy creation or modification
Was this helpful?
