M ManySignal
Detection Pack Microsoft Azure

Azure Detection Pack

72 production-ready detection rules covering Azure Activity Logs, Entra ID, Microsoft Defender for Cloud, Key Vault, and Storage. Activate once — get full MITRE ATT&CK coverage for your Azure environment.

Pack summary

Detection rules
72
Critical severity
21
Data sources
9
ATT&CK techniques
26

What's included

72 rules across 7 threat categories targeting the most common Azure attack patterns.

Identity & Access 22 rules

Entra ID sign-in anomalies, MFA abuse, conditional access bypass, privileged role manipulation.

Management Plane Tampering 16 rules

Diagnostic settings deletion, policy bypass, RBAC escalation, subscription-level changes.

Data Access & Exfiltration 12 rules

Key Vault secret access, blob mass download, storage public access, cross-tenant copy.

Compute Abuse 8 rules

VM extension execution, automation runbook abuse, function app creation, batch job manipulation.

Defender for Cloud Alerts 7 rules

High and critical severity Defender for Cloud findings mapped to ATT&CK.

Network & Firewall 7 rules

NSG all-inbound rules, VPN gateway changes, private endpoint creation, DNS zone modification.

Detection rules (20 of 72 shown)

Showing 20 representative rules. All 72 rules activate with one click.

Rule name Severity
Azure Diagnostic Settings Deleted Critical
Azure Policy Disabled or Deleted High
Entra ID Conditional Access Policy Disabled Critical
Azure Key Vault Secret Accessed by Unusual Principal High
Azure Key Vault Soft Delete Disabled Critical
Azure Storage Blob Public Access Enabled High
Mass Azure Blob Download — Exfiltration Pattern High
Azure RBAC Owner Role Assigned to External Identity Critical
Azure Privileged Identity Management Alert Fired High
Entra ID MFA Fraud Report Submitted Critical
Entra ID Sign-In from Anonymous Proxy High
Azure VM Extension Added to Running Instance High
Azure Network Security Group Rule Allows All Inbound High
Defender for Cloud Alert — High Severity Critical
Azure Automation Runbook Created or Modified Medium
Entra ID Application Credential Added (New Secret or Certificate) High
Azure Subscription-Level Role Assignment Created Critical
Entra ID Impossible Travel Sign-In High
Azure Resource Group Deleted High
Entra ID Global Administrator Added Critical

Prerequisites

  • Azure Diagnostic Settings configured to stream Activity Logs to Event Hub or Log Analytics workspace
  • Entra ID sign-in and audit logs exported to the same Log Analytics workspace
  • Microsoft Defender for Cloud enabled at Standard tier with auto-provisioning
  • Azure Key Vault and Storage diagnostic settings enabled per resource

Azure Detection Pack: frequently asked questions

What Azure services does this detection pack cover?

The Azure detection pack covers Azure Activity Logs (management plane), Entra ID (formerly Azure AD) sign-in and audit logs, Microsoft Defender for Cloud alerts, Azure Key Vault diagnostic logs, Azure Storage diagnostic logs, and Azure Network Watcher flow logs. Full coverage requires diagnostic settings configured to send logs to a Log Analytics workspace or Event Hub.

Does this pack cover Entra ID identity threats separately from Azure resource threats?

Yes. The pack includes a dedicated Entra ID sub-set covering MFA abuse, Conditional Access bypass, impossible travel, and privileged role manipulation. Azure resource threats (Activity Log, Defender for Cloud) are covered separately, and ManySignal correlates identity and resource events into unified investigation timelines.

How does ManySignal ingest Azure logs?

ManySignal connects via Azure Event Hub streaming or direct Log Analytics workspace query. The connector supports both real-time streaming (sub-minute latency) and historical backfill. Diagnostic settings must be configured for each resource type you want to monitor.

Can the pack detect Azure lateral movement into on-premises environments?

Yes — where Microsoft Defender for Identity is deployed, ManySignal ingests identity-based lateral movement alerts for hybrid environments. Pass-the-Hash, Kerberoasting, and DCSync alerts from Defender for Identity are included in the pack.

How does this pack handle Azure Government or sovereign clouds?

ManySignal's Azure connector supports Azure Commercial, Azure Government (US Gov Virginia/Texas), and Azure China endpoints. The Event Hub and Log Analytics URIs are configurable per environment.

Full Azure threat coverage in minutes

One-click activation deploys 72 Azure detection rules with ATT&CK mapping, severity triage, and automated investigation timelines.