Rules Contributing to Azure New CloudShell Created Alert
The following rules are used to identify events when an Azure new Cloud Shell is changed. Any one or more of these will trigger the Azure New CloudShell Created Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
Azure New CloudShell Created |
Identifies when a new cloudshell is created inside of Azure portal. More details
Rule IDQuery{'selection': {'operationName': 'MICROSOFT.PORTAL/CONSOLES/WRITE'}, 'condition': 'selection'} Log SourceStellar Cyber Microsoft Entra Events configured. Rule SourceSigmaHQ,72af37e2-ec32-47dc-992b-bc288a2708cb Author: Austin Songer Tactics, Techniques, and ProceduresReferencesSeverity50 Suppression Logic Based On
Additional Information
|