heroui logo

Privileged Account Creation

Sigma Rules

View Source
Summary
The rule titled 'Privileged Account Creation' is designed to detect the creation of new administrative accounts within an Azure environment, specifically by monitoring audit logs for specific events. It focuses on messages that contain keywords such as 'Add user' and 'Add member to role', combined with a status indicating success, which indicates a successful account addition. This rule is essential for maintaining security posture by alerting on potentially unauthorized or malicious creation of administrative privileges that could lead to escalated access or persistence on the network.
Categories
  • Cloud
  • Azure
  • Identity Management
Data Sources
  • Cloud Service
  • Application Log
Created: 2022-08-11