Azure Audit Logs: Application URI Configuration Changes (AppAddress)

Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.

FreeReviewedSigma · High · v5
Product
azure
Service
auditlogs
Author
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' (SigmaHQ), DRL 1.1
Published
2022-06-02
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule flags events where an application’s AppAddress property is updated, indicating a change to an application URI configuration. Attackers may alter application URIs to redirect access flows, enable persistence, or capture credentials by pointing to attacker-controlled or improperly scoped domains. It relies on Azure audit log telemetry containing the specific message and property name associated with updating the AppAddress value.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Suspicious Google Cloud Function Create or Update Triggering Build
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Entra ID Device Code Flow Authentication
Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.