cd

5 min read

AzureActivity - VM: Password Reset through EnableAccess VM Extension

Description

This query detects when the VM administrator account is reset through EnableAccess VM extension.

Query

AzureActivity
| where OperationNameValue == "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/WRITE"
| where Properties contains "enablevmaccess"
| where ActivityStatusValue == "Success"
| extend entity = parse_json(Properties).entity
| extend VMName = tostring(split(entity, "/")[8])
| project TimeGenerated, CorrelationId, Caller, CallerIpAddress, SubscriptionId, ResourceGroup, VMName, _ResourceId

MITRE ATT&CK

IDTechniqueTactic
T1651Cloud Administration CommandExecution

Analytic Rule

  • Yaml:
  • ARM:

Notes