Azure storage account was publicly shared
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Public Exposure, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Informational
Description
Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities.
Attacker's Goals
Attackers want to maintain indirect control over the resource.
Attackers intend to allow public access, making it harder to detect future activity.
Attackers are constantly monitoring for public assets to steal sensitive information.
Investigative actions
Check if the storage account should be accessed from all networks.
Disable public network access if needed.
Check if the identity performed additional malicious activity and restrict permissions for the identity if required.
Was this helpful?
