LoFP LoFP / a new cloudshell may be created by a system administrator.

Techniques

Sample rules

Azure New CloudShell Created

Description

Identifies when a new cloudshell is created inside of Azure portal.

Detection logic

condition: selection
selection:
  operationName: MICROSOFT.PORTAL/CONSOLES/WRITE