{
  "generated": "2026-08-19",
  "totalAlerts": 493,
  "deprecatedCount": 130,
  "alerts": [
    {
      "id": "not documented",
      "name": "A logon from a malicious IP has been detected. [seen multiple times]",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "A successful remote authentication for the account [account] and process [process] occurred, however the logon IP address (x.x.x.x) has previously been reported as malicious or highly unusual. A successful attack has probably occurred. Files with the .scr extensions are screen saver files and are normally reside and execute from the Windows system directory.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Addition of Guest account to Local Administrators group",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected the addition of the built-in Guest account to the Local Administrators group on %{Compromised Host}, which is strongly associated with attacker activity.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "An event log was cleared",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate a suspicious event log clearing operation by user: '%{user name}' in Machine: '%{CompromisedEntity}'. The %{log channel} log was cleared.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Antimalware Action Failed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Microsoft Antimalware has encountered an error when taking an action on malware or other potentially unwanted software.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Antimalware Action Taken",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Microsoft Antimalware for Azure has taken an action to protect this machine from malware or other potentially unwanted software.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_AmBroadFilesExclusion",
      "name": "Antimalware broad files exclusion in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Files exclusion from antimalware extension with broad exclusion rule was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Such exclusion practically disabling the Antimalware protection. Attackers might exclude files from the antimalware scan on your virtual machine to prevent detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_AmDisablementAndCodeExecution",
      "name": "Antimalware disabled and code execution in your virtual machine",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Antimalware disabled at the same time as code execution on your virtual machine. This was detected by analyzing Azure Resource Manager operations in your subscription. Attackers disable antimalware scanners to prevent detection while running unauthorized tools or infecting the machine with malware.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_AmDisablement",
      "name": "Antimalware disabled in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Antimalware disabled in your virtual machine. This was detected by analyzing Azure Resource Manager operations in your subscription. Attackers might disable the antimalware on your virtual machine to prevent detection.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_AmFileExclusionAndCodeExecution",
      "name": "Antimalware file exclusion and code execution in your virtual machine",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "File excluded from your antimalware scanner at the same time as code was executed via a custom script extension on your virtual machine. This was detected by analyzing Azure Resource Manager operations in your subscription. Attackers might exclude files from the antimalware scan on your virtual machine to prevent detection while running unauthorized tools or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "VM_AmTempFileExclusionAndCodeExecution",
      "name": "Antimalware file exclusion and code execution in your virtual machine (temporary)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Temporary file exclusion from antimalware extension in parallel to execution of code via custom script extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might exclude files from the antimalware scan on your virtual machine to prevent detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "VM_AmTempFileExclusion",
      "name": "Antimalware file exclusion in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "File excluded from your antimalware scanner on your virtual machine. This was detected by analyzing Azure Resource Manager operations in your subscription. Attackers might exclude files from the antimalware scan on your virtual machine to prevent detection while running unauthorized tools or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_AmRealtimeProtectionDisabled",
      "name": "Antimalware real-time protection was disabled in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Real-time protection disablement of the antimalware extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might disable real-time protection from the antimalware scan on your virtual machine to avoid detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_AmTempRealtimeProtectionDisablement",
      "name": "Antimalware real-time protection was disabled temporarily in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Real-time protection temporary disablement of the antimalware extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might disable real-time protection from the antimalware scan on your virtual machine to avoid detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_AmRealtimeProtectionDisablementAndCodeExec",
      "name": "Antimalware real-time protection was disabled temporarily while code was executed in your virtual machine",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Real-time protection temporary disablement of the antimalware extension in parallel to code execution via custom script extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might disable real-time protection from the antimalware scan on your virtual machine to avoid detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_AmMalwareCampaignRelatedExclusion",
      "name": "Antimalware scans blocked for files potentially related to malware campaigns on your virtual machine (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "An exclusion rule was detected in your virtual machine to prevent your antimalware extension scanning certain files that are suspected of being related to a malware campaign. The rule was detected by analyzing the Azure Resource Manager operations in your subscription. Attackers might exclude files from antimalware scans to prevent detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_AmTemporarilyDisablement",
      "name": "Antimalware temporarily disabled in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Antimalware temporarily disabled in your virtual machine. This was detected by analyzing Azure Resource Manager operations in your subscription. Attackers might disable the antimalware on your virtual machine to prevent detection.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_UnusualAmFileExclusion",
      "name": "Antimalware unusual file exclusion in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Unusual file exclusion from antimalware extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might exclude files from the antimalware scan on your virtual machine to prevent detection while running arbitrary code or infecting the machine with malware.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "AzureDNS_ThreatIntelSuspectDomain",
      "name": "Communication with suspicious domain identified by threat intelligence",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Communication with suspicious domain was detected by analyzing DNS transactions from your resource and comparing against known malicious domains identified by threat intelligence feeds. Communication to malicious domains is frequently performed by attackers and could imply that your resource is compromised.",
      "mitreTactics": [
        "Initial Access",
        "Persistence",
        "Execution",
        "Command and Control",
        "Exploitation"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected actions indicative of disabling and deleting IIS log files",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected actions that show IIS log files being disabled and/or deleted.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected anomalous mix of upper and lower case characters in command-line",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a command line with anomalous mix of upper and lower case characters. This kind of pattern, while possibly benign, is also typical of attackers trying to hide from case-sensitive or hash-based rule matching when performing administrative tasks on a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected change to a registry key that can be abused to bypass UAC",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected that a registry key that can be abused to bypass UAC (User Account Control) was changed. This kind of configuration, while possibly benign, is also typical of attacker activity when trying to move from unprivileged (standard user) to privileged (for example administrator) access on a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected decoding of an executable using built-in certutil.exe tool",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected that certutil.exe, a built-in administrator utility, was being used to decode an executable instead of its mainstream purpose that relates to manipulating certificates and certificate data. Attackers are known to abuse functionality of legitimate administrator tools to perform malicious actions, for example using a tool such as certutil.exe to decode a malicious executable that will then be subsequently executed.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected enabling of the WDigest UseLogonCredential registry key",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected a change in the registry key HKLM\\SYSTEM\\ CurrentControlSet\\Control\\SecurityProviders\\WDigest\\ \"UseLogonCredential\". Specifically this key has been updated to allow logon credentials to be stored in clear text in LSA memory. Once enabled, an attacker can dump clear text passwords from LSA memory with credential harvesting tools such as Mimikatz.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected encoded executable in command line data",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a base-64 encoded executable. This has previously been associated with attackers attempting to construct executables on-the-fly through a sequence of commands, and attempting to evade intrusion detection systems by ensuring that no individual command would trigger an alert. This could be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected obfuscated command line",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Attackers use increasingly complex obfuscation techniques to evade detections that run against the underlying data. Analysis of host data on %{Compromised Host} detected suspicious indicators of obfuscation on the commandline.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected possible execution of keygen executable",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected execution of a process whose name is indicative of a keygen tool; such tools are typically used to defeat software licensing mechanisms but their download is often bundled with other malicious software. Activity group GOLD has been known to make use of such keygens to covertly gain back door access to hosts that they compromise.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected possible execution of malware dropper",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a filename that has previously been associated with one of activity group GOLD's methods of installing malware on a victim host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected possible local reconnaissance activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a combination of systeminfo commands that has previously been associated with one of activity group GOLD's methods of performing reconnaissance activity. While 'systeminfo.exe' is a legitimate Windows tool, executing it twice in succession in the way that has occurred here is rare.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected potentially suspicious use of Telegram tool",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data shows installation of Telegram, a free cloud-based instant messaging service that exists both for mobile and desktop system. Attackers are known to abuse this service to transfer malicious binaries to any other computer, phone, or tablet.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suppression of legal notice displayed to users at logon",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected changes to the registry key that controls whether a legal notice is displayed to users when they log on. Microsoft security analysis has determined that this is a common activity undertaken by attackers after having compromised a host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious combination of HTA and PowerShell",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "mshta.exe (Microsoft HTML Application Host) which is a signed Microsoft binary is being used by the attackers to launch malicious PowerShell commands. Attackers often resort to having an HTA file with inline VBScript. When a victim browses to the HTA file and chooses to run it, the PowerShell commands and scripts that it contains are executed. Analysis of host data on %{Compromised Host} detected mshta.exe launching PowerShell commands.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious commandline arguments",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected suspicious commandline arguments that have been used in conjunction with a reverse shell used by activity group HYDROGEN.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious commandline used to start all executables in a directory",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected a suspicious process running on %{Compromised Host}. The commandline indicates an attempt to start all executables (\\*.exe) that might reside in a directory. This could be an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious credentials in commandline",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a suspicious password being used to execute a file by activity group BORON. This activity group has been known to use this password to execute Pirpi malware on a victim host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious document credentials",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a suspicious, common precomputed password hash used by malware being used to execute a file. Activity group HYDROGEN has been known to use this password to execute malware on a victim host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious execution of VBScript.Encode command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of VBScript.Encode command. This encodes the scripts into unreadable text, making it more difficult for users to examine the code. Microsoft threat research shows that attackers often use encoded VBscript files as part of their attack to evade detection systems. This could be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious execution via rundll32.exe",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected rundll32.exe being used to execute a process with an uncommon name, consistent with the process naming scheme previously seen used by activity group GOLD when installing their first stage implant on a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious file cleanup commands",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a combination of systeminfo commands that has previously been associated with one of activity group GOLD's methods of performing post-compromise self-cleanup activity. While 'systeminfo.exe' is a legitimate Windows tool, executing it twice in succession, followed by a delete command in the way that has occurred here is rare.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious file creation",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected creation or execution of a process that has previously indicated post-compromise action taken on a victim host by activity group BARIUM. This activity group has been known to use this technique to download more malware to a compromised host after an attachment in a phishing doc has been opened.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious named pipe communications",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected data being written to a local named pipe from a Windows console command. Named pipes are known to be a channel used by attackers to task and communicate with a malicious implant. This could be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious network activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of network traffic from %{Compromised Host} detected suspicious network activity. Such traffic, while possibly benign, is typically used by an attacker to communicate with malicious servers for downloading of tools, command-and-control and exfiltration of data. Typical related attacker activity includes copying remote administration tools to a compromised host and exfiltrating user data from it.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious new firewall rule",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected a new firewall rule has been added via netsh.exe to allow traffic from an executable in a suspicious location.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious use of Cacls to lower the security state of the system",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Attackers use myriad ways like brute force, spear phishing etc. to achieve initial compromise and get a foothold on the network. Once initial compromise is achieved they often take steps to lower the security settings of a system. Caclsâ€”short for change access control list is Microsoft Windows native command-line utility often used for modifying the security permission on folders and files. A lot of time the binary is used by the attackers to lower the security settings of a system. This is do",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious use of FTP -s Switch",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of process creation data from the %{Compromised Host} detected the use of the FTP \"-s:filename\" switch. This switch is used to specify an FTP script file for the client to run. Malware or malicious processes are known to use this FTP switch (-s:filename) to point to a script file, which is configured to connect to a remote FTP server and download more malicious binaries.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious use of Pcalua.exe to launch executable code",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the use of pcalua.exe to launch executable code. Pcalua.exe is component of the Microsoft Windows \"Program Compatibility Assistant\", which detects compatibility issues during the installation or execution of a program. Attackers are known to abuse functionality of legitimate Windows system tools to perform malicious actions, for example using pcalua.exe with the -a switch to launch malicious executables either locally or from remote shares.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected the disabling of critical services",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The analysis of host data on %{Compromised Host} detected execution of \"net.exe stop\" command being used to stop critical services like SharedAccess or the Windows Security app. The stopping of either of these services can be indication of a malicious behavior.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Digital currency mining related behavior detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of a process or command normally associated with digital currency mining.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Dynamic PS script construction",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a PowerShell script being constructed dynamically. Attackers sometimes use this approach of progressively building up a script in order to evade IDS systems. This could be legitimate activity, or an indication that one of your machines has been compromised.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Executable found running from a suspicious location",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected an executable file on %{Compromised Host} that is running from a location in common with known suspicious files. This executable could either be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_FilelessAttackBehavior.Windows",
      "name": "Fileless attack behavior detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified contains behaviors commonly used by fileless attacks. Specific behaviors include: 1. Shellcode, which is a small piece of code typically used as the payload in the exploitation of a software vulnerability. 2. Active network connections. See NetworkConnections below for details. 3. Function calls to security sensitive operating system interfaces. See Capabilities below for referenced OS capabilities. 4. Contains a thread that was started in a dynamically alloca",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "VM_FilelessAttackTechnique.Windows",
      "name": "Fileless attack technique detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified below contains evidence of a fileless attack technique. Fileless attacks are used by attackers to execute code while evading detection by security software. Specific behaviors include: 1. Shellcode, which is a small piece of code typically used as the payload in the exploitation of a software vulnerability. 2. Executable image injected into the process, such as in a code injection attack. 3. Active network connections. See NetworkConnections below for details.",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "VM_FilelessAttackToolkit.Windows",
      "name": "Fileless attack toolkit detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified contains a fileless attack toolkit: [toolkit name]. Fileless attack toolkits use techniques that minimize or eliminate traces of malware on disk, and greatly reduce the chances of detection by disk-based malware scanning solutions. Specific behaviors include: 1. Well-known toolkits and crypto mining software. 2. Shellcode, which is a small piece of code typically used as the payload in the exploitation of a software vulnerability. 3. Injected malicious executa",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "High risk software detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data from %{Compromised Host} detected the usage of software that has been associated with the installation of malware in the past. A common technique utilized in the distribution of malicious software is to package it within otherwise benign tools such as the one seen in this alert. When you use these tools, the malware can be silently installed in the background.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Local Administrators group members were enumerated",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate a successful enumeration on group %{Enumerated Group Domain Name}%{Enumerated Group Name}. Specifically, %{Enumerating User Domain Name}%{Enumerating User Name} remotely enumerated the members of the %{Enumerated Group Domain Name}%{Enumerated Group Name} group. This activity could either be legitimate activity, or an indication that a machine in your organization has been compromised and used to reconnaissance %{vmname}.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Malicious firewall rule created by ZINC server implant [seen multiple times]",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "A firewall rule was created using techniques that match a known actor, ZINC. The rule was possibly used to open a port on %{Compromised Host} to allow for Command & Control communications. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Malicious SQL activity",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate that '%{process name}' was executed by account: %{user name}. This activity is considered malicious.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Multiple Domain Accounts Queried",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has determined that an unusual number of distinct domain accounts are being queried within a short time period from %{Compromised Host}. This kind of activity could be legitimate, but can also be an indication of compromise.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Possible credential dumping detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected use of native windows tool (for example, sqldumper.exe) being used in a way that allows to extract credentials from memory. Attackers often use these techniques to extract credentials that they then further use for lateral movement and privilege escalation. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SvcHostRunInRareServiceGroup",
      "name": "Rare SVCHOST service group executed",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The system process SVCHOST was observed running a rare service group. Malware often uses SVCHOST to masquerade its malicious activity.",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Sticky keys attack detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data indicates that an attacker might be subverting an accessibility binary (for example sticky keys, onscreen keyboard, narrator) in order to provide backdoor access to the host %{Compromised Host}.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_LoginBruteForceSuccess",
      "name": "Successful brute force attack",
      "severity": "Medium/High",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Several sign in attempts were detected from the same source. Some successfully authenticated to the host. This resembles a burst attack, in which an attacker performs numerous authentication attempts to find valid account credentials.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspect integrity level indicative of RDP hijacking",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected the tscon.exe running with SYSTEM privileges - this can be indicative of an attacker abusing this binary in order to switch context to any other logged on user on this host; it's a known attacker technique to compromise more user accounts and move laterally across a network.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspect service installation",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected the installation of tscon.exe as a service: this binary being started as a service potentially allows an attacker to trivially switch to any other logged on user on this host by hijacking RDP connections; it's a known attacker technique to compromise more user accounts and move laterally across a network.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspected Kerberos Golden Ticket attack parameters observed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected commandline parameters consistent with a Kerberos Golden Ticket attack.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious Account Creation Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected creation or use of a local account %{Suspicious account name} : this account name closely resembles a standard Windows account or group name '%{Similar To Account Name}'. This is potentially a rogue account created by an attacker, so named in order to avoid being noticed by a human administrator.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspiciousActivity",
      "name": "Suspicious Activity Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected a sequence of one or more processes running on %{machine name} that have historically been associated with malicious activity. While individual commands might appear benign the alert is scored based on an aggregation of these commands. This could either be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_LoginBruteForceValidUserFailed",
