LoFP LoFP / t1037

t1037

TitleTags
infrastructure-as-code, configuration management, and patching automation routinely create, update, and delete vm extensions. the first time a given extension resource name is operated on from a new source as number will alert. baseline expected management networks (corporate egress, ci/cd runners, third-party automation saas) and exclude their as numbers if the activity is verified as authorized. read operations are typically not emitted to the azure activity log; the rule predominantly fires on write and delete.
investigate the contents of the \"userinitmprlogonscript\" value to determine of the added script is legitimate
legitimate addition of logon scripts via the command line by administrators or third party tools
legitimate administration activities
legitimate administrative activity
legitimate logon scripts or custom shells may trigger false positives. apply additional filters accordingly.
legitimate provisioning, patching, and configuration-management automation may deploy an extension to a host for the first time. the first occurrence per host will alert. baseline expected automation principals and hosts and exclude verified-benign ones.
the vast majority of vm writes are benign: provisioning, resizing, tagging, extension/identity changes, autoscale, and configuration management by users, service principals, and managed identities. this rule is informational only and is intended for correlation and baselining, not standalone alerting.