- 重要な情報
- はじめに
- 用語集
- ガイド
- エージェント
- インテグレーション
- OpenTelemetry
- 開発者
- API
- CoScreen
- アプリ内
- Service Management
- インフラストラクチャー
- アプリケーションパフォーマンス
- 継続的インテグレーション
- ログ管理
- セキュリティ
- UX モニタリング
- 管理
Set up the azure integration.
Detects when a user adds a secret or certificate to an Azure Active Directory Application that is not regularly updated.
Monitor Azure AD Audit logs for the following @evt.name
:
Update application – Certificates and secrets management
Add service principal credentials
Monitor Microsoft 365 Audit logs for the following @evt.name
:
Update application – Certificates and secrets management
Add service principal credentials.
An attacker can add a secret or certificate to an application in order to connect to Azure AD as the application and perform API operation leveraging the application permissions that are assigned to it. An attacker may target an application that is seldom changed to avoid detection. Using the New Value
detection method, a signal is raised when an application not seen in the previous 7 days has credentials added.
{{@usr.id}}
should have made a {{@evt.name}}
API call.2 November 2022 - Updated severity.