      "name": "Suspicious authentication activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Although none of them succeeded, some of them used accounts were recognized by the host. This resembles a dictionary attack, in which an attacker performs numerous authentication attempts using a dictionary of predefined account names and passwords in order to find valid credentials to access the host. This indicates that some of your host account names might exist in a well-known account name dictionary.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious code segment detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Indicates that a code segment has been allocated by using non-standard methods, such as reflective injection and process hollowing. The alert provides more characteristics of the code segment that have been processed to provide context for the capabilities and behaviors of the reported code segment.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious double extension file executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data indicates an execution of a process with a suspicious double extension. This extension might trick users into thinking files are safe to be opened and might indicate the presence of malware on the system.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious download using Certutil detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the use of certutil.exe, a built-in administrator utility, for the download of a binary instead of its mainstream purpose that relates to manipulating certificates and certificate data. Attackers are known to abuse functionality of legitimate administrator tools to perform malicious actions, for example using certutil.exe to download and decode a malicious executable that will then be subsequently executed. This behavior was seen [x] times to",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious download using Certutil detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the use of certutil.exe, a built-in administrator utility, for the download of a binary instead of its mainstream purpose that relates to manipulating certificates and certificate data. Attackers are known to abuse functionality of legitimate administrator tools to perform malicious actions, for example using certutil.exe to download and decode a malicious executable that will then be subsequently executed.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious PowerShell Activity Detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data detected a PowerShell script running on %{Compromised Host} that has features in common with known suspicious scripts. This script could either be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious PowerShell cmdlets executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data indicates execution of known malicious PowerShell PowerSploit cmdlets.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious process executed [seen multiple times]",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate that the suspicious process: '%{Suspicious Process}' was running on the machine, often associated with attacker attempts to access credentials. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate that the suspicious process: '%{Suspicious Process}' was running on the machine, often associated with attacker attempts to access credentials.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious process name detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a process whose name is suspicious, for example corresponding to a known attacker tool or named in a way that is suggestive of attacker tools that try to hide in plain sight. This process could be legitimate activity, or an indication that one of your machines has been compromised. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious SQL activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate that '%{process name}' was executed by account: %{user name}. This activity is uncommon with this account.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious SVCHOST process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The system process SVCHOST was observed running in an abnormal context. Malware often uses SVCHOST to masquerade its malicious activity.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SystemProcessInAbnormalContext",
      "name": "Suspicious system process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "The system process %{process name} was observed running in an abnormal context. Malware often uses this process name to masquerade its malicious activity.",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious Volume Shadow Copy Activity",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected a shadow copy deletion activity on the resource. Volume Shadow Copy (VSC) is an important artifact that stores data snapshots. Some malware and specifically Ransomware, targets VSC to sabotage backup strategies.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious WindowPosition registry value detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected an attempted WindowPosition registry configuration change that could be indicative of hiding application windows in nonvisible sections of the desktop. This could be legitimate activity, or an indication of a compromised machine: this type of activity has been previously associated with known adware (or unwanted software) such as Win32/OneSystemCare and Win32/SystemHealer and malware such as Win32/Creprote. When the WindowPosition value is se",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspiciously named process detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a process whose name is very similar to but different from a very commonly run process (%{Similar To Process Name}). While this process could be benign attackers are known to sometimes hide in plain sight by naming their malicious tools to resemble legitimate process names.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_VMAccessUnusualConfigReset",
      "name": "Unusual config reset in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "An unusual config reset was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. While this action might be legitimate, attackers can try utilizing VM Access extension to reset the configuration in your virtual machine and compromise it.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "not documented",
      "name": "Unusual process execution detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of a process by %{User Name} that was unusual. Accounts such as %{User Name} tend to perform a limited set of operations, this execution was determined to be out of character and might be suspicious.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_VMAccessUnusualPasswordReset",
      "name": "Unusual user password reset in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "An unusual user password reset was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. While this action might be legitimate, attackers can try utilizing the VM Access extension to reset the credentials of a local user in your virtual machine and compromise it.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "VM_VMAccessUnusualSSHReset",
      "name": "Unusual user SSH key reset in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "An unusual user SSH key reset was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. While this action might be legitimate, attackers can try utilizing VM Access extension to reset SSH key of a user account in your virtual machine and compromise it.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "not documented",
      "name": "VBScript HTTP object allocation detected",
      "severity": "Unknown",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Creation of a VBScript file using Command Prompt has been detected. The following script contains HTTP object allocation command. This action can be used to download malicious files.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_GPUDriverExtensionUnusualExecution",
      "name": "Suspicious installation of GPU extension in your virtual machine (Preview)",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "Suspicious installation of a GPU extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use the GPU driver extension to install GPU drivers on your virtual machine via the Azure Resource Manager to perform cryptojacking.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "ARM_AzureHound",
      "name": "AzureHound tool invocation detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Windows)",
      "sourceType": "ms-learn",
      "description": "AzureHound was run in your subscription and performed information gathering operations to enumerate resources. Threat actors use automated tools, like AzureHound, to enumerate resources and use them to access sensitive data or perform lateral movement. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your environment. Note For a",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "not documented",
      "name": "A history file has been cleared",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data indicates that the command history log file has been cleared. Attackers might do this to cover their traces. The operation was performed by user: '%{user name}'.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_AdaptiveApplicationControlLinuxViolationAudited",
      "name": "Adaptive application control policy violation was audited",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "The below users ran applications that are violating the application control policy of your organization on this machine. It can possibly expose the machine to malware or application vulnerabilities.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Behavior similar to ransomware detected [seen multiple times]",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of files that have resemblance of known ransomware that can prevent users from accessing their system or personal files, and demands ransom payment in order to regain access. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_MinerInContainerImage",
      "name": "Container with a miner image detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate execution of a Docker container that runs an image associated with a digital currency mining.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected anomalous mix of upper and lower case characters in command line",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a command line with anomalous mix of upper and lower case characters. This kind of pattern, while possibly benign, is also typical of attackers trying to hide from case-sensitive or hash-based rule matching when performing administrative tasks on a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected file download from a known malicious source",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected the download of a file from a known malware source on %{Compromised Host}.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Detected suspicious network activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of network traffic from %{Compromised Host} detected suspicious network activity. Such traffic, while possibly benign, is typically used by an attacker to communicate with malicious servers for downloading of tools, command-and-control and exfiltration of data. Typical related attacker activity includes copying remote administration tools to a compromised host and exfiltrating user data from it.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Digital currency mining related behavior detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of a process or command normally associated with digital currency mining.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Disabling of auditd logging [seen multiple times]",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "The Linux Audit system provides a way to track security-relevant information on the system. It records as much information about the events that are happening on your system as possible. Disabling auditd logging could hamper discovering violations of security policies used on the system. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Exploitation of Xorg vulnerability [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the user of Xorg with suspicious arguments. Attackers might use this technique in privilege escalation attempts. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SshBruteForceFailed",
      "name": "Failed SSH brute force attack",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Failed brute force attacks were detected from the following attackers: %{Attackers}. Attackers were trying to access the host with the following user names: %{Accounts used on failed sign in to host attempts}.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "VM_FilelessAttackBehavior.Linux",
      "name": "Fileless attack behavior detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified below contains behaviors commonly used by fileless attacks. Specific behaviors include: {list of observed behaviors}",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_FilelessAttackTechnique.Linux",
      "name": "Fileless attack technique detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified below contains evidence of a fileless attack technique. Fileless attacks are used by attackers to execute code while evading detection by security software. Specific behaviors include: {list of observed behaviors}",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_FilelessAttackToolkit.Linux",
      "name": "Fileless attack toolkit detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "The memory of the process specified below contains a fileless attack toolkit: {ToolKitName}. Fileless attack toolkits typically don't have a presence on the filesystem, making detection by traditional anti-virus software difficult. Specific behaviors include: {list of observed behaviors}",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Hidden file execution detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data indicates that a hidden file was executed by %{user name}. This activity could either be legitimate activity, or an indication of a compromised host.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SshKeyAddition",
      "name": "New SSH key added [seen multiple times]",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "A new SSH key was added to the authorized keys file. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "not documented",
      "name": "New SSH key added",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "A new SSH key was added to the authorized keys file.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Possible backdoor detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected a suspicious file being downloaded then run on %{Compromised Host} in your subscription. This activity has previously been associated with installation of a backdoor. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Possible exploitation of the mailserver detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected an unusual execution under the mail server account",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "not documented",
      "name": "Possible malicious web shell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a possible web shell. Attackers will often upload a web shell to a machine they've compromised to gain persistence or for further exploitation.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Possible password change using crypt-method detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected password change using crypt method. Attackers can make this change to continue access and gaining persistence after compromise. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Process associated with digital currency mining detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of a process normally associated with digital currency mining. This behavior was seen over 100 times today on the following machines: [Machine name]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Process associated with digital currency mining detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Host data analysis detected the execution of a process that is normally associated with digital currency mining.",
      "mitreTactics": [
        "Exploitation",
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Python encoded downloader detected [seen multiple times]",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the execution of encoded Python that downloads and runs code from a remote location. This might be an indication of malicious activity. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Screenshot taken on host [seen multiple times]",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected the user of a screen capture tool. Attackers might use these tools to access private data. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Shellcode detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected shellcode being generated from the command line. This process could be legitimate activity, or an indication that one of your machines has been compromised. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SshBruteForceSuccess",
      "name": "Successful SSH brute force attack",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected a successful brute force attack. The IP %{Attacker source IP} was seen making multiple login attempts. Successful logins were made from that IP with the following user(s): %{Accounts used to successfully sign in to host}. This means that the host might be compromised and controlled by a malicious actor.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious Account Creation Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected creation or use of a local account %{Suspicious account name} : this account name closely resembles a standard Windows account or group name '%{Similar To Account Name}'. This is potentially a rogue account created by an attacker, so named in order to avoid being noticed by a human administrator.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious kernel module detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data on %{Compromised Host} detected a shared object file being loaded as a kernel module. This could be legitimate activity, or an indication that one of your machines has been compromised. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious password access [seen multiple times]",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected suspicious access to encrypted user passwords on %{Compromised Host}. This behavior was seen [x] times today on the following machines: [Machine names]",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspicious password access",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Analysis of host data has detected suspicious access to encrypted user passwords on %{Compromised Host}.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_KubernetesDashboard",
      "name": "Suspicious request to the Kubernetes Dashboard",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Servers (Linux)",
      "sourceType": "ms-learn",
      "description": "Machine logs indicate that a suspicious request was made to the Kubernetes Dashboard. The request was sent from a Kubernetes node, possibly from one of the containers running in the node. Although this behavior can be intentional, it might indicate that the node is running a compromised container.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "ARM_OperationFromSuspiciousIP",
      "name": "Azure Resource Manager operation from suspicious IP address",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager detected an operation from an IP address that has been marked as suspicious in threat intelligence feeds.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "ARM_OperationFromSuspiciousProxyIP",
      "name": "Azure Resource Manager operation from suspicious proxy IP address",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager detected a resource management operation from an IP address that is associated with proxy services, such as TOR. While this behavior can be legitimate, it's often seen in malicious activities, when threat actors try to hide their source IP.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_MicroBurst.AzDomainInfo",
      "name": "MicroBurst exploitation toolkit used to enumerate resources in your subscriptions",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed suspicious pattern of executing an information gathering operations to discover resources, permissions, and network structures. Threat actors use automated scripts, like MicroBurst, to gather information for malicious activities. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_MicroBurst.AzureDomainInfo",
      "name": "MicroBurst exploitation toolkit used to enumerate resources in your subscriptions",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed suspicious pattern of executing an information gathering operations to discover resources, permissions, and network structures. Threat actors use automated scripts, like MicroBurst, to gather information for malicious activities. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_MicroBurst.AzVMBulkCMD",
      "name": "MicroBurst exploitation toolkit used to execute code on your virtual machine",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of executing code on a VM or a list of VMs. Threat actors use automated scripts, like MicroBurst, to run a script on a VM for malicious activities. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your environment for malicious intentions.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "RM_MicroBurst.AzureRmVMBulkCMD",
      "name": "MicroBurst exploitation toolkit used to execute code on your virtual machine",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "MicroBurst's exploitation toolkit was used to execute code on your virtual machines. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_MicroBurst.AzKeyVaultKeysREST",
      "name": "MicroBurst exploitation toolkit used to extract keys from your Azure key vaults",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of extracting keys from an Azure Key Vault(s). Threat actors use automated scripts, like MicroBurst, to list keys and use them to access sensitive data or perform lateral movement. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your environment",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_MicroBurst.AZStorageKeysREST",
      "name": "MicroBurst exploitation toolkit used to extract keys to your storage accounts",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of extracting keys to Storage Account(s). Threat actors use automated scripts, like MicroBurst, to list keys and use them to access sensitive data in your Storage Account(s). This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your environment for m",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_MicroBurst.AzKeyVaultSecretsREST",
      "name": "MicroBurst exploitation toolkit used to extract secrets from your Azure key vaults",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of extracting secrets from an Azure Key Vault(s). Threat actors use automated scripts, like MicroBurst, to list secrets and use them to access sensitive data or perform lateral movement. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your envir",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_PowerZure.AzureElevatedPrivileges",
      "name": "PowerZure exploitation toolkit used to elevate access from Microsoft Entra ID to Azure",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit was used to elevate access from AzureAD to Azure. This was detected by analyzing Azure Resource Manager operations in your tenant.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_PowerZure.GetAzureTargets",
      "name": "PowerZure exploitation toolkit used to enumerate resources",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit was used to enumerate resources on behalf of a legitimate user account in your organization. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_PowerZure.ShowStorageContent",
      "name": "PowerZure exploitation toolkit used to enumerate storage containers, shares, and tables",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit was used to enumerate storage shares, tables, and containers. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_PowerZure.StartRunbook",
      "name": "PowerZure exploitation toolkit used to execute a Runbook in your subscription",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit was used to execute a Runbook. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_PowerZure.AzureRunbookContent",
      "name": "PowerZure exploitation toolkit used to extract Runbooks content",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit was used to extract Runbook content. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_Azurite",
      "name": "PREVIEW - FSecure's Azurite toolkit detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A known cloud-environment reconnaissance toolkit run has been detected in your environment. The tool Azurite can be used by an attacker (or penetration tester) to map your subscriptions' resources and identify insecure configurations.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_SuspiciousComputeCreation",
      "name": "Suspicious creation of compute resources detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious creation of compute resources in your subscription utilizing Virtual Machines/Azure Scale Set. The identified operations are designed to allow administrators to efficiently manage their environments by deploying new resources when needed. While this activity might be legitimate, a threat actor might utilize such operations to conduct crypto mining. The activity is deemed suspicious as the compute resources scale is higher than previ",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "Arm_Suspicious_Vault_Recovering",
      "name": "Suspicious key vault recovery detected",
      "severity": "Medium/high",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager detected a suspicious recovery operation for a soft-deleted key vault resource. The user recovering the resource is different from the user that deleted it. This is highly suspicious because the user rarely invokes such an operation. In addition, the user logged on without multifactor authentication (MFA). This might indicate that the user is compromised and is attempting to discover secrets and keys to gain access to sensitive resources, or to perform lat",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "ARM_UnusedAccountPersistence",
      "name": "PREVIEW - Suspicious management session using an inactive account detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Subscription activity logs analysis has detected suspicious behavior. A principal not in use for a long period of time is now performing actions that can secure persistence for an attacker.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.CredentialAccess",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Credential Access' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to access credentials. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the service principal is compr",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.Collection",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Data Collection' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to collect data. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to collect sensitive data on resources in your environment. This can indicate that the service principal is compromised and is being used ",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.DefenseEvasion",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Defense Evasion' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to evade defenses. The identified operations are designed to allow administrators to efficiently manage the security posture of their environments. While this activity might be legitimate, a threat actor might utilize such operations to avoid being detected while compromising resources in your environment. This can indicate that the service pri",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.Execution",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Execution' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation on a machine in your subscription, which might indicate an attempt to execute code. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the service principal i",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.Impact",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Impact' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempted configuration change. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the service principal is comp",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.InitialAccess",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Initial Access' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to access restricted resources. The identified operations are designed to allow administrators to efficiently access their environments. While this activity might be legitimate, a threat actor might utilize such operations to gain initial access to restricted resources in your environment. This can indicate that the service principal is comprom",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.LateralMovement",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Lateral Movement Access' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to perform lateral movement. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to compromise more resources in your environment. This can indicate that the service principal is compromised and is being use",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.Persistence",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'persistence' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to establish persistence. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to establish persistence in your environment. This can indicate that the service principal is compromised and is being used with ",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "ARM_AnomalousServiceOperation.PrivilegeEscalation",
