For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon Azure Cosmos DB master key read by identity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552)

Severity

Low

Description

A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity.

Attacker's Goals

Obtain Cosmos DB master keys to gain full access to the database, allowing data exfiltration, modification, or destruction.

Investigative actions

  • Check the identity's actions before and after the key read operation.

  • Verify whether the identity is authorized to access Cosmos DB master keys.

  • Determine if the retrieved keys were used to access or modify data in the Cosmos DB account.

Was this helpful?