Credentials were added to Azure application
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Informational
Description
Credentials were added to an Azure application.
Attacker's Goals
An attacker can establish a backdoor in the application by adding additional credentials to it, such as secrets or certificates.
Investigative actions
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
PreviousCreation or modification of the default command executed when opening an application
NextData encryption was disabled
Was this helpful?