      "name": "PREVIEW - Suspicious invocation of a high-risk 'Privilege Escalation' operation by a service principal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to escalate privileges. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to escalate privileges while compromising resources in your environment. This can indicate that the service principal is compromise",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "ARM_UnusedAppPowershellPersistence",
      "name": "PREVIEW - Suspicious management session using PowerShell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Subscription activity logs analysis has detected suspicious behavior. A principal that doesn't regularly use PowerShell to manage the subscription environment is now using PowerShell, and performing actions that can secure persistence for an attacker.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "ARM_UnusedAppIbizaPersistence",
      "name": "PREVIEW â€“ Suspicious management session using Azure portal detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Analysis of your subscription activity logs has detected a suspicious behavior. A principal that doesn't regularly use the Azure portal (Ibiza) to manage the subscription environment (hasn't used Azure portal to manage for the last 45 days, or a subscription that it is actively managing), is now using the Azure portal and performing actions that can secure persistence for an attacker.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "ARM_PrivilegedRoleDefinitionCreation",
      "name": "Privileged custom role created for your subscription in a suspicious way",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager detected a suspicious creation of privileged custom role definition in your subscription. This operation might have been performed by a legitimate user in your organization. Alternatively, it might indicate that an account in your organization was breached, and that the threat actor is trying to create a privileged role to use in the future to evade detection.",
      "mitreTactics": [
        "Privilege Escalation",
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_AnomalousRBACRoleAssignment",
      "name": "Suspicious Azure role assignment detected (Preview)",
      "severity": "Low (PIM) / High",
      "severityColor": "#6c757d",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious Azure role assignment / performed using PIM (Privileged Identity Management) in your tenant, which might indicate that an account in your organization was compromised. The identified operations are designed to allow administrators to grant principals access to Azure resources. While this activity might be legitimate, a threat actor might utilize role assignment to escalate their permissions allowing them to advance their attack.",
      "mitreTactics": [
        "Lateral Movement",
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.CredentialAccess",
      "name": "Suspicious invocation of a high-risk 'Credential Access' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to access credentials. The identified operations are designed to allow administrators to efficiently access their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the account is compromised and",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.Collection",
      "name": "Suspicious invocation of a high-risk 'Data Collection' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to collect data. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to collect sensitive data on resources in your environment. This can indicate that the account is compromised and is being used with malic",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.DefenseEvasion",
      "name": "Suspicious invocation of a high-risk 'Defense Evasion' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to evade defenses. The identified operations are designed to allow administrators to efficiently manage the security posture of their environments. While this activity might be legitimate, a threat actor might utilize such operations to avoid being detected while compromising resources in your environment. This can indicate that the account is ",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.Execution",
      "name": "Suspicious invocation of a high-risk 'Execution' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation on a machine in your subscription, which might indicate an attempt to execute code. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the account is compromi",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.Impact",
      "name": "Suspicious invocation of a high-risk 'Impact' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempted configuration change. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to access restricted credentials and compromise resources in your environment. This can indicate that the account is compromised an",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.InitialAccess",
      "name": "Suspicious invocation of a high-risk 'Initial Access' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to access restricted resources. The identified operations are designed to allow administrators to efficiently access their environments. While this activity might be legitimate, a threat actor might utilize such operations to gain initial access to restricted resources in your environment. This can indicate that the account is compromised and i",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.LateralMovement",
      "name": "Suspicious invocation of a high-risk 'Lateral Movement' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to perform lateral movement. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to compromise more resources in your environment. This can indicate that the account is compromised and is being used with mal",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "ARM_AnomalousElevateAccess",
      "name": "Suspicious elevate access operation",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious \"Elevate Access\" operation. The activity is deemed suspicious, as this principal rarely invokes such operations. While this activity might be legitimate, a threat actor might utilize an \"Elevate Access\" operation to perform privilege escalation for a compromised user.",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.Persistence",
      "name": "Suspicious invocation of a high-risk 'Persistence' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to establish persistence. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to establish persistence in your environment. This can indicate that the account is compromised and is being used with malicious ",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "ARM_AnomalousOperation.PrivilegeEscalation",
      "name": "Suspicious invocation of a high-risk 'Privilege Escalation' operation detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to escalate privileges. The identified operations are designed to allow administrators to efficiently manage their environments. While this activity might be legitimate, a threat actor might utilize such operations to escalate privileges while compromising resources in your environment. This can indicate that the account is compromised and is b",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "ARM_MicroBurst.RunCodeOnBehalf",
      "name": "Usage of MicroBurst exploitation toolkit to run an arbitrary code or exfiltrate Azure Automation account credentials",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of executing an arbitrary code or exfiltrate Azure Automation account credentials. Threat actors use automated scripts, like MicroBurst, to run arbitrary code for malicious activities. This was detected by analyzing Azure Resource Manager operations in your subscription. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise your environ",
      "mitreTactics": [
        "Persistence",
        "Credential Access"
      ]
    },
    {
      "id": "ARM_NetSPI.MaintainPersistence",
      "name": "Usage of NetSPI techniques to maintain persistence in your Azure environment",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Usage of NetSPI persistence technique to create a webhook backdoor and maintain persistence in your Azure environment. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_PowerZure.RunCodeOnBehalf",
      "name": "Usage of PowerZure exploitation toolkit to run an arbitrary code or exfiltrate Azure Automation account credentials",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "PowerZure exploitation toolkit detected attempting to run code or exfiltrate Azure Automation account credentials. This was detected by analyzing Azure Resource Manager operations in your subscription.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "ARM_AnomalousClassicRoleAssignment",
      "name": "Suspicious classic role assignment detected (Preview)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Resource Manager",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Resource Manager identified a suspicious classic role assignment in your tenant, which might indicate that an account in your organization was compromised. The identified operations are designed to provide backward compatibility with classic roles that are no longer commonly used. While this activity might be legitimate, a threat actor might utilize such assignment to grant permissions to another user account under their control. Note For alerts that are in preview: The Az",
      "mitreTactics": [
        "Lateral Movement",
        "Defense Evasion"
      ]
    },
    {
      "id": "SQL.MI_VulnerabilityToSqlInjection",
      "name": "A possible vulnerability to SQL Injection",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An application generates a faulty SQL statement in the database. This indicates a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might construct the faulty SQL statement. Or, application code or stored procedures don't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Synapse.SQLPool_VulnerabilityToSqlInjection",
      "name": "A possible vulnerability to SQL Injection",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An application generates a faulty SQL statement in the database. This indicates a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might construct the faulty SQL statement. Or, application code or stored procedures don't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DB_VulnerabilityToSqlInjection",
      "name": "A possible vulnerability to SQL Injection",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An application generates a faulty SQL statement in the database. This indicates a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might construct the faulty SQL statement. Or, application code or stored procedures don't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.VM_VulnerabilityToSqlInjection",
      "name": "A possible vulnerability to SQL Injection",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An application generates a faulty SQL statement in the database. This indicates a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might construct the faulty SQL statement. Or, application code or stored procedures don't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_VulnerabilityToSqlInjection",
      "name": "A possible vulnerability to SQL Injection",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An application generates a faulty SQL statement in the database. This indicates a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might construct the faulty SQL statement. Or, application code or stored procedures don't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.VM_HarmfulApplication",
      "name": "Logon activity from a potentially harmful application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DB_HarmfulApplication",
      "name": "Logon activity from a potentially harmful application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_HarmfulApplication",
      "name": "Logon activity from a potentially harmful application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MI_HarmfulApplication",
      "name": "Logon activity from a potentially harmful application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Synapse.SQLPool_HarmfulApplication",
      "name": "Logon activity from a potentially harmful application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.VM_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to an SQL Server, where someone has signed in to the server from an unusual Azure Data Center. In some cases, the alert detects a legitimate action (a new application or Azure service). In other cases, the alert detects a malicious action (attacker operating from breached resource in Azure).",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.MI_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to an SQL Server, where someone has signed in to the server from an unusual Azure Data Center. In some cases, the alert detects a legitimate action (a new application or Azure service). In other cases, the alert detects a malicious action (attacker operating from breached resource in Azure).",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.DW_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to an SQL Server, where someone has signed in to the server from an unusual Azure Data Center. In some cases, the alert detects a legitimate action (a new application or Azure service). In other cases, the alert detects a malicious action (attacker operating from breached resource in Azure).",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "Synapse.SQLPool_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to an SQL Server, where someone has signed in to the server from an unusual Azure Data Center. In some cases, the alert detects a legitimate action (a new application or Azure service). In other cases, the alert detects a malicious action (attacker operating from breached resource in Azure).",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.DB_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to an SQL Server, where someone has signed in to the server from an unusual Azure Data Center. In some cases, the alert detects a legitimate action (a new application or Azure service). In other cases, the alert detects a malicious action (attacker operating from breached resource in Azure).",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.DB_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to SQL Server, where someone has signed in to the server from an unusual geographical location. In some cases, the alert detects a legitimate action (a new application or developer maintenance). In other cases, the alert detects a malicious action (a former employee or external attacker).",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.VM_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to SQL Server, where someone has signed in to the server from an unusual geographical location. In some cases, the alert detects a legitimate action (a new application or developer maintenance). In other cases, the alert detects a malicious action (a former employee or external attacker).",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MI_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to SQL Server, where someone has signed in to the server from an unusual geographical location. In some cases, the alert detects a legitimate action (a new application or developer maintenance). In other cases, the alert detects a malicious action (a former employee or external attacker).",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "Synapse.SQLPool_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to SQL Server, where someone has signed in to the server from an unusual geographical location. In some cases, the alert detects a legitimate action (a new application or developer maintenance). In other cases, the alert detects a malicious action (a former employee or external attacker).",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.DW_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "There has been a change in the access pattern to SQL Server, where someone has signed in to the server from an unusual geographical location. In some cases, the alert detects a legitimate action (a new application or developer maintenance). In other cases, the alert detects a malicious action (a former employee or external attacker).",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.VM_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "Synapse.SQLPool_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MI_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.DB_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.DW_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MI_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "Synapse.SQLPool_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.DW_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.VM_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.DB_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.VM_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Synapse.SQLPool_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DB_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MI_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_PotentialSqlInjection",
      "name": "Potential SQL injection",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An active exploit has occurred against an identified application vulnerable to SQL injection. This means an attacker is trying to inject malicious SQL statements by using the vulnerable application code or stored procedures.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DB_PotentialSqlInjection",
      "name": "Potential SQL injection",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An active exploit has occurred against an identified application vulnerable to SQL injection. This means an attacker is trying to inject malicious SQL statements by using the vulnerable application code or stored procedures.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Synapse.SQLPool_PotentialSqlInjection",
      "name": "Potential SQL injection",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An active exploit has occurred against an identified application vulnerable to SQL injection. This means an attacker is trying to inject malicious SQL statements by using the vulnerable application code or stored procedures.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.VM_PotentialSqlInjection",
      "name": "Potential SQL injection",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An active exploit has occurred against an identified application vulnerable to SQL injection. This means an attacker is trying to inject malicious SQL statements by using the vulnerable application code or stored procedures.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MI_PotentialSqlInjection",
      "name": "Potential SQL injection",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An active exploit has occurred against an identified application vulnerable to SQL injection. This means an attacker is trying to inject malicious SQL statements by using the vulnerable application code or stored procedures.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to sign-in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Synapse.SQLPool_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to sign-in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DB_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to sign-in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.VM_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to sign-in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MI_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to sign-in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.DW_ShellExternalSourceAnomaly",
      "name": "SQL Server potentially spawned a Windows command shell and accessed an abnormal external source",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement potentially spawned a Windows command shell with an external source that hasn't been seen before. Executing a shell that accesses an external source is a method used by attackers to download malicious payload and then execute it on the machine and compromise it. This enables an attacker to perform malicious tasks under remote direction. Alternatively, accessing an external source can be used to exfiltrate data to an external destination.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "SQL.VM_ShellExternalSourceAnomaly",
      "name": "SQL Server potentially spawned a Windows command shell and accessed an abnormal external source",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement potentially spawned a Windows command shell with an external source that hasn't been seen before. Executing a shell that accesses an external source is a method used by attackers to download malicious payload and then execute it on the machine and compromise it. This enables an attacker to perform malicious tasks under remote direction. Alternatively, accessing an external source can be used to exfiltrate data to an external destination.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "Synapse.SQLPool_ShellExternalSourceAnomaly",
      "name": "SQL Server potentially spawned a Windows command shell and accessed an abnormal external source",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement potentially spawned a Windows command shell with an external source that hasn't been seen before. Executing a shell that accesses an external source is a method used by attackers to download malicious payload and then execute it on the machine and compromise it. This enables an attacker to perform malicious tasks under remote direction. Alternatively, accessing an external source can be used to exfiltrate data to an external destination.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "SQL.DB_ShellExternalSourceAnomaly",
      "name": "SQL Server potentially spawned a Windows command shell and accessed an abnormal external source",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement potentially spawned a Windows command shell with an external source that hasn't been seen before. Executing a shell that accesses an external source is a method used by attackers to download malicious payload and then execute it on the machine and compromise it. This enables an attacker to perform malicious tasks under remote direction. Alternatively, accessing an external source can be used to exfiltrate data to an external destination.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "SQL.MI_ShellExternalSourceAnomaly",
      "name": "SQL Server potentially spawned a Windows command shell and accessed an abnormal external source",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement potentially spawned a Windows command shell with an external source that hasn't been seen before. Executing a shell that accesses an external source is a method used by attackers to download malicious payload and then execute it on the machine and compromise it. This enables an attacker to perform malicious tasks under remote direction. Alternatively, accessing an external source can be used to exfiltrate data to an external destination.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "SQL.VM_DataExfiltration",
      "name": "An abnormally large number of rows were extracted from your SQL Server - Preview",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for SQL",
      "sourceType": "ms-learn",
      "description": "An unusually large number of rows has been extracted from your database in a single query. The activity might be related to legitimate operations, such as nonstandard backups or maintenance tasks. Alternatively, it could indicate a potential attempt to exfiltrate data from your SQL Server instances. *Applies only to Defender for SQL on machines with extension version 2.0.3448.357 and later.* Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms ",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Blob_SuspiciousApp",
      "name": "Access from a suspicious application",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that a suspicious application has successfully accessed a container of a storage account with authentication. This might indicate that an attacker has obtained the credentials necessary to access the account, and is exploiting it. This could also be an indication of a penetration test carried out in your organization.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "Storage.Files_SuspiciousIp",
      "name": "Access from a suspicious IP address",
      "severity": "High/Medium/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that this storage account has been successfully accessed from an IP address that is considered suspicious. This alert is powered by Microsoft Threat Intelligence. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Storage.Blob_SuspiciousIp",
      "name": "Access from a suspicious IP address",
      "severity": "High/Medium/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that this storage account has been successfully accessed from an IP address that is considered suspicious. This alert is powered by Microsoft Threat Intelligence. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "Storage.Blob_PhishingContent",
      "name": "Phishing content hosted on a storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "A URL used in a phishing attack points to your Azure Storage account. This URL was part of a phishing attack affecting users of Microsoft 365. Typically, content hosted on such pages is designed to trick visitors into entering their corporate credentials or financial information into a web form that looks legitimate. This alert is powered by Microsoft Threat Intelligence. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Files_PhishingContent",
      "name": "Phishing content hosted on a storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "A URL used in a phishing attack points to your Azure Storage account. This URL was part of a phishing attack affecting users of Microsoft 365. Typically, content hosted on such pages is designed to trick visitors into entering their corporate credentials or financial information into a web form that looks legitimate. This alert is powered by Microsoft Threat Intelligence. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Blob_OpenACL",
      "name": "The access level of a potentially sensitive storage blob container was changed to allow unauthenticated public access",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone has changed the access level of a blob container in the storage account, which might contain sensitive data, to the 'Container' level, to allow unauthenticated (anonymous) public access. The change was made through the Azure portal. Based on statistical analysis, the blob container is flagged as possibly containing sensitive data. This analysis suggests that blob containers or storage accounts with similar names are typically not exposed to public access.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Blob_TorAnomaly",
      "name": "Authenticated access from a Tor exit node",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "One or more storage container(s) / file share(s) in your storage account were successfully accessed from an IP address known to be an active exit node of Tor (an anonymizing proxy). Threat actors use Tor to make it difficult to trace the activity back to them. Authenticated access from a Tor exit node is a likely indication that a threat actor is trying to hide their identity.",
      "mitreTactics": [
        "Initial Access",
        "Pre-Attack"
      ]
    },
    {
      "id": "Storage.Files_TorAnomaly",
      "name": "Authenticated access from a Tor exit node",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "One or more storage container(s) / file share(s) in your storage account were successfully accessed from an IP address known to be an active exit node of Tor (an anonymizing proxy). Threat actors use Tor to make it difficult to trace the activity back to them. Authenticated access from a Tor exit node is a likely indication that a threat actor is trying to hide their identity.",
      "mitreTactics": [
        "Initial Access",
        "Pre-Attack"
      ]
    },
    {
      "id": "Storage.Files_GeoAnomaly",
      "name": "Access from an unusual location to a storage account",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that there was a change in the access pattern to an Azure Storage account. Someone has accessed this account from an IP address considered unfamiliar when compared with recent activity. Either an attacker has gained access to the account, or a legitimate user has connected from a new or unusual geographic location. An example of the latter is remote maintenance from a new application or developer.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "Storage.Blob_GeoAnomaly",
      "name": "Access from an unusual location to a storage account",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that there was a change in the access pattern to an Azure Storage account. Someone has accessed this account from an IP address considered unfamiliar when compared with recent activity. Either an attacker has gained access to the account, or a legitimate user has connected from a new or unusual geographic location. An example of the latter is remote maintenance from a new application or developer.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "Storage.Blob_AnonymousAccessAnomaly",
