Rules Contributing to Suspicious Azure Deployment Activity Alert

The following rules are used to identify suspicious Azure deployment activity. Any one or more of these will trigger the Suspicious Azure Deployment Activity Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Number Of Resource Creation Or Deployment Activities

Number of VM creations or deployment activities occur in Azure via Azure Activity Log.

Azure Container Registry Modified or Deleted

Detects when a Container Registry is created, updated, or deleted.