Execution (TA0002)(external, opens in a new tab or window)
Persistence (TA0003)(external, opens in a new tab or window)
text code block:data_stream.dataset:azure.activitylogs and event.action:( "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/DELETE" or "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/READ" or "MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/WRITE" or "MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/EXTENSIONS/DELETE" or "MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/EXTENSIONS/READ" or "MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/EXTENSIONS/WRITE" ) and event.outcome:(Success or success) and azure.resource.name:* and source.as.number:(* and not (3598 or 8068 or 8069 or 8070 or 8071 or 8072 or 8073 or 8074 or 8075 or 12076))
Install detection rules in Elastic Security
Detect Azure VM Extension CRUD Operation with Unusual Source ASN in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).