      "name": "Unusual unauthenticated access to a storage container",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "This storage account was accessed without authentication, which is a change in the common access pattern. Read access to this container is usually authenticated. This might indicate that a threat actor was able to exploit public read access to storage container(s) in this storage account(s).",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "Storage.Blob_MalwareHashReputation",
      "name": "Potential malware uploaded to a storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that a blob containing potential malware has been uploaded to a blob container or a file share in a storage account. This alert is based on hash reputation analysis leveraging the power of Microsoft threat intelligence, which includes hashes for viruses, trojans, spyware and ransomware. Potential causes might include an intentional malware upload by an attacker, or an unintentional upload of a potentially malicious blob by a legitimate user. Note: The alert will not be sent if the same",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "Storage.Files_MalwareHashReputation",
      "name": "Potential malware uploaded to a storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that a blob containing potential malware has been uploaded to a blob container or a file share in a storage account. This alert is based on hash reputation analysis leveraging the power of Microsoft threat intelligence, which includes hashes for viruses, trojans, spyware and ransomware. Potential causes might include an intentional malware upload by an attacker, or an unintentional upload of a potentially malicious blob by a legitimate user. Note: The alert will not be sent if the same",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "Storage.Blob_OpenContainersScanning.SuccessfulDiscovery",
      "name": "Publicly accessible storage containers successfully discovered",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "A successful discovery of publicly open storage container(s) in your storage account was performed in the last hour by a scanning script or tool. This usually indicates a reconnaissance attack, where the threat actor tries to list blobs by guessing container names, in the hope of finding misconfigured open storage containers with sensitive data in them. The threat actor might use their own script or use known scanning tools like Microburst to scan for publicly open containers. ✔ Azure Blob Stora",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Blob_OpenContainersScanning.FailedAttempt",
      "name": "Publicly accessible storage containers unsuccessfully scanned",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "A series of failed attempts to scan for publicly open storage containers were performed in the last hour. This usually indicates a reconnaissance attack, where the threat actor tries to list blobs by guessing container names, in the hope of finding misconfigured open storage containers with sensitive data in them. The threat actor might use their own script or use known scanning tools like Microburst to scan for publicly open containers. ✔ Azure Blob Storage ✖ Azure Files ✖ Azure Data Lake Stora",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Files_AccessInspectionAnomaly",
      "name": "Unusual access inspection in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that the access permissions of a storage account have been inspected in an unusual way, compared to recent activity on this account. A potential cause is that an attacker has performed reconnaissance for a future attack.",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "Storage.Blob_AccessInspectionAnomaly",
      "name": "Unusual access inspection in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that the access permissions of a storage account have been inspected in an unusual way, compared to recent activity on this account. A potential cause is that an attacker has performed reconnaissance for a future attack.",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "Storage.Blob_DataExfiltration.NumberOfBlobsAnomaly",
      "name": "Unusual amount of data extracted from a storage account",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusually large amount of data has been extracted compared to recent activity on this storage container. A potential cause is that an attacker has extracted a large amount of data from a container that holds blob storage.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Files_DataExfiltration.AmountOfDataAnomaly",
      "name": "Unusual amount of data extracted from a storage account",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusually large amount of data has been extracted compared to recent activity on this storage container. A potential cause is that an attacker has extracted a large amount of data from a container that holds blob storage.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Files_DataExfiltration.NumberOfFilesAnomaly",
      "name": "Unusual amount of data extracted from a storage account",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusually large amount of data has been extracted compared to recent activity on this storage container. A potential cause is that an attacker has extracted a large amount of data from a container that holds blob storage.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Blob_DataExfiltration.AmountOfDataAnomaly",
      "name": "Unusual amount of data extracted from a storage account",
      "severity": "High/Low",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusually large amount of data has been extracted compared to recent activity on this storage container. A potential cause is that an attacker has extracted a large amount of data from a container that holds blob storage.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Files_ApplicationAnomaly",
      "name": "Unusual application accessed a storage account",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusual application has accessed this storage account. A potential cause is that an attacker has accessed your storage account by using a new application.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "Storage.Blob_ApplicationAnomaly",
      "name": "Unusual application accessed a storage account",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that an unusual application has accessed this storage account. A potential cause is that an attacker has accessed your storage account by using a new application.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "Storage.Files_DataExplorationAnomaly",
      "name": "Unusual data exploration in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that blobs or containers in a storage account have been enumerated in an abnormal way, compared to recent activity on this account. A potential cause is that an attacker has performed reconnaissance for a future attack.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "Storage.Blob_DataExplorationAnomaly",
      "name": "Unusual data exploration in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that blobs or containers in a storage account have been enumerated in an abnormal way, compared to recent activity on this account. A potential cause is that an attacker has performed reconnaissance for a future attack.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "Storage.Files_DeletionAnomaly",
      "name": "Unusual deletion in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that one or more unexpected delete operations has occurred in a storage account, compared to recent activity on this account. A potential cause is that an attacker has deleted data from your storage account.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Storage.Blob_DeletionAnomaly",
      "name": "Unusual deletion in a storage account",
      "severity": "Medium/Low",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "Indicates that one or more unexpected delete operations has occurred in a storage account, compared to recent activity on this account. A potential cause is that an attacker has deleted data from your storage account.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "not documented",
      "name": "Unusual unauthenticated public access to a sensitive blob container",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone accessed a blob container with sensitive data in the storage account without authentication, using an external (public) IP address. This access is suspicious since the blob container is open to public access and is typically only accessed with authentication from internal networks (private IP addresses). This access could indicate that the blob container's access level is misconfigured, and a malicious actor might have exploited the public access. The security al",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "not documented",
      "name": "Unusual amount of data extracted from a sensitive blob container",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone has extracted an unusually large amount of data from a blob container with sensitive data in the storage account.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "not documented",
      "name": "Unusual number of blobs extracted from a sensitive blob container",
      "severity": "Unknown",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone has extracted an unusually large number of blobs from a blob container with sensitive data in the storage account.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "not documented",
      "name": "Access from a known suspicious application to a sensitive blob container",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with a known suspicious application accessed a blob container with sensitive data in the storage account and performed authenticated operations. The access might indicate that a threat actor obtained credentials to access the storage account by using a known suspicious application. However, the access could also indicate a penetration test carried out in the organization.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "not documented",
      "name": "Access from a known suspicious IP address to a sensitive blob container",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone accessed a blob container with sensitive data in the storage account from a known suspicious IP address associated with threat intel by Microsoft Threat Intelligence. Since the access was authenticated, it's possible that the credentials allowing access to this storage account were compromised. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "not documented",
      "name": "Access from a Tor exit node to a sensitive blob container",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an IP address known to be a Tor exit node accessed a blob container with sensitive data in the storage account with authenticated access. Authenticated access from a Tor exit node strongly indicates that the actor is attempting to remain anonymous for possible malicious intent. Since the access was authenticated, it's possible that the credentials allowing access to this storage account were compromised.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "not documented",
      "name": "Access from an unusual location to a sensitive blob container",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone has accessed blob container with sensitive data in the storage account with authentication from an unusual location. Since the access was authenticated, it's possible that the credentials allowing access to this storage account were compromised.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "not documented",
      "name": "The access level of a sensitive storage blob container was changed to allow unauthenticated public access",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone has changed the access level of a blob container in the storage account, which contains sensitive data, to the 'Container' level, which allows unauthenticated (anonymous) public access. The change was made through the Azure portal. The access level change might compromise the security of the data. We recommend taking immediate action to secure the data and prevent unauthorized access in case this alert is triggered.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "Storage.Files_AccountSas.InternalSasUsedExternally",
      "name": "Suspicious external access to an Azure storage account with overly permissive SAS token",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address accessed the storage account using an overly permissive SAS token with a long expiration date (not including user delegated SAS). This type of access is considered suspicious because the SAS token is typically only used in internal networks (from private IP addresses). The activity might indicate that a SAS token has been leaked by a malicious actor or leaked unintentionally from a legitimate source. Even if the access is legi",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "Storage.Blob_AccountSas.InternalSasUsedExternally",
      "name": "Suspicious external access to an Azure storage account with overly permissive SAS token",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address accessed the storage account using an overly permissive SAS token with a long expiration date (not including user delegated SAS). This type of access is considered suspicious because the SAS token is typically only used in internal networks (from private IP addresses). The activity might indicate that a SAS token has been leaked by a malicious actor or leaked unintentionally from a legitimate source. Even if the access is legi",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "Storage.Blob_AccountSas.UnusualOperationFromExternalIp",
      "name": "Suspicious external operation to an Azure storage account with overly permissive SAS token",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address accessed the storage account using an overly permissive SAS token with a long expiration date (not including user delegated SAS). The access is considered suspicious because operations invoked outside your network (not from private IP addresses) with this SAS token are typically used for a specific set of Read/Write/Delete operations, but other operations occurred, which makes this access suspicious. This activity might indica",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "Storage.Files_AccountSas.UnusualOperationFromExternalIp",
      "name": "Suspicious external operation to an Azure storage account with overly permissive SAS token",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address accessed the storage account using an overly permissive SAS token with a long expiration date (not including user delegated SAS). The access is considered suspicious because operations invoked outside your network (not from private IP addresses) with this SAS token are typically used for a specific set of Read/Write/Delete operations, but other operations occurred, which makes this access suspicious. This activity might indica",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "Storage.Blob_AccountSas.UnusualExternalAccess",
      "name": "Unusual SAS token was used to access an Azure storage account from a public IP address",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address has accessed the storage account using an account SAS token (not including user delegated SAS). The access is highly unusual and considered suspicious, as access to the storage account using SAS tokens typically comes only from internal (private) IP addresses. It's possible that a SAS token was leaked or generated by a malicious actor either from within your organization or externally to gain access to this storage account.",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "Storage.Files_AccountSas.UnusualExternalAccess",
      "name": "Unusual SAS token was used to access an Azure storage account from a public IP address",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that someone with an external (public) IP address has accessed the storage account using an account SAS token (not including user delegated SAS). The access is highly unusual and considered suspicious, as access to the storage account using SAS tokens typically comes only from internal (private) IP addresses. It's possible that a SAS token was leaked or generated by a malicious actor either from within your organization or externally to gain access to this storage account.",
      "mitreTactics": [
        "Exfiltration",
        "Resource Development",
        "Impact"
      ]
    },
    {
      "id": "not documented",
      "name": "Malicious blob uploaded to storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that a malicious blob was found in a storage account. This security alert is generated by the malware scanning feature in Defender for Storage. Potential causes might include an intentional upload of malware by a threat actor or an unintentional upload of a malicious blob by a legitimate user.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "not documented",
      "name": "Malicious file uploaded to storage account",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that a malicious file was found in a storage account. This security alert is generated by the malware scanning feature in Defender for Storage. Potential causes might include an intentional upload of malware by a threat actor or an unintentional upload of a malicious blob by a legitimate user.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "not documented",
      "name": "Malicious blob was downloaded from a storage account",
      "severity": "High, if Eicar - low",
      "severityColor": "#6c757d",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The alert indicates that a malicious blob was downloaded from a storage account. Potential causes might include malware that was uploaded to the storage account and not removed or quarantined, thereby enabling a threat actor to download it, or an unintentional download of the malware by legitimate users or applications.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "not documented",
      "name": "Suspected exposure of Azure Storage account key in a distributed client-side application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Storage",
      "sourceType": "ms-learn",
      "description": "The access key of this storage account was used by a large number of distinct client IP addresses across multiple countries. This usage pattern is consistent with the storage account key being embedded in a distributed client-side application (such as an Android or iOS app, or a decompilable .NET application), allowing any user of the application - or an attacker who extracted the key from it - to access blob data outside of the intended trust boundary Note For alerts that are in preview: The Az",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "AzureDNS_ProtocolAnomaly",
      "name": "Anomalous network protocol usage",
      "severity": "-",
      "severityColor": "#6c757d",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected anomalous protocol usage. Such traffic, while possibly benign, might indicate abuse of this common protocol to bypass network traffic filtering. Typical related attacker activity includes copying remote administration tools to a compromised host and exfiltrating user data from it.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DarkWeb",
      "name": "Anonymity network activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected anonymity network activity. Such activity, while possibly legitimate user behavior, is frequently employed by attackers to evade tracking and fingerprinting of network communications. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DarkWebProxy",
      "name": "Anonymity network activity using web proxy",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected anonymity network activity. Such activity, while possibly legitimate user behavior, is frequently employed by attackers to evade tracking and fingerprinting of network communications. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_SinkholedDomain",
      "name": "Attempted communication with suspicious sinkholed domain",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected request for sinkholed domain. Such activity, while possibly legitimate user behavior, is frequently an indication of the download or execution of malicious software. Typical related attacker activity is likely to include the download and execution of further malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_PhishingDomain",
      "name": "Communication with possible phishing domain",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected a request for a possible phishing domain. Such activity, while possibly benign, is frequently performed by attackers to harvest credentials to remote services. Typical related attacker activity is likely to include the exploitation of any credentials on the legitimate service.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DomainGenerationAlgorithm",
      "name": "Communication with suspicious algorithmically generated domain",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected possible usage of a domain generation algorithm. Such activity, while possibly benign, is frequently performed by attackers to evade network monitoring and filtering. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_RandomizedDomain",
      "name": "Communication with suspicious random domain name",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected usage of a suspicious randomly generated domain name. Such activity, while possibly benign, is frequently performed by attackers to evade network monitoring and filtering. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_CurrencyMining",
      "name": "Digital currency mining activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected digital currency mining activity. Such activity, while possibly legitimate user behavior, is frequently performed by attackers following compromise of resources. Typical related attacker activity is likely to include the download and execution of common mining tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_SuspiciousDomain",
      "name": "Network intrusion detection signature activation",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected a known malicious network signature. Such activity, while possibly legitimate user behavior, is frequently an indication of the download or execution of malicious software. Typical related attacker activity is likely to include the download and execution of further malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DataInfiltration",
      "name": "Possible data download via DNS tunnel",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected a possible DNS tunnel. Such activity, while possibly legitimate user behavior, is frequently performed by attackers to evade network monitoring and filtering. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DataExfiltration",
      "name": "Possible data exfiltration via DNS tunnel",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected a possible DNS tunnel. Such activity, while possibly legitimate user behavior, is frequently performed by attackers to evade network monitoring and filtering. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AzureDNS_DataObfuscation",
      "name": "Possible data transfer via DNS tunnel",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DNS",
      "sourceType": "ms-learn",
      "description": "Analysis of DNS transactions from %{CompromisedEntity} detected a possible DNS tunnel. Such activity, while possibly legitimate user behavior, is frequently performed by attackers to evade network monitoring and filtering. Typical related attacker activity is likely to include the download and execution of malicious software or remote administration tools. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that ar",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "Network_CommunicationWithC2",
      "name": "Network communication with a malicious machine detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis indicates that your machine (IP %{Victim IP}) has communicated with what is possibly a Command and Control center. When the compromised resource is a load balancer or an application gateway, the suspected activity might indicate that one or more of the resources in the backend pool (of the load balancer or application gateway) has communicated with what is possibly a Command and Control center.",
      "mitreTactics": [
        "Command and Control"
      ]
    },
    {
      "id": "Network_ResourceIpIndicatedAsMalicious",
      "name": "Possible compromised machine detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Threat intelligence indicates that your machine (at IP %{Machine IP}) might have been compromised by a malware of type Conficker. Conficker was a computer worm that targets the Microsoft Windows operating system and was first detected in November 2008. Conficker infected millions of computers including government, business and home computers in over 200 countries/regions, making it the largest known computer worm infection since the 2003 Welchia worm.",
      "mitreTactics": [
        "Command and Control"
      ]
    },
    {
      "id": "Generic_Incoming_BF_OneToOne",
      "name": "Possible incoming %{Service Name} brute force attempts detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected incoming %{Service Name} communication to %{Victim IP}, associated with your resource %{Compromised Host} from %{Attacker IP}. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows suspicious activity between %{Start Time} and %{End Time} on port %{Victi",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL_Incoming_BF_OneToOne",
      "name": "Possible incoming SQL brute force attempts detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected incoming SQL communication to %{Victim IP}, associated with your resource %{Compromised Host}, from %{Attacker IP}. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows suspicious activity between %{Start Time} and %{End Time} on port %{Port Number} (%{",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "DDOS",
      "name": "Possible outgoing denial-of-service attack detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous outgoing activity originating from %{Compromised Host}, a resource in your deployment. This activity might indicate that your resource was compromised and is now engaged in denial-of-service attacks against external endpoints. When the compromised resource is a load balancer or an application gateway, the suspected activity might indicate that one or more of the resources in the backend pool (of the load balancer or application gateway) was compromised",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "RDP_Incoming_BF_ManyToOne",
      "name": "Suspicious incoming RDP network activity from multiple sources",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous incoming Remote Desktop Protocol (RDP) communication to %{Victim IP}, associated with your resource %{Compromised Host}, from multiple sources. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Attacking IPs} unique IPs connecti",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "RDP_Incoming_BF_OneToOne",
      "name": "Suspicious incoming RDP network activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous incoming Remote Desktop Protocol (RDP) communication to %{Victim IP}, associated with your resource %{Compromised Host}, from %{Attacker IP}. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Connections} incoming connections to",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SSH_Incoming_BF_ManyToOne",
      "name": "Suspicious incoming SSH network activity from multiple sources",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous incoming SSH communication to %{Victim IP}, associated with your resource %{Compromised Host}, from multiple sources. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Attacking IPs} unique IPs connecting to your resource, which",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SSH_Incoming_BF_OneToOne",
      "name": "Suspicious incoming SSH network activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous incoming SSH communication to %{Victim IP}, associated with your resource %{Compromised Host}, from %{Attacker IP}. When the compromised resource is a load balancer or an application gateway, the suspected incoming traffic has been forwarded to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Connections} incoming connections to your resource, which is c",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "PortScanning",
