Azure Active Directory Hybrid Health AD FS Service Delete

 Original Source: [Sigma source]
Title: Azure Active Directory Hybrid Health AD FS Service Delete
Status: test
Description:This detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.
References:
  -https://o365blog.com/post/hybridhealthagent/
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date: 2021-08-26
modified:2023-10-11
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1578.003'
Logsource:
  • product: azure
  • service: activitylogs
Detection:
  selection:
    CategoryValue: 'Administrative'
    ResourceProviderValue: 'Microsoft.ADHybridHealthService'
    ResourceId|contains: 'AdFederationService'
    OperationNameValue: 'Microsoft.ADHybridHealthService/services/delete'
  condition:selection
Falsepositives:
  -Legitimate AAD Health AD FS service instances being deleted in a tenant
Level: medium