Platform
Azure
5 queries tagged with this platform.
-
Analytics Rules
Detect Autogen Studio Agent Tool Execution Anomaly
AutoGen Studio-hosted AI agent taking code-execution or sensitive-tool actions outside its baseline set — the 'AutoJack' agent-abuse shape.
-
Analytics Rules
Detect Ci Build Egress To First Seen Domain
CI/CD build process reaching out to a domain never seen from your build fleet before — 'the build that called a stranger.'
-
Analytics Rules
Detect Diagnostic Deletion Then Tenant Activity Same Session
Enhanced log-suppression sequence detection that further requires the follow-on activity to share the same CallerIpAddress — same session, not just same identity.
-
Analytics Rules
Detect Diagnostic Deletion Then Tenant Activity Sequence
T1562.008 sequence: Azure diagnostic-setting deletion followed by any activity from the same Caller within 60 minutes.
-
Hunting
Hunt Azure Diagnostic Setting Deletions
Deletions of Azure diagnostic settings — the moment an attacker turns off logging (T1562.008). Step 1 of a two-step sequence.