      "name": "Suspicious outgoing %{Attacked Protocol} traffic detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected suspicious outgoing traffic from %{Compromised Host} to destination port %{Most Common Port}. When the compromised resource is a load balancer or an application gateway, the suspected outgoing traffic has been originated from to one or more of the resources in the backend pool (of the load balancer or application gateway). This behavior might indicate that your resource is taking part in %{Attacked Protocol} brute force attempts or port sweeping attacks.",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "RDP_Outgoing_BF_OneToMany",
      "name": "Suspicious outgoing RDP network activity to multiple destinations",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous outgoing Remote Desktop Protocol (RDP) communication to multiple destinations originating from %{Compromised Host} (%{Attacker IP}), a resource in your deployment. When the compromised resource is a load balancer or an application gateway, the suspected outgoing traffic has been originated from to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows your machine connect",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "RDP_Outgoing_BF_OneToOne",
      "name": "Suspicious outgoing RDP network activity",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous outgoing Remote Desktop Protocol (RDP) communication to %{Victim IP} originating from %{Compromised Host} (%{Attacker IP}), a resource in your deployment. When the compromised resource is a load balancer or an application gateway, the suspected outgoing traffic has been originated from to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Connections} outg",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "SSH_Outgoing_BF_OneToMany",
      "name": "Suspicious outgoing SSH network activity to multiple destinations",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous outgoing SSH communication to multiple destinations originating from %{Compromised Host} (%{Attacker IP}), a resource in your deployment. When the compromised resource is a load balancer or an application gateway, the suspected outgoing traffic has been originated from to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows your resource connecting to %{Number of Attack",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "SSH_Outgoing_BF_OneToOne",
      "name": "Suspicious outgoing SSH network activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Network traffic analysis detected anomalous outgoing SSH communication to %{Victim IP} originating from %{Compromised Host} (%{Attacker IP}), a resource in your deployment. When the compromised resource is a load balancer or an application gateway, the suspected outgoing traffic has been originated from to one or more of the resources in the backend pool (of the load balancer or application gateway). Specifically, sampled network data shows %{Number of Connections} outgoing connections from your",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "Network_TrafficFromUnrecommendedIP",
      "name": "Traffic detected from IP addresses recommended for blocking",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Network Layer",
      "sourceType": "ms-learn",
      "description": "Microsoft Defender for Cloud detected inbound traffic from IP addresses that are recommended to be blocked. This typically occurs when this IP address doesn't communicate regularly with this resource. Alternatively, the IP address has been flagged as malicious by Defender for Cloud's threat intelligence sources. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet rele",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "KV_SuspiciousIPAccess",
      "name": "Access from a suspicious IP address to a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault has been successfully accessed by an IP that has been identified by Microsoft Threat Intelligence as a suspicious IP address. This might indicate that your infrastructure has been compromised. We recommend further investigation. Learn more about Microsoft's threat intelligence capabilities.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_TORAccess",
      "name": "Access from a TOR exit node to a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault has been accessed from a known TOR exit node. This could be an indication that a threat actor has accessed the key vault and is using the TOR network to hide their source location. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_OperationVolumeAnomaly",
      "name": "High volume of operations in a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "An anomalous number of key vault operations were performed by a user, service principal, and/or a specific key vault. This anomalous activity pattern might be legitimate, but it could be an indication that a threat actor has gained access to the key vault and the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_PutGetAnomaly",
      "name": "Suspicious policy change and secret query in a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A user or service principal has performed an anomalous Vault Put policy change operation followed by one or more Secret Get operations. This pattern is not normally performed by the specified user or service principal. This might be legitimate activity, but it could be an indication that a threat actor has updated the key vault policy to access previously inaccessible secrets. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_ListGetAnomaly",
      "name": "Suspicious secret listing and query in a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A user or service principal has performed an anomalous Secret List operation followed by one or more Secret Get operations. This pattern is not normally performed by the specified user or service principal and is typically associated with secret dumping. This might be legitimate activity, but it could be an indication that a threat actor has gained access to the key vault and is trying to discover secrets that can be used to move laterally through your network and/or gain access to sensitive res",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_AccountVolumeAccessDeniedAnomaly",
      "name": "Unusual access denied - User accessing high volume of key vaults denied",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A user or service principal has attempted access to anomalously high volume of key vaults in the last 24 hours. This anomalous access pattern might be legitimate activity. Though this attempt was unsuccessful, it could be an indication of a possible attempt to gain access of key vault and the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "KV_UserAccessDeniedAnomaly",
      "name": "Unusual access denied - Unusual user accessing key vault denied",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault access was attempted by a user that does not normally access it, this anomalous access pattern might be legitimate activity. Though this attempt was unsuccessful, it could be an indication of a possible attempt to gain access of key vault and the secrets contained within it.",
      "mitreTactics": [
        "Initial Access",
        "Discovery"
      ]
    },
    {
      "id": "KV_AppAnomaly",
      "name": "Unusual application accessed a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault has been accessed by a service principal that doesn't normally access it. This anomalous access pattern might be legitimate activity, but it could be an indication that a threat actor has gained access to the key vault in an attempt to access the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_OperationPatternAnomaly",
      "name": "Unusual operation pattern in a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "An anomalous pattern of key vault operations was performed by a user, service principal, and/or a specific key vault. This anomalous activity pattern might be legitimate, but it could be an indication that a threat actor has gained access to the key vault and the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_UserAnomaly",
      "name": "Unusual user accessed a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault has been accessed by a user that does not normally access it. This anomalous access pattern might be legitimate activity, but it could be an indication that a threat actor has gained access to the key vault in an attempt to access the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_UserAppAnomaly",
      "name": "Unusual user-application pair accessed a key vault",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A key vault has been accessed by a user-service principal pair that doesn't normally access it. This anomalous access pattern might be legitimate activity, but it could be an indication that a threat actor has gained access to the key vault in an attempt to access the secrets contained within it. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_AccountVolumeAnomaly",
      "name": "User accessed high volume of key vaults",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A user or service principal has accessed an anomalously high volume of key vaults. This anomalous access pattern might be legitimate activity, but it could be an indication that a threat actor has gained access to multiple key vaults in an attempt to access the secrets contained within them. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_SuspiciousIPAccessDenied",
      "name": "Denied access from a suspicious IP to a key vault",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "An unsuccessful key vault access has been attempted by an IP that has been identified by Microsoft Threat Intelligence as a suspicious IP address. Though this attempt was unsuccessful, it indicates that your infrastructure might have been compromised. We recommend further investigations.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "KV_UnusualAccessSuspiciousIP",
      "name": "Unusual access to the key vault from a suspicious IP (Non-Microsoft or external)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Key Vault",
      "sourceType": "ms-learn",
      "description": "A user or service principal has attempted anomalous access to key vaults from a non-Microsoft IP in the last 24 hours. This anomalous access pattern might be legitimate activity. It could be an indication of a possible attempt to gain access of the key vault and the secrets contained within it. We recommend further investigations. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or oth",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "CosmosDB_TorAnomaly",
      "name": "Access from a Tor exit node",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "This Azure Cosmos DB account was successfully accessed from an IP address known to be an active exit node of Tor, an anonymizing proxy. Authenticated access from a Tor exit node is a likely indication that a threat actor is trying to hide their identity.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "CosmosDB_SuspiciousIp",
      "name": "Access from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "This Azure Cosmos DB account was successfully accessed from an IP address that was identified as a threat by Microsoft Threat Intelligence.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "CosmosDB_GeoAnomaly",
      "name": "Access from an unusual location",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "This Azure Cosmos DB account was accessed from a location considered unfamiliar, based on the usual access pattern. Either a threat actor has gained access to the account, or a legitimate user has connected from a new or unusual geographic location",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "CosmosDB_DataExfiltrationAnomaly",
      "name": "Unusual volume of data extracted",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "An unusually large volume of data has been extracted from this Azure Cosmos DB account. This might indicate that a threat actor exfiltrated data.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "CosmosDB_SuspiciousListKeys.MaliciousScript",
      "name": "Extraction of Azure Cosmos DB accounts keys via a potentially malicious script",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "A PowerShell script was run in your subscription and performed a suspicious pattern of key-listing operations to get the keys of Azure Cosmos DB accounts in your subscription. Threat actors use automated scripts, like Microburst, to list keys and find Azure Cosmos DB accounts they can access. This operation might indicate that an identity in your organization was breached, and that the threat actor is trying to compromise Azure Cosmos DB accounts in your environment for malicious intentions. Alt",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "AzureCosmosDB_SuspiciousListKeys.SuspiciousPrincipal",
      "name": "Suspicious extraction of Azure Cosmos DB account keys",
      "severity": "high",
      "severityColor": "#dc3545",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "A suspicious source extracted Azure Cosmos DB account access keys from your subscription. If this source is not a legitimate source, this might be a high impact issue. The access key that was extracted provides full control over the associated databases and the data stored within. See the details of each specific alert to understand why the source was flagged as suspicious.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "CosmosDB_SqlInjection.DataExfiltration",
      "name": "SQL injection: potential data exfiltration",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement was used to query a container in this Azure Cosmos DB account. The injected statement might have succeeded in exfiltrating data that the threat actor isn't authorized to access. Due to the structure and capabilities of Azure Cosmos DB queries, many known SQL injection attacks on Azure Cosmos DB accounts can't work. However, the variation used in this attack might work and threat actors can exfiltrate data.",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "CosmosDB_SqlInjection.FailedFuzzingAttempt",
      "name": "SQL injection: fuzzing attempt",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Cosmos DB",
      "sourceType": "ms-learn",
      "description": "A suspicious SQL statement was used to query a container in this Azure Cosmos DB account. Like other well-known SQL injection attacks, this attack won't succeed in compromising the Azure Cosmos DB account. Nevertheless, it's an indication that a threat actor is trying to attack the resources in this account, and your application might be compromised. Some SQL injection attacks can succeed and be used to exfiltrate data. This means that if the attacker continues performing SQL injection attempts,",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "VM_GPUExtensionSuspiciousFailure",
      "name": "Suspicious failure installing GPU extension in your subscription (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious intent of installing a GPU extension on unsupported VMs. This extension should be installed on virtual machines equipped with a graphic processor, and in this case the virtual machines are not equipped with such. These failures can be seen when malicious adversaries execute multiple installations of such extension for crypto-mining purposes.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "VM_RunCommandSuspiciousScript",
      "name": "Run Command with a suspicious script was detected on your virtual machine (Preview)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "A Run Command with a suspicious script was detected on your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use Run Command to execute malicious code with high privileges on your virtual machine via the Azure Resource Manager. The script is deemed suspicious as certain parts were identified as being potentially malicious.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_RunCommandSuspiciousFailure",
      "name": "Suspicious unauthorized Run Command usage was detected on your virtual machine (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious unauthorized usage of Run Command has failed and was detected on your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might attempt to use Run Command to execute malicious code with high privileges on your virtual machines via the Azure Resource Manager. This activity is deemed suspicious as it hasn't been commonly seen before.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_RunCommandSuspiciousUsage",
      "name": "Suspicious Run Command usage was detected on your virtual machine (Preview)",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious usage of Run Command was detected on your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use Run Command to execute malicious code with high privileges on your virtual machines via the Azure Resource Manager. This activity is deemed suspicious as it hasn't been commonly seen before.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_SuspiciousMultiExtensionUsage",
      "name": "Suspicious usage of multiple monitoring or data collection extensions was detected on your virtual machines (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious usage of multiple monitoring or data collection extensions was detected on your virtual machines by analyzing the Azure Resource Manager operations in your subscription. Attackers might abuse such extensions for data collection, network traffic monitoring, and more, in your subscription. This usage is deemed suspicious as it hasn't been commonly seen before.",
      "mitreTactics": [
        "Reconnaissance"
      ]
    },
    {
      "id": "VM_DiskEncryptionSuspiciousUsage",
      "name": "Suspicious installation of disk encryption extensions was detected on your virtual machines (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious installation of disk encryption extensions was detected on your virtual machines by analyzing the Azure Resource Manager operations in your subscription. Attackers might abuse the disk encryption extension to deploy full disk encryptions on your virtual machines via the Azure Resource Manager in an attempt to perform ransomware activity. This activity is deemed suspicious as it hasn't been commonly seen before and due to the high number of extension installations.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "VM_VMAccessSuspiciousUsage",
      "name": "Suspicious usage of VMAccess extension was detected on your virtual machines (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious usage of VMAccess extension was detected on your virtual machines. Attackers might abuse the VMAccess extension to gain access and compromise your virtual machines with high privileges by resetting access or managing administrative users. This activity is deemed suspicious as the principal's behavior departs from its usual patterns, and due to the high number of the extension installations.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "VM_DSCExtensionSuspiciousScript",
      "name": "Desired State Configuration (DSC) extension with a suspicious script was detected on your virtual machine (Preview)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Desired State Configuration (DSC) extension with a suspicious script was detected on your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use the Desired State Configuration (DSC) extension to deploy malicious configurations, such as persistence mechanisms, malicious scripts, and more, with high privileges, on your virtual machines. The script is deemed suspicious as certain parts were identified as being potentially malicious.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_DSCExtensionSuspiciousUsage",
      "name": "Suspicious usage of a Desired State Configuration (DSC) extension was detected on your virtual machines (Preview)",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious usage of a Desired State Configuration (DSC) extension was detected on your virtual machines by analyzing the Azure Resource Manager operations in your subscription. Attackers might use the Desired State Configuration (DSC) extension to deploy malicious configurations, such as persistence mechanisms, malicious scripts, and more, with high privileges, on your virtual machines. This activity is deemed suspicious as the principal's behavior departs from its usual patterns, and due to the",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionSuspiciousCmd",
      "name": "Custom script extension with a suspicious script was detected on your virtual machine (Preview)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Custom script extension with a suspicious script was detected on your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use Custom script extension to execute malicious code with high privileges on your virtual machine via the Azure Resource Manager. The script is deemed suspicious as certain parts were identified as being potentially malicious.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionSuspiciousFailure",
      "name": "Suspicious failed execution of custom script extension in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Suspicious failure of a custom script extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Such failures might be associated with malicious scripts run by this extension.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionUnusualDeletion",
      "name": "Unusual deletion of custom script extension in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Unusual deletion of a custom script extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use custom script extensions to execute malicious code on your virtual machines via the Azure Resource Manager.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionUnusualExecution",
      "name": "Unusual execution of custom script extension in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Unusual execution of a custom script extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use custom script extensions to execute malicious code on your virtual machines via the Azure Resource Manager.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionSuspiciousEntryPoint",
      "name": "Custom script extension with suspicious entry-point in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Custom script extension with a suspicious entry-point was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. The entry-point refers to a suspicious GitHub repository. Attackers might use custom script extensions to execute malicious code on your virtual machines via the Azure Resource Manager.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "VM_CustomScriptExtensionSuspiciousPayload",
      "name": "Custom script extension with suspicious payload in your virtual machine",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for VM Extensions",
      "sourceType": "ms-learn",
      "description": "Custom script extension with a payload from a suspicious GitHub repository was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use custom script extensions to execute malicious code on your virtual machines via the Azure Resource Manager. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet relea",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "SQL.PostgreSQL_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to log in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MariaDB_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to log in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MySQL_BruteForce",
      "name": "Suspected brute force attack using a valid user",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potential brute force attack has been detected on your resource. The attacker is using the valid user (username), which has permissions to log in.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MariaDB_HarmfulApplication",
      "name": "Attempted logon by a potentially harmful application",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MySQL_HarmfulApplication",
      "name": "Attempted logon by a potentially harmful application",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.PostgreSQL_HarmfulApplication",
      "name": "Attempted logon by a potentially harmful application",
      "severity": "High/Medium",
      "severityColor": "#dc3545",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A potentially harmful application attempted to access your resource.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MySQL_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MariaDB_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.PostgreSQL_PrincipalAnomaly",
      "name": "Login from a principal user not seen in 60 days",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A principal user not seen in the last 60 days has logged into your database. If this database is new or this is expected behavior caused by recent changes in the users accessing the database, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.PostgreSQL_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MySQL_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MariaDB_DomainAnomaly",
      "name": "Login from a domain not seen in 60 days",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "A user has logged in to your resource from a domain no other users have connected from in the last 60 days. If this resource is new or this is expected behavior caused by recent changes in the users accessing the resource, Defender for Cloud will identify significant changes to the access patterns and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.PostgreSQL_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.MariaDB_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.MySQL_DataCenterAnomaly",
      "name": "Log on from an unusual Azure Data Center",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "SQL.PostgreSQL_CloudProviderAnomaly",
      "name": "Logon from an unusual cloud provider",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from a cloud provider not seen in the last 60 days. It's quick and easy for threat actors to obtain disposable compute power for use in their campaigns. If this is expected behavior caused by the recent adoption of a new cloud provider, Defender for Cloud will learn over time and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MariaDB_CloudProviderAnomaly",
      "name": "Logon from an unusual cloud provider",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from a cloud provider not seen in the last 60 days. It's quick and easy for threat actors to obtain disposable compute power for use in their campaigns. If this is expected behavior caused by the recent adoption of a new cloud provider, Defender for Cloud will learn over time and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MySQL_CloudProviderAnomaly",
      "name": "Logon from an unusual cloud provider",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from a cloud provider not seen in the last 60 days. It's quick and easy for threat actors to obtain disposable compute power for use in their campaigns. If this is expected behavior caused by the recent adoption of a new cloud provider, Defender for Cloud will learn over time and attempt to prevent future false positives.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MariaDB_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.PostgreSQL_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MySQL_GeoAnomaly",
      "name": "Log on from an unusual location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Someone logged on to your resource from an unusual Azure Data Center.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "SQL.MySQL_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.MariaDB_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "SQL.PostgreSQL_SuspiciousIpAnomaly",
      "name": "Login from a suspicious IP",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Open-Source DBs",
      "sourceType": "ms-learn",
      "description": "Your resource has been accessed successfully from an IP address that Microsoft Threat Intelligence has associated with suspicious activity. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "NETWORK_DDOS_DETECTED",
      "name": "DDoS Attack detected for Public IP",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for DDoS",
      "sourceType": "ms-learn",
      "description": "DDoS Attack detected for Public IP (IP address) and being mitigated.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "NETWORK_DDOS_MITIGATED",
      "name": "DDoS Attack mitigated for Public IP",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for DDoS",
      "sourceType": "ms-learn",
      "description": "DDoS Attack mitigated for Public IP (IP address). Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.",
      "mitreTactics": [
        "Probing"
      ]
    },
    {
      "id": "API_PopulationSpikeInAPITraffic",
      "name": "Suspicious population-level spike in API traffic to an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A suspicious spike in API traffic was detected at one of the API endpoints. The detection system used historical traffic patterns to establish a baseline for routine API traffic volume between all IPs and the endpoint, with the baseline being specific to API traffic for each status code (such as 200 Success). The detection system flagged an unusual deviation from this baseline leading to the detection of suspicious activity.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "API_SpikeInAPITraffic",
