Managed Sentinel – Alert 199

Alert IDMS-A199
Alert NameSuspicious Azure Resource deployment
DescriptionThis alert identifies when a rare Azure Resource and ResourceGroup deployment occurs by a previously unseen Caller.
Severity LevelLow
Threat Indicator
MITRE ATT&CK TacticsDefensiveEvasion
Log sourcesAzureActivity
False Positives
Recommendations