Suspicious activity

Anomaly detection: service principal executed multiple API calls which changed fw settings



Service principal can remove/alter FW (network, azure servers) rules. If a service principal started executing multiple API calls which try to alter Firewall rules unlike before it may indicate a presence of an unauthorized actor in the cloud environment since this kind of activity is seen mostly when attackers conduct reconnaissance actions in order to map the internal environment and spread inside the environment. It was detected that the service principal {AzureServicePrincipal} has executed multiple API calls to alter FW rules which can be risky.
  • Recommended Mitigation

    It is recommended to review relevant ActivityLog event that issued this API call to determine if this is a legit activity.