      "name": "Suspicious spike in API traffic from a single IP address to an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A suspicious spike in API traffic was detected from a client IP to the API endpoint. The detection system used historical traffic patterns to establish a baseline for routine API traffic volume to the endpoint coming from a specific IP to the endpoint. The detection system flagged an unusual deviation from this baseline leading to the detection of suspicious activity.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "API_SpikeInPayload",
      "name": "Unusually large response payload transmitted between a single IP address and an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A suspicious spike in API response payload size was observed for traffic between a single IP and one of the API endpoints. Based on historical traffic patterns from the last 30 days, Defender for APIs learns a baseline that represents the typical API response payload size between a specific IP and API endpoint. The learned baseline is specific to API traffic for each status code (for example, 200 Success). The alert was triggered because an API response payload size deviated significantly from t",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "API_SpikeInLatency",
      "name": "(Preview) Suspicious spike in latency for traffic between a single IP address and an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A suspicious spike in latency was observed for traffic between a single IP and one of the API endpoints. Based on historical traffic patterns from the last 30 days, Defender for APIs learns a baseline that represents the routine API traffic latency between a specific IP and API endpoint. The learned baseline is specific to API traffic for each status code (for example, 200 Success). The alert was triggered because an API call latency deviated significantly from the historical baseline.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "API_SprayInRequests",
      "name": "API requests spray from a single IP address to an unusually large number of distinct API endpoints",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A single IP was observed making API calls to an unusually large number of distinct endpoints. Based on historical traffic patterns from the last 30 days, Defenders for APIs learns a baseline that represents the typical number of distinct endpoints called by a single IP across 20-minute windows. The alert was triggered because a single IP's behavior deviated significantly from the historical baseline.",
      "mitreTactics": [
        "Discovery"
      ]
    },
    {
      "id": "API_ParameterEnumeration",
      "name": "Parameter enumeration on an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A single IP was observed enumerating parameters when accessing one of the API endpoints. Based on historical traffic patterns from the last 30 days, Defender for APIs learns a baseline that represents the typical number of distinct parameter values used by a single IP when accessing this endpoint across 20-minute windows. The alert was triggered because a single client IP recently accessed an endpoint using an unusually large number of distinct parameter values.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "API_DistributedParameterEnumeration",
      "name": "Distributed parameter enumeration on an API endpoint",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "The aggregate user population (all IPs) was observed enumerating parameters when accessing one of the API endpoints. Based on historical traffic patterns from the last 30 days, Defender for APIs learns a baseline that represents the typical number of distinct parameter values used by the user population (all IPs) when accessing an endpoint across 20-minute windows. The alert was triggered because the user population recently accessed an endpoint using an unusually large number of distinct parame",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "API_UnseenParamType",
      "name": "Parameter value(s) with anomalous data types in an API call",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A single IP was observed accessing one of your API endpoints and using parameter values of a low probability data type (for example, string, integer, etc.). Based on historical traffic patterns from the last 30 days, Defender for APIs learns the expected data types for each API parameter. The alert was triggered because an IP recently accessed an endpoint using a previously low probability data type as a parameter input.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "API_UnseenParam",
      "name": "Previously unseen parameter used in an API call",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "A single IP was observed accessing one of the API endpoints using a previously unseen or out-of-bounds parameter in the request. Based on historical traffic patterns from the last 30 days, Defender for APIs learns a set of expected parameters associated with calls to an endpoint. The alert was triggered because an IP recently accessed an endpoint using a previously unseen parameter.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "API_AccessFromTorExitNode",
      "name": "Access from a Tor exit node to an API endpoint",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "An IP address from the Tor network accessed one of your API endpoints. Tor is a network that allows people to access the Internet while keeping their real IP hidden. Though there are legitimate uses, it is frequently used by attackers to hide their identity when they target people's systems online.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "API_AccessFromSuspiciousIP",
      "name": "API Endpoint access from suspicious IP",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "An IP address accessing one of your API endpoints was identified by Microsoft Threat Intelligence as having a high probability of being a threat. While observing malicious Internet traffic, this IP came up as involved in attacking other online targets.",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "API_AccessFromSuspiciousUserAgent",
      "name": "Suspicious User Agent detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for APIs",
      "sourceType": "ms-learn",
      "description": "The user agent of a request accessing one of your API endpoints contained anomalous values indicative of an attempt at remote code execution. This does not mean that any of your API endpoints have been breached, but it does suggest that an attempted attack is underway. Note For alerts that are in preview: The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "not documented",
      "name": "Exposed Kubernetes service detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert indicates that a Kubernetes Service of type `LoadBalancer` was created or updated in a way that can publicly expose workloads. For AI applications that run on Kubernetes, this exposure can increase risk, especially when externally reachable endpoints rely on weak authentication or missing authentication controls.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AI.Azure_CredentialTheftAttempt",
      "name": "Detected credential theft attempts on an Azure AI model deployment",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "The credential theft alert is designed to notify the security operations center (SOC) when credentials are detected within GenAI model responses to a user prompt, indicating a potential breach. This alert is crucial for detecting cases of credential leak or theft, which are unique to generative AI and can have severe consequences if successful.",
      "mitreTactics": [
        "Credential Access",
        "Lateral Movement",
        "Exfiltration"
      ]
    },
    {
      "id": "AI.Azure_Jailbreak.ContentFiltering.BlockedAttempt",
      "name": "A Jailbreak attempt on an Azure AI model deployment was blocked by Azure AI Content Safety Prompt Shields",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "The Jailbreak alert, carried out using a direct prompt injection technique, is designed to notify the SOC there was an attempt to manipulate the system prompt to bypass the generative AI’s safeguards, potentially accessing sensitive data or privileged functions. It indicated that such attempts were blocked by Azure Responsible AI Content Safety (also known as Prompt Shields), ensuring the integrity of the AI resources and the data security.",
      "mitreTactics": [
        "Privilege Escalation",
        "Defense Evasion"
      ]
    },
    {
      "id": "AI.Azure_Jailbreak.ContentFiltering.DetectedAttempt",
      "name": "A Jailbreak attempt on an Azure AI model deployment was detected by Azure AI Content Safety Prompt Shields",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "The Jailbreak alert, carried out using a direct prompt injection technique, is designed to notify the SOC there was an attempt to manipulate the system prompt to bypass the generative AI’s safeguards, potentially accessing sensitive data or privileged functions. It indicated that such attempts were detected by Azure Responsible AI Content Safety (also known as Prompt Shields), but weren't blocked due to content filtering settings or due to low confidence.",
      "mitreTactics": [
        "Privilege Escalation",
        "Defense Evasion"
      ]
    },
    {
      "id": "AI.Azure_MaliciousUrl.ModelResponse",
      "name": "Corrupted AI application\\model\\data directed a phishing attempt at a user",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert indicates a corruption of an AI application developed by the organization, as it has actively shared a known malicious URL used for phishing with a user. The URL originated within the application itself, the AI model, or the data the application can access.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "AI.Azure_MaliciousUrl.UnknownSource",
      "name": "Phishing URL shared in an AI application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert indicates a potential corruption of an AI application, or a phishing attempt by one of the end users. The alert determines that a malicious URL used for phishing was passed during a conversation through the AI application, however the origin of the URL (user or application) is unclear.",
      "mitreTactics": [
        "Impact",
        "Collection"
      ]
    },
    {
      "id": "AI.Azure_MaliciousUrl.UserPrompt",
      "name": "Phishing attempt detected in an AI application",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert indicates a URL used for phishing attack was sent by a user to an AI application. The content typically lures visitors into entering their corporate credentials or financial information into a legitimate looking website. Sending this to an AI application might be for the purpose of corrupting it, poisoning the data sources it has access to, or gaining access to employees or other customers via the application's tools.",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "AI.Azure_AccessFromSuspiciousUserAgent",
      "name": "Suspicious user agent detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "The user agent of a request accessing one of your Azure AI resources contained anomalous values indicative of an attempt to abuse or manipulate the resource. The suspicious user agent in question has been mapped by Microsoft threat intelligence as suspected of malicious intent and hence your resources were likely compromised.",
      "mitreTactics": [
        "Execution",
        "Reconnaissance",
        "Initial Access"
      ]
    },
    {
      "id": "AI.Azure_ASCIISmuggling",
      "name": "ASCII Smuggling prompt injection detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "ASCII smuggling technique allows an attacker to send invisible instructions to an AI model. These attacks are commonly attributed to indirect prompt injections, where the malicious threat actor is passing hidden instructions to bypass the application and model guardrails. These attacks are usually applied without the user's knowledge given their lack of visibility in the text and can compromise the application tools or connected data sets.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "AI.Azure_AccessFromAnonymizedIP",
      "name": "Access from a Tor IP",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "An IP address from the Tor network accessed one of the AI resources. Tor is a network that allows people to access the Internet while keeping their real IP hidden. Though there are legitimate uses, it is frequently used by attackers to hide their identity when they target people's systems online.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AI.Azure_AccessFromSuspiciousIP",
      "name": "Access from suspicious IP",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "An IP address accessing one of your AI services was identified by Microsoft Threat Intelligence as having a high probability of being a threat. While observing malicious Internet traffic, this IP came up as involved in attacking other online targets.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AI.Azure_DOWDuplicateRequests",
      "name": "Suspected wallet attack - recurring requests",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "Wallet attacks are a family of attacks common for AI resources that consist of threat actors excessively engage with an AI resource directly or through an application in hopes of causing the organization large financial damages. This detection tracks high volumes of identical requests targeting the same AI resource which may be caused due to an ongoing attack.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "AI.Azure_DOWVolumeAnomaly",
      "name": "Suspected wallet attack - volume anomaly",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "Wallet attacks are a family of attacks common for AI resources that consist of threat actors excessively engage with an AI resource directly or through an application in hopes of causing the organization large financial damages. This detection tracks high volumes of requests and responses by the resource that are inconsistent with its historical usage patters.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "AI.Azure_AccessAnomaly",
      "name": "Access anomaly in AI resource",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert track anomalies in access patterns to an AI resource. Changes in request parameters by users or applications such as user agents, IP ranges, authentication methods, etc. can indicate a compromised resource that is now being accessed by malicious actors. This alert may trigger when requests are valid if they represent significant changes in the pattern of previous access to a certain resource.",
      "mitreTactics": [
        "Execution",
        "Reconnaissance",
        "Initial Access"
      ]
    },
    {
      "id": "AI.Azure_AnomalousOperation.InitialAccess",
      "name": "Suspicious invocation of a high-risk 'Initial Access' operation by a service principal detected (AI resources)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert detects a suspicious invocation of a high-risk operation in your subscription, which might indicate an attempt to access restricted resources. The identified AI-resource related operations are designed to allow administrators to efficiently access their environments. While this activity might be legitimate, a threat actor might utilize such operations to gain initial access to restricted AI resources in your environment. This can indicate that the service principal is compromised and ",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "AI.Azure_AnomalousToolInvocation",
      "name": "Anomalous tool invocation",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "This alert analyzes anomalous activity from an AI application connected to an Azure OpenAI model deployment. The application attempted to invoke a tool in a manner that deviates from expected behavior. This behavior may indicate potential misuse or an attempted attack through one of the tools available to the application.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AI.Azure_LLMReconnaissance",
      "name": "(Preview) LLM Reconnaissance Attempt Detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "A threat actor is interacting with your AI application in a way that resembles reconnaissance behavior, including attempts to extract system instructions, model capabilities, or bypass safety guardrails. These prompts may precede attempted prompt injection or jailbreak attacks. ## Alerts for AI models",
      "mitreTactics": [
        "Reconnaissance"
      ]
    },
    {
      "id": "AI.AIModelScan_MalwareDetected",
      "name": "(Preview) Malicious content detected in uploaded AI model",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for AI",
      "sourceType": "ms-learn",
      "description": "A user-uploaded machine learning model was scanned and found to contain malware. The detection indicates the file may execute malicious code if loaded, posing a threat to account integrity, data confidentiality, and the compute environment.",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "K8S.NODE_FirewallDisabled",
      "name": "Manipulation of host firewall detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a possible manipulation of the on-host firewall. Attackers will often disable this to exfiltrate data.",
      "mitreTactics": [
        "Defense Evasion",
        "Exfiltration"
      ]
    },
    {
      "id": "K8S.NODE_SuspiciousDNSOverHttps",
      "name": "Suspicious use of DNS over HTTPS",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected the use of a DNS call over HTTPS in an uncommon fashion. This technique is used by attackers to hide calls out to suspect or malicious sites.",
      "mitreTactics": [
        "Defense Evasion",
        "Exfiltration"
      ]
    },
    {
      "id": "K8S.NODE_ThreatIntelCommandLineSuspectDomain",
      "name": "A possible connection to malicious location has been detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a connection to a location that has been reported to be malicious or unusual. This is an indicator that a compromise might have occurred.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S.NODE_CurrencyMining",
      "name": "Digital currency mining activity",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "Analysis of DNS transactions detected digital currency mining activity. Such activity, while possibly legitimate user behavior, is frequently performed by attackers following compromise of resources. Typical related attacker activity is likely to include the download and execution of common mining tools. ## Deprecated Defender for Servers Linux alerts",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "VM_AbnormalDaemonTermination",
      "name": "Abnormal Termination",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_BinaryGeneratedFromCommandLine",
      "name": "Suspicious binary detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "not documented",
      "name": "domain name reference",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CommonBot",
      "name": "Behavior similar to common Linux bots detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CompCommonBots",
      "name": "Commands similar to common Linux bots detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CompSuspiciousScript",
      "name": "Shell Script Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CompTestRule",
      "name": "Composite Analytic Test Alert",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CronJobAccess",
      "name": "Manipulation of scheduled tasks detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CryptoCoinMinerArtifacts",
      "name": "Process associated with digital currency mining detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CryptoCoinMinerDownload",
      "name": "Possible Cryptocoinminer download detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_CryptoCoinMinerExecution",
      "name": "Potential crypto coin miner started",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_DataEgressArtifacts",
      "name": "Possible data exfiltration detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_DigitalCurrencyMining",
      "name": "Digital currency mining related behavior detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_DownloadAndRunCombo",
      "name": "Suspicious Download Then Run Activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_EICAR",
      "name": "Microsoft Defender for Cloud test alert (not a threat)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ExecuteHiddenFile",
      "name": "Execution of hidden file",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ExploitAttempt",
      "name": "Possible command line exploitation attempt",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ExposedDocker",
      "name": "Exposed Docker daemon on TCP socket",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_FairwareMalware",
      "name": "Behavior similar to Fairware ransomware detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_FirewallDisabled",
      "name": "Manipulation of host firewall detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_HadoopYarnExploit",
      "name": "Possible exploitation of Hadoop Yarn",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_HistoryFileCleared",
      "name": "A history file has been cleared",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_KnownLinuxAttackTool",
      "name": "Possible attack tool detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_KnownLinuxCredentialAccessTool",
      "name": "Possible credential access tool detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_KnownLinuxDDoSToolkit",
      "name": "Indicators associated with DDOS toolkit detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_KnownLinuxScreenshotTool",
      "name": "Screenshot taken on host",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_LinuxBackdoorArtifact",
      "name": "Possible backdoor detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_LinuxReconnaissance",
      "name": "Local host reconnaissance detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_MismatchedScriptFeatures",
      "name": "Script extension mismatch detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_MitreCalderaTools",
      "name": "MITRE Caldera agent detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_NewSingleUserModeStartupScript",
      "name": "Detected Persistence Attempt",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_NewSudoerAccount",
      "name": "Account added to sudo group",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_OverridingCommonFiles",
      "name": "Potential overriding of common files",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_PrivilegedContainerArtifacts",
      "name": "Container running in privileged mode",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_PrivilegedExecutionInContainer",
      "name": "Command within a container running with high privileges",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ReadingHistoryFile",
      "name": "Unusual access to bash history file",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ReverseShell",
      "name": "Potential reverse shell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SshKeyAccess",
      "name": "Process seen accessing the SSH authorized keys file in an unusual way",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectCompilation",
      "name": "Suspicious compilation detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectConnection",
      "name": "An uncommon connection attempt detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectDownload",
      "name": "Detected file download from a known malicious source",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectDownloadArtifacts",
      "name": "Detected suspicious file download",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectExecutablePath",
      "name": "Executable found running from a suspicious location",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectHtaccessFileAccess",
      "name": "Access of htaccess file detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectInitialShellCommand",
      "name": "Suspicious first command in shell",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectMixedCaseText",
      "name": "Detected anomalous mix of uppercase and lowercase characters in command line",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectNetworkConnection",
      "name": "Suspicious network connection",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectNohup",
      "name": "Detected suspicious use of the nohup command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectPasswordChange",
      "name": "Possible password change using crypt-method detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectPasswordFileAccess",
      "name": "Suspicious password access",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectPhp",
      "name": "Suspicious PHP execution detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectPortForwarding",
      "name": "Potential port forwarding to external IP address",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectProcessAccountPrivilegeCombo",
      "name": "Process running in a service account became root unexpectedly",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectProcessTermination",
      "name": "Security-related process termination detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspectUserAddition",
      "name": "Detected suspicious use of the useradd command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspiciousCommandLineExecution",
      "name": "Suspicious command execution",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspiciousDNSOverHttps",
      "name": "Suspicious use of DNS over HTTPS",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SystemLogRemoval",
      "name": "Possible Log Tampering Activity Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ThreatIntelCommandLineSuspectDomain",
      "name": "A possible connection to malicious location has been detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ThreatIntelSuspectLogon",
      "name": "A logon from a malicious IP has been detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_TimerServiceDisabled",
      "name": "Attempt to stop apt-daily-upgrade.timer service detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_TimestampTampering",
      "name": "Suspicious file timestamp modification",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_Webshell",
      "name": "Possible malicious web shell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_MULTIPLEACCOUNTCREATE",
      "name": "Suspicious creation of accounts on multiple hosts",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_PSINSIGHT_CONTEXT",
      "name": "Suspicious use of PowerShell detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_AddGuestToAdministrators",
      "name": "Addition of Guest account to Local Administrators group",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_Apache_Tomcat_executing_suspicious_commands",
      "name": "Apache\\_Tomcat\\_executing\\_suspicious\\_commands",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownBruteForcingTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownCollectionTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownDefenseEvasionTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownExecutionTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownPassTheHashTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_KnownSpammingTools",
      "name": "Suspicious process executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_Lowering_Security_Settings",
      "name": "Detected the disabling of critical services",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_OtherKnownHackerTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_RDP_session_hijacking_via_tscon",
      "name": "Suspect integrity level indicative of RDP hijacking",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_RDP_session_hijacking_via_tscon_service",
      "name": "Suspect service installation",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_Suppress_pesky_unauthorized_use_prohibited_notices",
      "name": "Detected suppression of legal notice displayed to users at logon",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "SCUBA_RULE_WDigest_Enabling",
      "name": "Detected enabling of the WDigest UseLogonCredential registry key",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_ApplockerBypass",
      "name": "Potential attempt to bypass AppLocker detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_BariumKnownSuspiciousProcessExecution",
      "name": "Detected suspicious file creation",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_Base64EncodedExecutableInCommandLineParams",
      "name": "Detected encoded executable in command line data",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_CalcsCommandLineUse",
      "name": "Detected suspicious use of Cacls to lower the security state of the system",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_CommandLineStartingAllExe",
