Azure Activity Logs: Azure Kubernetes Connected Cluster Created or Deleted
Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.
- Product
- azure
- Service
- activitylogs
- Author
- Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-08-07
- Updated
- 2026-07-31
ATT&CK techniques
ImpactRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
What it detects
This rule flags Azure Activity Log events where a connected Kubernetes cluster is created or deleted. Such operations are high-impact because attackers can disrupt availability or establish infrastructure for containerized workloads. It relies on Azure Activity Logs entries with operationName values for connected cluster write and delete actions, allowing correlation by identity and client metadata during investigation.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- microsoft.comhttps://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- microsoft.comhttps://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- medium.comhttps://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_cluster_created_or_deleted.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Azure Activity Logs: Azure Kubernetes Connected Cluster Created or Deleted"
id: 387fa0a1-81f6-499e-b9aa-4f63ec117ca2
status: test
description: This rule flags Azure Activity Log events where a connected Kubernetes cluster is created or deleted. Such operations are high-impact because attackers can disrupt availability or establish infrastructure for containerized workloads. It relies on Azure Activity Logs entries with operationName values for connected cluster write and delete actions, allowing correlation by identity and client metadata during investigation.
references:
- https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes
- https://www.microsoft.com/security/blog/2021/03/23/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes/
- https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
- https://medium.com/mitre-engenuity/att-ck-for-containers-now-available-4c2359654bf1
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/activity_logs/azure_kubernetes_cluster_created_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-08-07
modified: 2022-08-23
tags:
- attack.impact
- attack.t1485
- attack.t1496
- attack.t1489
logsource:
product: azure
service: activitylogs
detection:
selection:
operationName:
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/WRITE
- MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/DELETE
condition: selection
falsepositives:
- Kubernetes cluster being created or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Kubernetes cluster created or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 9541f321-7cba-4b43-80fc-fbd1fb922808
type: derived