LoFP LoFP / t1037

t1037

TitleTags
infrastructure-as-code, configuration management, and patching automation routinely create, update, and delete vm extensions. the first time a given extension resource name is operated on from a new source as number will alert. baseline expected management networks (corporate egress, ci/cd runners, third-party automation saas) and exclude their as numbers if the activity is verified as authorized. read operations are typically not emitted to the azure activity log; the rule predominantly fires on write and delete.
investigate the contents of the \"userinitmprlogonscript\" value to determine of the added script is legitimate
legitimate addition of logon scripts via the command line by administrators or third party tools
legitimate administration activities
legitimate administrative activity
legitimate logon scripts or custom shells may trigger false positives. apply additional filters accordingly.
the vast majority of vm writes are benign: provisioning, resizing, tagging, extension/identity changes, autoscale, and configuration management by users, service principals, and managed identities. this rule is informational only and is intended for correlation and baselining, not standalone alerting.