      "name": "Detected suspicious command line used to start all executables in a directory",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_DisablingAndDeletingIISLogFiles",
      "name": "Detected actions indicative of disabling and deleting IIS log files",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_DownloadUsingCertutil",
      "name": "Suspicious download using Certutil detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_EchoOverPipeOnLocalhost",
      "name": "Detected suspicious named pipe communications",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_EchoToConstructPowerShellScript",
      "name": "Dynamic PowerShell script construction",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_ExecutableDecodedUsingCertutil",
      "name": "Detected decoding of an executable using built-in certutil.exe tool",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_FileDeletionIsSospisiousLocation",
      "name": "Suspicious file deletion detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_KerberosGoldenTicketAttack",
      "name": "Suspected Kerberos Golden Ticket attack parameters observed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_KeygenToolKnownProcessName",
      "name": "Detected possible execution of keygen executable Suspicious process executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_KnownCredentialAccessTools",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_KnownSuspiciousPowerShellScript",
      "name": "Suspicious use of PowerShell detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_KnownSuspiciousSoftwareInstallation",
      "name": "High risk software detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_MsHtaAndPowerShellCombination",
      "name": "Detected suspicious combination of HTA and PowerShell",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_MultipleAccountsQuery",
      "name": "Multiple Domain Accounts Queried",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_NewAccountCreation",
      "name": "Account creation detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_ObfuscatedCommandLine",
      "name": "Detected obfuscated command line.",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_PcaluaUseToLaunchExecutable",
      "name": "Detected suspicious use of Pcalua.exe to launch executable code",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_PetyaRansomware",
      "name": "Detected Petya ransomware indicators",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_PowerShellPowerSploitScriptExecution",
      "name": "Suspicious PowerShell cmdlets executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_RansomwareIndication",
      "name": "Ransomware indicators detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SqlDumperUsedSuspiciously",
      "name": "Possible credential dumping detected [seen multiple times]",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_StopCriticalServices",
      "name": "Detected the disabling of critical services",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SubvertingAccessibilityBinary",
      "name": "Sticky keys attack detected Suspicious account creation detected Medium",
      "severity": "Unknown",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SuspiciousAccountCreation",
      "name": "Suspicious Account Creation Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SuspiciousFirewallRuleAdded",
      "name": "Detected suspicious new firewall rule",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SuspiciousFTPSSwitchUsage",
      "name": "Detected suspicious use of FTP -s switch",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SuspiciousSQLActivity",
      "name": "Suspicious SQL activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SVCHostFromInvalidPath",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_SystemEventLogCleared",
      "name": "The Windows Security log was cleared",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_TelegramInstallation",
      "name": "Detected potentially suspicious use of Telegram tool",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_UndercoverProcess",
      "name": "Suspiciously named process detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_UserAccountControlBypass",
      "name": "Detected change to a registry key that can be abused to bypass UAC",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_VBScriptEncoding",
      "name": "Detected suspicious execution of VBScript.Encode command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_WindowPositionRegisteryChange",
      "name": "Suspicious WindowPosition registry value detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM.Windows_ZincPortOpenningUsingFirewallRule",
      "name": "Malicious firewall rule created by ZINC server implant",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_MaliciousSQLActivity",
      "name": "Malicious SQL activity",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ProcessWithDoubleExtensionExecution",
      "name": "Suspicious double extension file executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_RegistryPersistencyKey",
      "name": "Windows registry persistence method detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_ShadowCopyDeletion",
      "name": "Suspicious Volume Shadow Copy Activity Executable found running from a suspicious location",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_SuspiciousScreenSaverExecution",
      "name": "Suspicious Screensaver process executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_VbScriptHttpObjectAllocation",
      "name": "VBScript HTTP object allocation detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_TaskkillBurst",
      "name": "Suspicious process termination burst",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "VM_RunByPsExec",
      "name": "PsExec execution detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Deprecated Alerts",
      "sourceType": "deprecated",
      "description": "not documented",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "K8S_ExposedPostgresTrustAuth",
      "name": "Exposed Postgres service with trust authentication configuration in Kubernetes detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes cluster configuration analysis detected exposure of a Postgres service by a load balancer. The service is configured with trust authentication method, which doesn't require credentials.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S_ExposedPostgresBroadIPRange",
      "name": "Exposed Postgres service with risky configuration in Kubernetes detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes cluster configuration analysis detected exposure of a Postgres service by a load balancer with a risky configuration. Exposing the service to a wide range of IP addresses poses a security risk.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S.NODE_NamespaceCreation",
      "name": "Attempt to create a new Linux namespace from a container detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container in Kubernetes cluster detected an attempt to create a new Linux namespace. While this behavior might be legitimate, it might indicate that an attacker tries to escape from the container to the node. Some CVE-2022-0185 exploitations use this technique.",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "K8S.NODE_HistoryFileCleared",
      "name": "A history file has been cleared",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected that the command history log file has been cleared. Attackers might do this to cover their tracks. The operation was performed by the specified user account.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S_AbnormalMiActivity",
      "name": "Abnormal activity of managed identity associated with Kubernetes (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of Azure Resource Manager operations detected an abnormal behavior of a managed identity used by an AKS addon. The detected activity isn\\'t consistent with the behavior of the associated addon. While this activity can be legitimate, such behavior might indicate that the identity was gained by an attacker, possibly from a compromised container in the Kubernetes cluster.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "K8S_ServiceAccountRareOperation",
      "name": "Abnormal Kubernetes service account operation detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected abnormal behavior by a service account in your Kubernetes cluster. The service account was used for an operation, which isn't common for this service account. While this activity can be legitimate, such behavior might indicate that the service account is being used for malicious purposes.",
      "mitreTactics": [
        "Lateral Movement",
        "Credential Access"
      ]
    },
    {
      "id": "K8S.NODE_SuspectConnection",
      "name": "An uncommon connection attempt detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected an uncommon connection attempt utilizing a socks protocol. This is very rare in normal operations, but a known technique for attackers attempting to bypass network-layer detections.",
      "mitreTactics": [
        "Execution",
        "Exfiltration",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_TimerServiceDisabled",
      "name": "Attempt to stop apt-daily-upgrade.timer service detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected an attempt to stop apt-daily-upgrade.timer service. Attackers have been observed stopping this service to download malicious files and grant execution privileges for their attacks. This activity can also happen if the service is updated through normal administrative actions.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S.NODE_CommonBot",
      "name": "Behavior similar to common Linux bots detected (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected the execution of a process normally associated with common Linux botnets.",
      "mitreTactics": [
        "Execution",
        "Collection",
        "Command and Control"
      ]
    },
    {
      "id": "K8S.NODE_PrivilegedExecutionInContainer",
      "name": "Command within a container running with high privileges",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Machine logs indicate that a privileged command was run in a Docker container. A privileged command has extended privileges on the host machine.",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "K8S.NODE_PrivilegedContainerArtifacts",
      "name": "Container running in privileged mode",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected the execution of a Docker command that is running a privileged container. The privileged container has full access to the hosting pod or host resource. If compromised, an attacker might use the privileged container to gain access to the hosting pod or host.",
      "mitreTactics": [
        "Privilege Escalation",
        "Execution"
      ]
    },
    {
      "id": "K8S_SensitiveMount",
      "name": "Container with a sensitive volume mount detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new container with a sensitive volume mount. The volume that was detected is a hostPath type which mounts a sensitive file or folder from the node to the container. If the container gets compromised, the attacker can use this mount for gaining access to the node.",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "K8S_CoreDnsModification",
      "name": "CoreDNS modification in Kubernetes detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a modification of the CoreDNS configuration. The configuration of CoreDNS can be modified by overriding its configmap. While this activity can be legitimate, if attackers have permissions to modify the configmap, they can change the behavior of the cluster's DNS server and poison it.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "K8S_AdmissionController",
      "name": "Creation of admission webhook configuration detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new admission webhook configuration. Kubernetes has two built-in generic admission controllers: MutatingAdmissionWebhook and ValidatingAdmissionWebhook. The behavior of these admission controllers is determined by an admission webhook that the user deploys to the cluster. The usage of such admission controllers can be legitimate, however attackers can use such webhooks for modifying the requests (in case of MutatingAdmissionWebhook) or inspecting the requ",
      "mitreTactics": [
        "Credential Access",
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_SuspectDownload",
      "name": "Detected file download from a known malicious source",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a download of a file from a source frequently used to distribute malware.",
      "mitreTactics": [
        "Privilege Escalation",
        "Execution",
        "Exfiltration",
        "Command and Control"
      ]
    },
    {
      "id": "K8S.NODE_SuspectDownloadArtifacts",
      "name": "Detected suspicious file download",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious download of a remote file.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_SuspectNohup",
      "name": "Detected suspicious use of the nohup command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious use of the nohup command. Attackers have been seen using the command nohup to run hidden files from a temporary directory to allow their executables to run in the background. It's rare to see this command run on hidden files located in a temporary directory.",
      "mitreTactics": [
        "Persistence",
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S.NODE_SuspectUserAddition",
      "name": "Detected suspicious use of the useradd command",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious use of the useradd command.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S_MaliciousContainerImage",
      "name": "Digital currency mining container detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a container that has an image associated with a digital currency mining tool.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_DigitalCurrencyMining",
      "name": "Digital currency mining related behavior detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected an execution of a process or command normally associated with digital currency mining.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_ImageBuildOnNode",
      "name": "Docker build operation detected on a Kubernetes node",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a build operation of a container image on a Kubernetes node. While this behavior might be legitimate, attackers might build their malicious images locally to avoid detection.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S_ExposedKubeflow",
      "name": "Exposed Kubeflow dashboard detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "The Kubernetes audit log analysis detected exposure of the Istio Ingress by a load balancer in a cluster that runs Kubeflow. This action might expose the Kubeflow dashboard to the internet. If the dashboard is exposed to the internet, attackers can access it and run malicious containers or code on the cluster. Find more details in the following article: <https://aka.ms/exposedkubeflow-blog>",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S_ExposedDashboard",
      "name": "Exposed Kubernetes dashboard detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected exposure of the Kubernetes Dashboard by a LoadBalancer service. Exposed dashboard allows an unauthenticated access to the cluster management and poses a security threat.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S_ExposedService",
      "name": "Exposed Kubernetes service detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "The Kubernetes audit log analysis detected exposure of a service by a load balancer. This service is related to a sensitive application that allows high impact operations in the cluster such as running processes on the node or creating new containers. In some cases, this service doesn't require authentication. If the service doesn't require authentication, exposing it to the internet poses a security risk.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S_ExposedRedis",
      "name": "Exposed Redis service in AKS detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "The Kubernetes audit log analysis detected exposure of a Redis service by a load balancer. If the service doesn't require authentication, exposing it to the internet poses a security risk.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "K8S.NODE_KnownLinuxDDoSToolkit",
      "name": "Indicators associated with DDOS toolkit detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected file names that are part of a toolkit associated with malware capable of launching DDoS attacks, opening ports and services, and taking full control over the infected system. This could also possibly be legitimate activity.",
      "mitreTactics": [
        "Persistence",
        "Lateral Movement",
        "Execution",
        "Exploitation"
      ]
    },
    {
      "id": "K8S_TI_Proxy",
      "name": "K8S API requests from proxy IP address detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected API requests to your cluster from an IP address that is associated with proxy services, such as TOR. While this behavior can be legitimate, it's often seen in malicious activities, when attackers try to hide their source IP.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S_DeleteEvents",
      "name": "Kubernetes events deleted",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Defender for Cloud detected that some Kubernetes events have been deleted. Kubernetes events are objects in Kubernetes that contain information about changes in the cluster. Attackers might delete those events for hiding their operations in the cluster.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S_PenTestToolsKubeHunter",
      "name": "Kubernetes penetration testing tool detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected usage of Kubernetes penetration testing tool in the AKS cluster. While this behavior can be legitimate, attackers might use such public tools for malicious purposes.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_EICAR",
      "name": "Microsoft Defender for Cloud test alert (not a threat).",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "This is a test alert generated by Microsoft Defender for Cloud. No further action is needed.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S_KubeSystemContainer",
      "name": "New container in the kube-system namespace detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new container in the kube-system namespace that isn't among the containers that normally run in this namespace. The kube-system namespaces shouldn't contain user resources. Attackers can use this namespace for hiding malicious components.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S_HighPrivilegesRole",
      "name": "New high privileges role detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new role with high privileges. A binding to a role with high privileges gives the user\\group high privileges in the cluster. Unnecessary privileges might cause privilege escalation in the cluster.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_KnownLinuxAttackTool",
      "name": "Possible attack tool detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious tool invocation. This tool is often associated with malicious users attacking others.",
      "mitreTactics": [
        "Execution",
        "Collection",
        "Command and Control",
        "Probing"
      ]
    },
    {
      "id": "K8S.NODE_LinuxBackdoorArtifact",
      "name": "Possible backdoor detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious file being downloaded and run. This activity has previously been associated with installation of a backdoor.",
      "mitreTactics": [
        "Persistence",
        "Defense Evasion",
        "Execution",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_ExploitAttempt",
      "name": "Possible command line exploitation attempt",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a possible exploitation attempt against a known vulnerability.",
      "mitreTactics": [
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_KnownLinuxCredentialAccessTool",
      "name": "Possible credential access tool detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a possible known credential access tool was running on the container, as identified by the specified process and commandline history item. This tool is often associated with attacker attempts to access credentials.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "K8S.NODE_CryptoCoinMinerDownload",
      "name": "Possible Cryptocoinminer download detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected download of a file normally associated with digital currency mining.",
      "mitreTactics": [
        "Defense Evasion",
        "Command and Control",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_SystemLogRemoval",
      "name": "Possible Log Tampering Activity Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a possible removal of files that tracks user's activity during the course of its operation. Attackers often try to evade detection and leave no trace of malicious activities by deleting such log files.",
      "mitreTactics": [
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S.NODE_SuspectPasswordChange",
      "name": "Possible password change using crypt-method detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a password change using the crypt method. Attackers can make this change to continue access and gain persistence after compromise.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "K8S.NODE_SuspectPortForwarding",
      "name": "Potential port forwarding to external IP address",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected an initiation of port forwarding to an external IP address.",
      "mitreTactics": [
        "Exfiltration",
        "Command and Control"
      ]
    },
    {
      "id": "K8S.NODE_ReverseShell",
      "name": "Potential reverse shell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a potential reverse shell. These are used to get a compromised machine to call back into a machine an attacker owns.",
      "mitreTactics": [
        "Exfiltration",
        "Exploitation"
      ]
    },
    {
      "id": "K8S_PrivilegedContainer",
      "name": "Privileged container detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new privileged container. A privileged container has access to the node's resources and breaks the isolation between containers. If compromised, an attacker can use the privileged container to gain access to the node.",
      "mitreTactics": [
        "Privilege Escalation"
      ]
    },
    {
      "id": "K8S.NODE_CryptoCoinMinerArtifacts",
      "name": "Process associated with digital currency mining detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container detected the execution of a process normally associated with digital currency mining.",
      "mitreTactics": [
        "Execution",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_SshKeyAccess",
      "name": "Process seen accessing the SSH authorized keys file in an unusual way",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "An SSH authorized_keys file was accessed in a method similar to known malware campaigns. This access could signify that an actor is attempting to gain persistent access to a machine.",
      "mitreTactics": [
        "Unknown"
      ]
    },
    {
      "id": "K8S_ClusterAdminBinding",
      "name": "Role binding to the cluster-admin role detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Kubernetes audit log analysis detected a new binding to the cluster-admin role which gives administrator privileges. Unnecessary administrator privileges might cause privilege escalation in the cluster.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_SuspectProcessTermination",
      "name": "Security-related process termination detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected an attempt to terminate processes related to security monitoring on the container. Attackers will often try to terminate such processes using predefined scripts post-compromise.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_ContainerSSH",
      "name": "SSH server is running inside a container",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container detected an SSH server running inside the container.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_TimestampTampering",
      "name": "Suspicious file timestamp modification",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious timestamp modification. Attackers will often copy timestamps from existing legitimate files to new tools to avoid detection of these newly dropped files.",
      "mitreTactics": [
        "Persistence",
        "Defense Evasion"
      ]
    },
    {
      "id": "K8S.NODE_KubernetesAPI",
      "name": "Suspicious request to Kubernetes API",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container indicates that a suspicious request was made to the Kubernetes API. The request was sent from a container in the cluster. Although this behavior can be intentional, it might indicate that a compromised container is running in the cluster.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "K8S.NODE_KubernetesDashboard",
      "name": "Suspicious request to the Kubernetes Dashboard",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container indicates that a suspicious request was made to the Kubernetes Dashboard. The request was sent from a container in the cluster. Although this behavior can be intentional, it might indicate that a compromised container is running in the cluster.",
      "mitreTactics": [
        "Lateral Movement"
      ]
    },
    {
      "id": "K8S.NODE_CryptoCoinMinerExecution",
      "name": "Potential crypto coin miner started",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a process being started in a way normally associated with digital currency mining.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_SuspectPasswordFileAccess",
      "name": "Suspicious password access",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected suspicious attempt to access encrypted user passwords.",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "K8S.NODE_Webshell",
      "name": "Possible malicious web shell detected.",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container detected a possible web shell. Attackers will often upload a web shell to a compute resource they have compromised to gain persistence or for further exploitation.",
      "mitreTactics": [
        "Persistence",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_ReconnaissanceArtifactsBurst",
      "name": "Burst of multiple reconnaissance commands could indicate initial activity after compromise",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of host/device data detected execution of multiple reconnaissance commands related to gathering system or host details performed by attackers after initial compromise.",
      "mitreTactics": [
        "Discovery",
        "Collection"
      ]
    },
    {
      "id": "K8S.NODE_DownloadAndRunCombo",
      "name": "Suspicious Download Then Run Activity",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a file being downloaded then run in the same command. While this isn't always malicious, this is a very common technique attackers use to get malicious files onto victim machines.",
      "mitreTactics": [
        "Execution",
        "Command and Control",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_KubeConfigAccess",
      "name": "Access to kubelet kubeconfig file detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running on a Kubernetes cluster node detected access to kubeconfig file on the host. The kubeconfig file, normally used by the Kubelet process, contains credentials to the Kubernetes cluster API server. Access to this file is often associated with attackers attempting to access those credentials, or with security scanning tools which check if the file is accessible.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "K8S.NODE_ImdsCall",
      "name": "Access to cloud metadata service detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container detected access to the cloud metadata service for acquiring identity token. The container doesn't normally perform such operation. While this behavior might be legitimate, attackers might use this technique to access cloud resources after gaining initial access to a running container.",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "K8S.NODE_MitreCalderaTools",
      "name": "MITRE Caldera agent detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers (archive)",
      "sourceType": "archive",
      "description": "Analysis of processes running within a container or directly on a Kubernetes node, has detected a suspicious process. This is often associated with the MITRE 54ndc47 agent, which could be used maliciously to attack other machines. <sup><a name=\"footnote1\"></a>1</sup>: **Preview for non-AKS clusters**: This alert is generally available for AKS clusters, but it is in preview for other environments, such as Azure Arc, EKS, and GKE. <sup><a name=\"footnote2\"></a>2</sup>: **Limitations on GKE clusters",
