Azure Activity Logs: Container Registry Created or Deleted
Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.
FreeUnreviewedSigmalowv1
azure-activity-logs-container-registry-created-or-deleted-93e0ef48
title: "Azure Activity Logs: Container Registry Created or Deleted"
id: 1723d75a-cf12-40a6-9923-06aee0a96962
status: test
description: This rule identifies Microsoft Container Registry write and delete operations recorded in Azure Activity Logs. Creating or deleting a registry can enable attackers to disrupt image storage or manipulate where container images are pulled from. It relies on telemetry fields that capture the operation name for Container Registry registry write and delete actions.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_container_registry_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.CONTAINERREGISTRY/REGISTRIES/WRITE
- MICROSOFT.CONTAINERREGISTRY/REGISTRIES/DELETE
condition: selection
falsepositives:
- Container Registry being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Container Registry created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 93e0ef48-37c8-49ed-a02c-038aab23628e
type: derived
What it detects
This rule identifies Microsoft Container Registry write and delete operations recorded in Azure Activity Logs. Creating or deleting a registry can enable attackers to disrupt image storage or manipulate where container images are pulled from. It relies on telemetry fields that capture the operation name for Container Registry registry write and delete actions.
Known false positives
- Container Registry being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Container Registry created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.