Azure Network Security Group Open to the World

Detect when an Azure network security group allows inbound traffic from all IP Addresses.


This rule monitors Azure Activity logs for network changes and detects when the has a value of MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/WRITE, has a value of Inbound, has a value of Allow, and has a value of either OR *.

Triage and response

  1. Inspect which Virtual Machines are associated with this security group.
  2. Determine whether this security group and the VMs should permit inbound traffic from all IP addresses.