{"id":"09438caa-07b1-4870-8405-1dbafe3dad95","title":"Azure Subscription Permission Elevation Via ActivityLogs","description":"Detects when a user has been elevated to manage all Azure Subscriptions.\nThis change should be investigated immediately if it isn't planned.\nThis setting could allow an attacker access to Azure subscriptions in your environment.\n","author":"Austin Songer @austinsonger","status":"test","level":"high","date":"2021-11-26","modified":"2022-08-23","tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078.004"],"technique_ids":["T1078.004"],"logsource":{"product":"azure","service":"activitylogs"},"falsepositives":["If this was approved by System Administrator."],"references":["https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftauthorization"],"source_path":"rules/cloud/azure/activity_logs/azure_subscription_permissions_elevation_via_activitylogs.yml","source_sha256":"5fddfb4ebc4a3d8da5dbd7c402bc839ed878e1d75d5318e010d2773209d2c999","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/activity_logs/azure_subscription_permissions_elevation_via_activitylogs.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Azure Subscription Permission Elevation Via ActivityLogs\nid: 09438caa-07b1-4870-8405-1dbafe3dad95\nstatus: test\ndescription: |\n    Detects when a user has been elevated to manage all Azure Subscriptions.\n    This change should be investigated immediately if it isn't planned.\n    This setting could allow an attacker access to Azure subscriptions in your environment.\nreferences:\n    - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftauthorization\nauthor: Austin Songer @austinsonger\ndate: 2021-11-26\nmodified: 2022-08-23\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.initial-access\n    - attack.stealth\n    - attack.t1078.004\nlogsource:\n    product: azure\n    service: activitylogs\ndetection:\n    selection:\n        operationName: MICROSOFT.AUTHORIZATION/ELEVATEACCESS/ACTION\n    condition: selection\nfalsepositives:\n    - If this was approved by System Administrator.\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1078.004","id":"T1078.004","name":"Cloud Accounts","page":"techniques/enterprise/T1078.004/"}],"data_path":"data/detection-rules/09438caa-07b1-4870-8405-1dbafe3dad95.json","kind":"sigma"}
