Azure Activity Logs: Container Registry Created or Deleted
Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.
FreeReviewedSigma · Low · v5
- Product
- azure
- Service
- activitylogs
- Author
- Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-08-07
- Updated
- 2026-07-31
ATT&CK techniques
ImpactRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
What it detects
This rule flags Azure Activity Log events where a Container Registry is created or deleted. Such changes can impact where container images are stored and retrieved, making them a relevant signal for persistence and disruption attempts. It relies on activity log records containing operationName values for Microsoft.ContainerRegistry/registries WRITE and DELETE.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- microsoft.comhttps://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- microsoft.comhttps://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- medium.comhttps://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_container_registry_created_or_deleted.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
azure-activity-logs-container-registry-created-or-deleted-93e0ef48
title: "Azure Activity Logs: Container Registry Created or Deleted"
id: 1723d75a-cf12-40a6-9923-06aee0a96962
status: test
description: This rule flags Azure Activity Log events where a Container Registry is created or deleted. Such changes can impact where container images are stored and retrieved, making them a relevant signal for persistence and disruption attempts. It relies on activity log records containing operationName values for Microsoft.ContainerRegistry/registries WRITE and DELETE.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_container_registry_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.CONTAINERREGISTRY/REGISTRIES/WRITE
- MICROSOFT.CONTAINERREGISTRY/REGISTRIES/DELETE
condition: selection
falsepositives:
- Container Registry being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Container Registry created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 93e0ef48-37c8-49ed-a02c-038aab23628e
type: derived