Azure Storage Account key generated
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal Application Access Token (T1528)
Severity
Informational
Description
Azure storage access keys rotation, might affect services/applications depended on the key set.
Attacker's Goals
Exfiltrate information or damage critical services.
Investigative actions
Check what actions were made by the users a few hours prior/after to the generation operation.
Which actions were taken using the newly generated access keys.
PreviousAzure storage account cross-tenant object replication was enabled
NextAzure storage account was publicly shared
Was this helpful?
