For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure storage account was publicly shared

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Azure Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Public Exposure, Data Detection & Response

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Informational

Description

Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities.

Attacker's Goals

  • Attackers want to maintain indirect control over the resource.

  • Attackers intend to allow public access, making it harder to detect future activity.

  • Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions

  • Check if the storage account should be accessed from all networks.

  • Disable public network access if needed.

  • Check if the identity performed additional malicious activity and restrict permissions for the identity if required.

Was this helpful?