<  Back to rules search

Azure New Service Principal created

azure

Classification:

attack

Tactic:

Set up the azure integration.

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a new service principal is created in Azure, which applies to a persistence mechanism.

Strategy

Monitor Azure Active Directory logs where @evt.name is "Add service principal" and @evt.outcome of Success.

Triage and response

  1. Inspect the new service principal in @properties.targetResources.
  2. Verify with the user ({{$usr.name}}) to determine if the service principal is legitimate.