Suspicious Azure NSG Rule Opening SSH to the Internet

PremiumReviewedSigma · Medium · v1
Product
azure
Service
activitylogs
Author
HuntRule
Published
2026-05-16
Updated
2026-08-28

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation or modification of a Network Security Group rule that exposes SSH port 22 to any source address, the network-backdoor action performed in the Azure Fabric intrusion to enable inbound remote access. Opening management ports to 0.0.0.0/0 is a high-risk change and a common cloud persistence step.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.