Azure Activity Logs: Container Registry Created or Deleted

Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.

FreeUnreviewedSigmalowv1
title: "Azure Activity Logs: Container Registry Created or Deleted"
id: 1723d75a-cf12-40a6-9923-06aee0a96962
status: test
description: This rule identifies Microsoft Container Registry write and delete operations recorded in Azure Activity Logs. Creating or deleting a registry can enable attackers to disrupt image storage or manipulate where container images are pulled from. It relies on telemetry fields that capture the operation name for Container Registry registry write and delete actions.
references:
  - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
  - https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
  - https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
  - https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_container_registry_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
  - attack.impact
  - attack.t1485
  - attack.t1496
  - attack.t1489
logsource:
  product: azure
  service: activitylogs
detection:
  selection:
    operationName:
      - MICROSOFT.CONTAINERREGISTRY/REGISTRIES/WRITE
      - MICROSOFT.CONTAINERREGISTRY/REGISTRIES/DELETE
  condition: selection
falsepositives:
  - Container Registry being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - Container Registry created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
  - id: 93e0ef48-37c8-49ed-a02c-038aab23628e
    type: derived

What it detects

This rule identifies Microsoft Container Registry write and delete operations recorded in Azure Activity Logs. Creating or deleting a registry can enable attackers to disrupt image storage or manipulate where container images are pulled from. It relies on telemetry fields that capture the operation name for Container Registry registry write and delete actions.

Known false positives

  • Container Registry being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • Container Registry created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.