Rules Contributing to Suspicious Azure Key Vault Activity Alert

The following rules are used to identify suspicious Azure Key Vault activity. Any one or more of these will trigger the Suspicious Azure Key Vault Activity Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Azure Keyvault Key Modified or Deleted

Identifies when a Keyvault Key is modified or deleted in Azure.

Azure Key Vault Modified or Deleted

Identifies when a key vault is modified or deleted.

Azure Keyvault Secrets Modified or Deleted

Identifies when secrets are modified or deleted in Azure.