Techniques
Sample rules
Azure Kubernetes Service Account Modified or Deleted
- source: sigma
- technicques:
- t1531
Description
Identifies when a service account is modified or deleted.
Detection logic
condition: selection
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/DELETE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/SERVICEACCOUNTS/IMPERSONATE/ACTION