Suspicious Azure Network Security Group Rule Opening Inbound Access to the Internet

PremiumReviewedSigma · Medium · v1
Product
azure
Service
activitylogs
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects a Microsoft.Network/networkSecurityGroups/securityRules/write operation that creates an allow inbound rule with an unrestricted source, exposing resources to the entire Internet. Adversaries modify NSG rules to open management ports or services for later remote access after gaining cloud control-plane permissions. This is important because Internet-exposed inbound rules sharply increase attack surface and often precede lateral movement or data access.

Related detections6 linkedT1686.001 — drag to rearrange
Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail
AWS CloudTrail: CreateRoute Adds New Network Route to a Route Table
AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Azure Network Firewall Policy Modified or Deleted via Activity Logs
Azure Firewall Rule Collection Modified or Deleted via Activity Logs
Azure Firewall Created, Modified, or Deleted via Activity Log
Suspicious Azure Network Security Group Rule Opening Inbound Access to the Internet
Pivot detection · T1686.001 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.