      "mitreTactics": [
        "Persistence",
        "Privilege Escalation",
        "Defense Evasion",
        "Credential Access",
        "Discovery",
        "Lateral Movement",
        "Execution",
        "Collection",
        "Exfiltration",
        "Command and Control",
        "Probing",
        "Exploitation"
      ]
    },
    {
      "id": "AppServices_LinuxCommandOnWindows",
      "name": "An attempt to run Linux commands on a Windows App Service",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of App Service processes detected an attempt to run a Linux command on a Windows App Service. This action was running by the web application. This behavior is often seen during campaigns that exploit a vulnerability in a common web application. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_IncomingTiClientIpFtp",
      "name": "An IP that connected to your Azure App Service FTP Interface was found in Threat Intelligence",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service FTP log indicates a connection from a source address that was found in the threat intelligence feed. During this connection, a user accessed the pages listed. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "AppServices_HighPrivilegeCommand",
      "name": "Attempt to run high privilege command detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of App Service processes detected an attempt to run a command that requires high privileges. The command ran in the web application context. While this behavior can be legitimate, in web applications this behavior is also observed in malicious activities. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_AnomalousPageAccess",
      "name": "Connection to web page from anomalous IP address detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates an anomalous connection to a sensitive web page from the listed source IP address. This might indicate that someone is attempting a brute force attack into your web app administration pages. It might also be the result of a new IP address being used by a legitimate user. If the source IP address is trusted, you can safely suppress this alert for this resource. To learn how to suppress security alerts, see Suppress alerts from Microsoft Defender for Cloud.",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "AppServices_DanglingDomain",
      "name": "Dangling DNS record for an App Service resource detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "A DNS record that points to a recently deleted App Service resource (also known as \"dangling DNS\" entry) has been detected. This leaves you susceptible to a subdomain takeover. Subdomain takeovers enable malicious actors to redirect traffic intended for an organization's domain to a site performing malicious activity. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_Base64EncodedExecutableInCommandLineParams",
      "name": "Detected encoded executable in command line data",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data on {Compromised host} detected a base-64 encoded executable. This has previously been associated with attackers attempting to construct executables on-the-fly through a sequence of commands, and attempting to evade intrusion detection systems by ensuring that no individual command would trigger an alert. This could be legitimate activity, or an indication of a compromised host. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "AppServices_SuspectDownload",
      "name": "Detected file download from a known malicious source",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data has detected the download of a file from a known malware source on your host. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Privilege Escalation",
        "Execution",
        "Exfiltration",
        "Command and Control"
      ]
    },
    {
      "id": "AppServices_SuspectDownloadArtifacts",
      "name": "Detected suspicious file download",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data has detected suspicious download of remote file. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Persistence"
      ]
    },
    {
      "id": "AppServices_DigitalCurrencyMining",
      "name": "Digital currency mining related behavior detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data on Inn-Flow-WebJobs detected the execution of a process or command normally associated with digital currency mining. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_ExecutableDecodedUsingCertutil",
      "name": "Executable decoded using certutil",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data on [Compromised entity] detected that certutil.exe, a built-in administrator utility, was being used to decode an executable instead of its mainstream purpose that relates to manipulating certificates and certificate data. Attackers are known to abuse functionality of legitimate administrator tools to perform malicious actions, for example using a tool such as certutil.exe to decode a malicious executable that will then be subsequently executed. (Applies to: App Service on ",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "AppServices_FilelessAttackBehaviorDetection",
      "name": "Fileless attack behavior detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "The memory of the process specified below contains behaviors commonly used by fileless attacks. Specific behaviors include: {list of observed behaviors} (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_FilelessAttackTechniqueDetection",
      "name": "Fileless attack technique detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "The memory of the process specified below contains evidence of a fileless attack technique. Fileless attacks are used by attackers to execute code while evading detection by security software. Specific behaviors include: {list of observed behaviors} (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_FilelessAttackToolkitDetection",
      "name": "Fileless attack toolkit detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "The memory of the process specified below contains a fileless attack toolkit: {ToolKitName}. Fileless attack toolkits typically do not have a presence on the filesystem, making detection by traditional anti-virus software difficult. Specific behaviors include: {list of observed behaviors} (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "AppServices_EICAR",
      "name": "Microsoft Defender for Cloud test alert for App Service (not a threat)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "This is a test alert generated by Microsoft Defender for Cloud. No further action is needed. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_Nmap",
      "name": "NMap scanning detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates a possible web fingerprinting activity on your App Service resource. The suspicious activity detected is associated with NMAP. Attackers often use this tool for probing the web application to find vulnerabilities. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "AppServices_PhishingContent",
      "name": "Phishing content hosted on Azure Webapps",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "URL used for phishing attack found on the Azure AppServices website. This URL was part of a phishing attack sent to Microsoft 365 customers. The content typically lures visitors into entering their corporate credentials or financial information into a legitimate looking website. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "AppServices_PhpInUploadFolder",
      "name": "PHP file in upload folder",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates an access to a suspicious PHP page located in the upload folder. This type of folder doesn't usually contain PHP files. The existence of this type of file might indicate an exploitation taking advantage of arbitrary file upload vulnerabilities. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_CryptoCoinMinerDownload",
      "name": "Possible Cryptocoinminer download detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data has detected the download of a file normally associated with digital currency mining. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Defense Evasion",
        "Command and Control",
        "Exploitation"
      ]
    },
    {
      "id": "AppServices_DataEgressArtifacts",
      "name": "Possible data exfiltration detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host/device data detected a possible data egress condition. Attackers will often egress data from machines they have compromised. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Collection",
        "Exfiltration"
      ]
    },
    {
      "id": "AppServices_PotentialDanglingDomain",
      "name": "Potential dangling DNS record for an App Service resource detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "A DNS record that points to a recently deleted App Service resource (also known as \"dangling DNS\" entry) has been detected. This might leave you susceptible to a subdomain takeover. Subdomain takeovers enable malicious actors to redirect traffic intended for an organization's domain to a site performing malicious activity. In this case, a text record with the Domain Verification ID was found. Such text records prevent subdomain takeover but we still recommend removing the dangling domain. If you",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_ReverseShell",
      "name": "Potential reverse shell detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data detected a potential reverse shell. These are used to get a compromised machine to call back into a machine an attacker owns. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Exfiltration",
        "Exploitation"
      ]
    },
    {
      "id": "AppServices_DownloadCodeFromWebsite",
      "name": "Raw data download detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of App Service processes detected an attempt to download code from raw-data websites such as Pastebin. This action was run by a PHP process. This behavior is associated with attempts to download web shells or other malicious components to the App Service. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_CurlToDisk",
      "name": "Saving curl output to disk detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of App Service processes detected the running of a curl command in which the output was saved to the disk. While this behavior can be legitimate, in web applications this behavior is also observed in malicious activities such as attempts to infect websites with web shells. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_SpamReferrer",
      "name": "Spam folder referrer detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates web activity that was identified as originating from a web site associated with spam activity. This can occur if your website is compromised and used for spam activity. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_ScanSensitivePage",
      "name": "Suspicious access to possibly vulnerable web page detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates a web page that seems to be sensitive was accessed. This suspicious activity originated from a source IP address whose access pattern resembles that of a web scanner. This activity is often associated with an attempt by an attacker to scan your network to try to gain access to sensitive or vulnerable web pages. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "-"
      ]
    },
    {
      "id": "AppServices_CommandlineSuspectDomain",
      "name": "Suspicious domain name reference",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data detected reference to suspicious domain name. Such activity, while possibly legitimate user behavior, is frequently an indication of the download or execution of malicious software. Typical related attacker activity is likely to include the download and execution of further malicious software or remote administration tools. (Applies to: App Service on Linux)",
      "mitreTactics": [
        "Exfiltration"
      ]
    },
    {
      "id": "AppServices_DownloadUsingCertutil",
      "name": "Suspicious download using Certutil detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data on {NAME} detected the use of certutil.exe, a built-in administrator utility, for the download of a binary instead of its mainstream purpose that relates to manipulating certificates and certificate data. Attackers are known to abuse functionality of legitimate administrator tools to perform malicious actions, for example using certutil.exe to download and decode a malicious executable that will then be subsequently executed. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_SuspectPhp",
      "name": "Suspicious PHP execution detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Machine logs indicate that a suspicious PHP process is running. The action included an attempt to run operating system commands or PHP code from the command line, by using the PHP process. While this behavior can be legitimate, in web applications this behavior might indicate malicious activities, such as attempts to infect websites with web shells. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_PowerShellPowerSploitScriptExecution",
      "name": "Suspicious PowerShell cmdlets executed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data indicates execution of known malicious PowerShell PowerSploit cmdlets. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_KnownCredential",
      "name": "Suspicious process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Machine logs indicate that the suspicious process: '%{process path}' was running on the machine, often associated with attacker attempts to access credentials. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Credential Access"
      ]
    },
    {
      "id": "AppServices_ProcessWithKnownSuspiciousExtension",
      "name": "Suspicious process name detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Analysis of host data on {NAME} detected a process whose name is suspicious, for example corresponding to a known attacker tool or named in a way that is suggestive of attacker tools that try to hide in plain sight. This process could be legitimate activity, or an indication that one of your machines has been compromised. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Persistence",
        "Defense Evasion"
      ]
    },
    {
      "id": "AppServices_SVCHostFromInvalidPath",
      "name": "Suspicious SVCHOST process executed",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "The system process SVCHOST was observed running in an abnormal context. Malware often uses SVCHOST to mask its malicious activity. (Applies to: App Service on Windows)",
      "mitreTactics": [
        "Defense Evasion",
        "Execution"
      ]
    },
    {
      "id": "AppServices_UserAgentInjection",
      "name": "Suspicious User Agent detected",
      "severity": "Informational",
      "severityColor": "#6c757d",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates requests with suspicious user agent. This behavior can indicate on attempts to exploit a vulnerability in your App Service application. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Initial Access"
      ]
    },
    {
      "id": "AppServices_WpThemeInjection",
      "name": "Suspicious WordPress theme invocation detected",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates a possible code injection activity on your App Service resource. The suspicious activity detected resembles that of a manipulation of WordPress theme to support server side execution of code, followed by a direct web request to invoke the manipulated theme file. This type of activity was seen in the past as part of an attack campaign over WordPress. If your App Service resource isn't hosting a WordPress site, it isn't vulnerable to this specific code inje",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "AppServices_DrupalScanner",
      "name": "Vulnerability scanner detected",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates that a possible vulnerability scanner was used on your App Service resource. The suspicious activity detected resembles that of tools targeting a content management system (CMS). If your App Service resource isn't hosting a Drupal site, it isn't vulnerable to this specific code injection exploit and you can safely suppress this alert for the resource. To learn how to suppress security alerts, see Suppress alerts from Microsoft Defender for Cloud. (Applies",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "AppServices_JoomlaScanner",
      "name": "Vulnerability scanner detected (Joomla)",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates that a possible vulnerability scanner was used on your App Service resource. The suspicious activity detected resembles that of tools targeting Joomla applications. If your App Service resource isn't hosting a Joomla site, it isn't vulnerable to this specific code injection exploit and you can safely suppress this alert for the resource. To learn how to suppress security alerts, see Suppress alerts from Microsoft Defender for Cloud. (Applies to: App Servi",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "AppServices_WpScanner",
      "name": "Vulnerability scanner detected (WordPress)",
      "severity": "Low",
      "severityColor": "#28a745",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates that a possible vulnerability scanner was used on your App Service resource. The suspicious activity detected resembles that of tools targeting WordPress applications. If your App Service resource isn't hosting a WordPress site, it isn't vulnerable to this specific code injection exploit and you can safely suppress this alert for the resource. To learn how to suppress security alerts, see Suppress alerts from Microsoft Defender for Cloud. (Applies to: App",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "AppServices_WebFingerprinting",
      "name": "Web fingerprinting detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Azure App Service activity log indicates a possible web fingerprinting activity on your App Service resource. The suspicious activity detected is associated with a tool called Blind Elephant. The tool fingerprint web servers and tries to detect the installed applications and version. Attackers often use this tool for probing the web application to find vulnerabilities. (Applies to: App Service on Windows and App Service on Linux)",
      "mitreTactics": [
        "Pre-Attack"
      ]
    },
    {
      "id": "AppServices_SmartScreen",
      "name": "Website is tagged as malicious in threat intelligence feed",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for App Service (archive)",
      "sourceType": "archive",
      "description": "Your website as described below is marked as a malicious site by Windows SmartScreen. If you think this is a false positive, contact Windows SmartScreen via report feedback link provided. (Applies to: App Service on Windows and App Service on Linux) > [!NOTE] > For alerts that are in preview: !INCLUDE [Legalese] ## Next steps - Security alerts in Microsoft Defender for Cloud - Manage and respond to security alerts in Microsoft Defender for Cloud - Continuously export Defender for Cloud data",
      "mitreTactics": [
        "Collection"
      ]
    },
    {
      "id": "K8S.NODE_CPUOptimization",
      "name": "Kubernetes CPU optimization detected.",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "A Kubernetes container ran CPU and memory optimization commands that attackers commonly abuse to force high_performance modes, bypass resource limits, and run cryptomining workloads. \nThis increases resource consumption, reduces cluster performance, raises costs, and affects application availability.",
      "mitreTactics": [
        "Impact"
      ]
    },
    {
      "id": "K8S.NODE_DriftDetection",
      "name": "A drift binary detected executing in the container",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "A process that hasn’t been included in the original image was detected executing in the container. This situation is referred to as image drift and can point to an attacker running an unauthorized process.",
      "mitreTactics": [
        "Execution"
      ]
    },
    {
      "id": "K8S.NODE_LDPreloadManipulation",
      "name": "Command within a container accessed ld.so.preload (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Machine logs indicate that a process inside the container accessed ld.so.preload. This activity is often used by crypto miners and other malware to override legitimate functions.",
      "mitreTactics": [
        "DefenseEvasion"
      ]
    },
    {
      "id": "K8S.NODE_SecretReconnaissance",
      "name": "Possible Secret Reconnaissance Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Analysis of processes running within your workload has detected a suspicious command looking for secrets and tokens. While this behavior might be legitimate, it may also indicate adversaries looking for sensitive information in the environment.",
      "mitreTactics": [
        "CredentialAccess"
      ]
    },
    {
      "id": "K8S.NODE_SensitiveFilesLookUp",
      "name": "Sensitive Files Access Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Analysis of processes running within your workload has detected a suspicious command looking for patterns inside sensitive files. While this behavior might be legitimate, it may also indicate adversaries looking for sensitive information in the environment.",
      "mitreTactics": [
        "CredentialAccess"
      ]
    },
    {
      "id": "K8S.NODE_WebshellActivity",
      "name": "Possible Web Shell Activity Detected",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Analysis of processes running within a container detected a suspicoius command running under a web service. While this behavior might be legitimate, it might indicate a web shell exploitation.",
      "mitreTactics": [
        "Persistence",
        "Exploitation"
      ]
    },
    {
      "id": "K8S.NODE_WorkloadIdentityTheft",
      "name": "Suspicious access to workload identity token or service account token detected",
      "severity": "Low",
      "severityColor": "#17a2b8",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Analysis of processes running within your workload has detected a suspicious command reading the tokens of the service account or the workload identity token inside a pod. While this behavior might be legitimate especially when an application accessing cloud services needs to authenticate using these tokens, it may also indicate adversaries trying to steal tokens to authenticate to your cloud account.",
      "mitreTactics": [
        "CredentialAccess"
      ]
    },
    {
      "id": "K8S_AttemptToTerminateMDCAgent",
      "name": "Attempt to terminate Microsoft Defender for Cloud agent in a cluster (Preview)",
      "severity": "Medium",
      "severityColor": "#ffc107",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Kubernetes audit log analysis detected an attempt to terminate Microsoft Defender for Cloud agent in the cluster. This action might indicate that an attacker has tried to hide malicious actions in the cluster.",
      "mitreTactics": [
        "DefenseEvasion"
      ]
    },
    {
      "id": "K8S_SaSuspiciousOperation",
      "name": "Suspicious Kubernetes service account operation detected",
      "severity": "Low",
      "severityColor": "#17a2b8",
      "source": "Defender for Containers",
      "sourceType": "observed",
      "description": "Kubernetes audit log analysis detected suspicious operation by a service account in your Kubernetes cluster. While this activity can be legitimate, such behavior might indicate that the service account is being used for malicious purposes.",
      "mitreTactics": [
        "Reconnaissance"
      ]
    },
    {
      "id": "Storage.Blob_MalwareScanningCapApproaching",
      "name": "Malware Scanning will stop soon: 75% of monthly gigabytes scan cap reached",
      "severity": "Low",
      "severityColor": "#17a2b8",
      "source": "Defender for Storage",
      "sourceType": "observed",
      "description": "One or more storage accounts in subscription _[REDACTED] have reached 75% of the monthly Malware Scanning cap.\r\n\r\nFor the remainder of this month, you are nearing the threshold where future file uploads will not be scanned if the limit is reached.\r\n\r\nYou may receive multiple alerts for this subscription as more storage accounts approach their cap. To get the full list of affected storage accounts, refer to the _Azure resource_ entities in the _Related entities_ section of this security alert.\r\n\r\nSetting a cap on the amount of GB scanned for malware is a failsafe for containing costs due to unexpected use of storage accounts. However, when the cap is reached, the affected storage accounts become open to the risk of uploading malicious content.\r\n\r\nIf you would like Malware Scanning to continue for the affected storage accounts, you should increase the cap. This can be done for specific storage accounts or for all storage accounts in the subscription.",
      "mitreTactics": [
        "Unknown"
      ]
    },
    {
      "id": "Storage.Blob_MalwareScanningCapReached",
      "name": "Malware Scanning stopped: monthly gigabytes scan cap reached",
      "severity": "Low",
      "severityColor": "#17a2b8",
      "source": "Defender for Storage",
      "sourceType": "observed",
      "description": "One or more storage accounts in subscription _[REDACTED] have reached the monthly Malware Scanning cap.\r\n\r\nFor the remainder of this month, any blobs uploaded to the affected storage accounts will not be scanned for malware and any automation that relies on malware scanning of uploaded blobs will not work.\r\n\r\nYou may receive multiple alerts for this subscription as more storage accounts reach the cap. To get the full list of affected storage accounts, refer to the _Azure resource_ entities in the _Related entities_ section of this security alert.\r\n\r\nSetting a cap on the amount of GB scanned for malware is a failsafe for containing costs due to unexpected use of storage accounts. However, when the cap is reached, the affected storage accounts become open to the risk of uploading malicious content.\r\n\r\nIf you would like Malware Scanning to resume for the affected storage accounts, you should increase the cap. This can be done for specific storage accounts or for all storage accounts in the subscription.",
      "mitreTactics": [
        "Unknown"
      ]
    },
    {
      "id": "VM.Agentless_BackdoorWasDetected",
      "name": "'Berbew' backdoor was detected (Agentless)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Agentless)",
      "sourceType": "observed",
      "description": "Backdoors are malicious remote access tools that allow attackers to access and control infected machines. Backdoors can also be used to exfiltrate data.\r\n\r\nThis detection might indicate that the malware was stopped from delivering its payload. However, it is prudent to check the machine for signs of infection.",
      "mitreTactics": [
        "Unknown"
      ]
    },
    {
      "id": "VM.Agentless_MalwareWasDetected",
      "name": "'Multiverze' malware was detected (Agentless)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Agentless)",
      "sourceType": "observed",
      "description": "Malware and unwanted software are undesirable applications that perform annoying, disruptive, or harmful actions on affected machines. Some of these undesirable applications can replicate and spread from one machine to another. Others are able to receive commands from remote attackers and perform activities associated with cyber attacks.\r\n\r\nThis detection might indicate that the malware was stopped from delivering its payload. However, it is prudent to check the machine for signs of infection.",
      "mitreTactics": [
        "Unknown"
      ]
    },
    {
      "id": "VM.Agentless_RansomwareWasDetected",
      "name": "'CVE' ransomware was detected (Agentless)",
      "severity": "High",
      "severityColor": "#dc3545",
      "source": "Defender for Servers (Agentless)",
      "sourceType": "observed",
      "description": "Ransomware use common methods to encrypt files using keys that are known only to attackers. As a result, victims are unable to access the contents of the encrypted files. Most ransomware display or drop a ransom note—an image or an HTML file that contains information about how to obtain the attacker-supplied decryption tool for a fee.\r\n\r\nTo target documents or other files that contain user data, some ransomware look for files in certain locations and files with certain extension names. It is also common for ransomware to rename encrypted files so that they all use the same extension name. \r\n\r\nThis detection might indicate that the malware was stopped from delivering its payload. However, it is prudent to check the machine for signs of infection.",
      "mitreTactics": [
        "Unknown"
      ]
    }
  ]
}
