Azure azure_defender_for_resource_manager Mappings

Azure Defender for Resource Manager automatically monitors the resource management operations in your organization, whether they're performed through the Azure portal, Azure REST APIs, Azure CLI, or other Azure programmatic clients. Alerts are generated by threats detected in Azure Resource Manager logs and Azure Activity logs. Azure Defender runs advanced security analytics to detect threats and alert you about suspicious activity.

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name
azure_defender_for_resource_manager Azure Defender for Resource Manager detect minimal T1562 Impair Defenses
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1562.001 Disable or Modify Tools
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1580 Cloud Infrastructure Discovery
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1538 Cloud Service Dashboard
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1526 Cloud Service Discovery
azure_defender_for_resource_manager Azure Defender for Resource Manager detect minimal T1069 Permission Groups Discovery
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1069.003 Cloud Groups
azure_defender_for_resource_manager Azure Defender for Resource Manager detect minimal T1087 Account Discovery
azure_defender_for_resource_manager Azure Defender for Resource Manager detect partial T1087.004 Cloud Account
azure_defender_for_resource_manager Azure Defender for Resource Manager detect minimal T1555 Credentials from Password Stores
azure_defender_for_resource_manager Azure Defender for Resource Manager detect minimal T1068 Exploitation for Privilege Escalation