Unusual resource access by Azure application
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Service Discovery (T1526)
Severity
Informational
Description
An Azure application had interacted with an unusual resource using the Microsoft Graph API.
Attacker's Goals
Abuse applications to gain access to the Azure tenant.
Investigative actions
Verify whether the application is intended to use the resource in question.
Investigate any unusual activity originating from the application.
Variations
PreviousUnusual Process Spawned by Nginx in Ingress-Nginx pod
NextUnusual resource modification by newly seen IAM user
Was this helpful?
