Title:Azure Subscription Permission Elevation Via ActivityLogs Status:test Description:Detects when a user has been elevated to manage all Azure Subscriptions.
This change should be investigated immediately if it isn't planned.
This setting could allow an attacker access to Azure subscriptions in your environment.
References: -https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftauthorization Author: Austin Songer @austinsonger Date: 2021-11-26 modified:2022-08-23 Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.initial-access'
-'attack.stealth'
-'attack.t1078.004'
Logsource:
product: azure
service: activitylogs
Detection: selection: operationName:
'MICROSOFT.AUTHORIZATION/ELEVATEACCESS/ACTION' condition:selection Falsepositives:
-If this was approved by System Administrator. Level:high