Name:Azure Automation Runbook Created id:178d696d-6dc6-4ee8-9d25-93fee34eaf5b version:12 date:2026-03-10 author:Mauricio Velazco, Brian Serocki, Splunk status:production type:TTP Description:The following analytic detects the creation of a new Azure Automation Runbook within an Azure tenant. It leverages Azure Audit events, specifically the Azure Activity log category, to identify when a new Runbook is created or updated. This activity is significant because adversaries with privileged access can use Runbooks to maintain persistence, escalate privileges, or execute malicious code. If confirmed malicious, this could lead to unauthorized actions such as creating Global Administrators, executing code on VMs, and compromising the entire Azure environment. Data_source:
-Azure Audit Create or Update an Azure Automation Runbook