For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure Storage Account key generated

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Azure Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Configuration, Data Detection & Response

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528)

Severity

Informational

Description

Azure storage access keys rotation, might affect services/applications depended on the key set.

Attacker's Goals

Exfiltrate information or damage critical services.

Investigative actions

  • Check what actions were made by the users a few hours prior/after to the generation operation.

  • Which actions were taken using the newly generated access keys.

Was this helpful?