Azure Detection Pack
72 production-ready detection rules covering Azure Activity Logs, Entra ID, Microsoft Defender for Cloud, Key Vault, and Storage. Activate once — get full MITRE ATT&CK coverage for your Azure environment.
Pack summary
- Detection rules
- 72
- Critical severity
- 21
- Data sources
- 9
- ATT&CK techniques
- 26
What's included
72 rules across 7 threat categories targeting the most common Azure attack patterns.
Entra ID sign-in anomalies, MFA abuse, conditional access bypass, privileged role manipulation.
Diagnostic settings deletion, policy bypass, RBAC escalation, subscription-level changes.
Key Vault secret access, blob mass download, storage public access, cross-tenant copy.
VM extension execution, automation runbook abuse, function app creation, batch job manipulation.
High and critical severity Defender for Cloud findings mapped to ATT&CK.
NSG all-inbound rules, VPN gateway changes, private endpoint creation, DNS zone modification.
Detection rules (20 of 72 shown)
Showing 20 representative rules. All 72 rules activate with one click.
| Rule name | Severity |
|---|---|
| Azure Diagnostic Settings Deleted | Critical |
| Azure Policy Disabled or Deleted | High |
| Entra ID Conditional Access Policy Disabled | Critical |
| Azure Key Vault Secret Accessed by Unusual Principal | High |
| Azure Key Vault Soft Delete Disabled | Critical |
| Azure Storage Blob Public Access Enabled | High |
| Mass Azure Blob Download — Exfiltration Pattern | High |
| Azure RBAC Owner Role Assigned to External Identity | Critical |
| Azure Privileged Identity Management Alert Fired | High |
| Entra ID MFA Fraud Report Submitted | Critical |
| Entra ID Sign-In from Anonymous Proxy | High |
| Azure VM Extension Added to Running Instance | High |
| Azure Network Security Group Rule Allows All Inbound | High |
| Defender for Cloud Alert — High Severity | Critical |
| Azure Automation Runbook Created or Modified | Medium |
| Entra ID Application Credential Added (New Secret or Certificate) | High |
| Azure Subscription-Level Role Assignment Created | Critical |
| Entra ID Impossible Travel Sign-In | High |
| Azure Resource Group Deleted | High |
| Entra ID Global Administrator Added | Critical |
Prerequisites
- Azure Diagnostic Settings configured to stream Activity Logs to Event Hub or Log Analytics workspace
- Entra ID sign-in and audit logs exported to the same Log Analytics workspace
- Microsoft Defender for Cloud enabled at Standard tier with auto-provisioning
- Azure Key Vault and Storage diagnostic settings enabled per resource
Azure Detection Pack: frequently asked questions
What Azure services does this detection pack cover?
The Azure detection pack covers Azure Activity Logs (management plane), Entra ID (formerly Azure AD) sign-in and audit logs, Microsoft Defender for Cloud alerts, Azure Key Vault diagnostic logs, Azure Storage diagnostic logs, and Azure Network Watcher flow logs. Full coverage requires diagnostic settings configured to send logs to a Log Analytics workspace or Event Hub.
Does this pack cover Entra ID identity threats separately from Azure resource threats?
Yes. The pack includes a dedicated Entra ID sub-set covering MFA abuse, Conditional Access bypass, impossible travel, and privileged role manipulation. Azure resource threats (Activity Log, Defender for Cloud) are covered separately, and ManySignal correlates identity and resource events into unified investigation timelines.
How does ManySignal ingest Azure logs?
ManySignal connects via Azure Event Hub streaming or direct Log Analytics workspace query. The connector supports both real-time streaming (sub-minute latency) and historical backfill. Diagnostic settings must be configured for each resource type you want to monitor.
Can the pack detect Azure lateral movement into on-premises environments?
Yes — where Microsoft Defender for Identity is deployed, ManySignal ingests identity-based lateral movement alerts for hybrid environments. Pass-the-Hash, Kerberoasting, and DCSync alerts from Defender for Identity are included in the pack.
How does this pack handle Azure Government or sovereign clouds?
ManySignal's Azure connector supports Azure Commercial, Azure Government (US Gov Virginia/Texas), and Azure China endpoints. The Event Hub and Log Analytics URIs are configurable per environment.
Full Azure threat coverage in minutes
One-click activation deploys 72 Azure detection rules with ATT&CK mapping, severity triage, and automated investigation timelines.