Techniques
Sample rules
Azure Compute VM Command Executed
- source: elastic
- technicques:
- T1651
Description
Identifies synchronous command execution on a virtual machine (VM) or virtual machine scale set (VMSS) in Azure via the action-based Run Command (“runCommand/action”). A Virtual Machine Contributor role lets you manage virtual machines, but not access them, nor access the virtual network or storage account they’re connected to. However, commands can be run on the VM via the Run Command feature, which execute as System (Windows) or root (Linux). Other roles, such as certain Administrator roles, may be able to execute commands on a VM as well.
Detection logic
data_stream.dataset:azure.activitylogs and
azure.activitylogs.operation_name:(
"MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION" or
"MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/VIRTUALMACHINES/RUNCOMMAND/ACTION"
) and event.outcome:(Success or success) and
azure.activitylogs.identity.authorization.evidence.principal_id: * and
source.as.number: * and
azure.resource.name: *