Modification or Deletion of an Azure Application Gateway Detected
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
External Remote Services (T1133)
Severity
Informational
Description
Modification or Deletion of an Azure Application Gateway Detected. A change has been detected in an Azure Application Gateway. This may indicate unauthorized access or malicious activity.
Attacker's Goals
Gain access to the resources behind the Azure Application Gateway.
Investigative actions
Check the Azure Application Gateway to identify the changes made.
Verify whether the identity should be making this action.
PreviousModification of the AD FS IdentityServer configuration file
NextMoniker link detected in URL(s)
Was this helpful?
