Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Hunts for successful Azure network configuration write and delete operations by user or service principal identities, including NSGs, firewall policies, route tables, VPN gateways, subnets, and role assignments, with UEBA and appliance-IP enrichment.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | 455ffadf-ce55-4a0e-b339-fd3c2d67c71c |
| Tactics | DefenseEvasion, Persistence, PrivilegeEscalation |
| Techniques | T1686.001, T1098 |
| Required Connectors | AzureActivity, MicrosoftDefenderAdvancedThreatProtection, BehaviorAnalytics |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
BehaviorAnalytics |
✓ | ✗ | ? | |
DeviceInfo |
✓ | ✗ | ? | |
DeviceNetworkInfo |
✓ | ✗ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity