Techniques
Sample rules
Azure Kubernetes Cluster Created or Deleted
- source: sigma
- technicques:
- t1485
- t1489
- t1496
Description
Detects when a Azure Kubernetes Cluster is created or deleted.
Detection logic
condition: selection
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE