Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Series

Azure incident response

5 posts in this series. Read them in order or jump to any one.

  1. Azure subscription compromised? An incident response guide

    Think your Azure subscription is compromised? Which logs to preserve first, the operations that betray an attacker, and how to go from Activity Log to verdict.

  2. How to export the Azure Activity Log and resource logs

    Export the Azure Activity Log, Key Vault, storage and flow logs for an investigation: portal, az CLI, Log Analytics and storage exports, and the traps.

  3. Azure Activity Log analysis, step by step, in your browser

    Step-by-step Azure Activity Log analysis with the free Azure Forensics analyzer: load exports, read the verdict, findings, timeline and entities, export.

  4. An Azure breach, walked through (fictional case)

    A fictional Azure breach investigated end to end: leaked app secret, self-assigned role, Run Command, stolen managed identity token, Key Vault and blob theft.

  5. Azure log forensics limits: retention and missing logs

    Azure Activity Log retention is 90 days and resource logs are off by default. What each Azure log cannot tell you, and how to write an honest conclusion.

All posts in this series

Think your Azure subscription is compromised? Which logs to preserve first, the operations that betray an attacker, and how to go from Activity Log to verdict.
Export the Azure Activity Log, Key Vault, storage and flow logs for an investigation: portal, az CLI, Log Analytics and storage exports, and the traps.
Step-by-step Azure Activity Log analysis with the free Azure Forensics analyzer: load exports, read the verdict, findings, timeline and entities, export.
A fictional Azure breach investigated end to end: leaked app secret, self-assigned role, Run Command, stolen managed identity token, Key Vault and blob theft.
Azure Activity Log retention is 90 days and resource logs are off by default. What each Azure log cannot tell you, and how to write an honest conclusion.

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.