Posts tagged: #incident-response
Azure Activity Log retention is 90 days and resource logs are off by default. What each Azure log cannot tell you, and how to write an honest conclusion.
A fictional Azure breach investigated end to end: leaked app secret, self-assigned role, Run Command, stolen managed identity token, Key Vault and blob theft.
Use Azure Key Vault audit logs (AuditEvent) to find who read which secret: SecretGet and SecretList, access policy changes, new principals and enumeration.
Step-by-step Azure Activity Log analysis with the free Azure Forensics analyzer: load exports, read the verdict, findings, timeline and entities, export.
Think your Azure subscription is compromised? Which logs to preserve first, the operations that betray an attacker, and how to go from Activity Log to verdict.