Azure Automation Azure-Microsoft.Automation

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Automation rules that match the resource provider but no specific operation.NN
Microsoft.Automation/automationAccounts/agentRegistrationInformation/regenerateKey/actionWrites a request to regenerate Azure Automation DSC keysNN
Microsoft.Automation/automationAccounts/certificates/deleteDeletes an Azure Automation certificate assetNN
Microsoft.Automation/automationAccounts/certificates/getCount/actionReads the count of certificatesNN
Microsoft.Automation/automationAccounts/certificates/writeCreates or updates an Azure Automation certificate assetNN
Microsoft.Automation/automationAccounts/compilationjobs/writeWrites an Azure Automation DSC's CompilationNN
Microsoft.Automation/automationAccounts/configurations/deleteDeletes an Azure Automation DSC's contentNN
Microsoft.Automation/automationAccounts/configurations/getCount/actionReads the count of an Azure Automation DSC's contentNN
Microsoft.Automation/automationAccounts/configurations/writeWrites an Azure Automation DSC's contentNN
Microsoft.Automation/automationAccounts/connections/deleteDeletes an Azure Automation connection assetNN
Microsoft.Automation/automationAccounts/connections/getCount/actionReads the count of connectionsNN
Microsoft.Automation/automationAccounts/connections/writeCreates or updates an Azure Automation connection assetNN
Microsoft.Automation/automationAccounts/connectionTypes/deleteDeletes an Azure Automation connection type assetNN
Microsoft.Automation/automationAccounts/connectionTypes/writeCreates an Azure Automation connection type assetNN
Microsoft.Automation/automationAccounts/convertGraphRunbookContent/actionConvert Graph Runbook Content to its raw serialized format and vice-versaNN
Microsoft.Automation/automationAccounts/credentials/deleteDeletes an Azure Automation credential assetNN
Microsoft.Automation/automationAccounts/credentials/getCount/actionReads the count of credentialsNN
Microsoft.Automation/automationAccounts/credentials/writeCreates or updates an Azure Automation credential assetNN
Microsoft.Automation/automationAccounts/deleteDeletes an Azure Automation accountYN
Microsoft.Automation/automationAccounts/diagnosticSettings/writeSets the diagnostic setting for the resourceNN
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/deleteDeletes a Hybrid Runbook Worker GroupNN
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/deleteDeletes a Hybrid Runbook WorkerNN
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/move/actionMoves Hybrid Runbook Worker from one Worker Group to anotherNN
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/writeCreates a Hybrid Runbook WorkerNN
Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/writeCreates a Hybrid Runbook Worker GroupNN
Microsoft.Automation/automationAccounts/jobs/resume/actionResumes an Azure Automation jobNN
Microsoft.Automation/automationAccounts/jobs/runbookContent/actionGets the content of the Azure Automation runbook at the time of the job executionNN
Microsoft.Automation/automationAccounts/jobs/stop/actionStops an Azure Automation jobNN
Microsoft.Automation/automationAccounts/jobs/suspend/actionSuspends an Azure Automation jobNN
Microsoft.Automation/automationAccounts/jobs/writeCreates an Azure Automation jobNY
Microsoft.Automation/automationAccounts/jobSchedules/deleteDeletes an Azure Automation job scheduleNN
Microsoft.Automation/automationAccounts/jobSchedules/writeCreates an Azure Automation job scheduleNN
Microsoft.Automation/automationAccounts/listKeys/actionReads the Keys for the automation accountNN
Microsoft.Automation/automationAccounts/modules/deleteDeletes an Azure Automation Powershell moduleNN
Microsoft.Automation/automationAccounts/modules/getCount/actionGets the count of Powershell modules within the Automation AccountNN
Microsoft.Automation/automationAccounts/modules/writeCreates or updates an Azure Automation Powershell moduleNN
Microsoft.Automation/automationAccounts/nodeConfigurations/deleteDeletes an Azure Automation DSC's node configurationNN
Microsoft.Automation/automationAccounts/nodeConfigurations/rawContent/actionReads an Azure Automation DSC's node configuration contentNN
Microsoft.Automation/automationAccounts/nodeConfigurations/writeWrites an Azure Automation DSC's node configurationNN
Microsoft.Automation/automationAccounts/nodes/deleteDeletes Azure Automation DSC nodesNN
Microsoft.Automation/automationAccounts/nodes/writeCreates or updates Azure Automation DSC nodesNN
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/deleteDelete an Azure Automation Private Endpoint Connection ProxyNN
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/validate/actionValidate a Private endpoint connection request (groupId Validation)NN
Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/writeCreates an Azure Automation Private Endpoint Connection ProxyNN
Microsoft.Automation/automationAccounts/privateEndpointConnections/deleteDelete an Azure Automation Private Endpoint ConnectionNN
Microsoft.Automation/automationAccounts/privateEndpointConnections/writeApprove or reject an Azure Automation Private Endpoint ConnectionNN
Microsoft.Automation/automationAccounts/python2Packages/deleteDeletes an Azure Automation Python 2 packageNN
Microsoft.Automation/automationAccounts/python2Packages/writeCreates or updates an Azure Automation Python 2 packageNN
Microsoft.Automation/automationAccounts/python3Packages/deleteDeletes an Azure Automation Python 3 packageNN
Microsoft.Automation/automationAccounts/python3Packages/writeCreates or updates an Azure Automation Python 3 packageNN
Microsoft.Automation/automationAccounts/runbooks/deleteDeletes an Azure Automation runbookNY
Microsoft.Automation/automationAccounts/runbooks/draft/content/writeCreates the content of an Azure Automation runbook draftNN
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/resume/actionResumes an Azure Automation runbook draft test jobNN
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/stop/actionStops an Azure Automation runbook draft test jobNN
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/suspend/actionSuspends an Azure Automation runbook draft test jobNN
Microsoft.Automation/automationAccounts/runbooks/draft/testJob/writeCreates an Azure Automation runbook draft test jobNN
Microsoft.Automation/automationAccounts/runbooks/draft/undoEdit/actionUndo edits to an Azure Automation runbook draftNN
Microsoft.Automation/automationAccounts/runbooks/draft/writeCreates an Azure Automation runbook draftYY
Microsoft.Automation/automationAccounts/runbooks/getCount/actionGets the count of Azure Automation runbooksNN
Microsoft.Automation/automationAccounts/runbooks/publish/actionPublishes an Azure Automation runbook draftNY
Microsoft.Automation/automationAccounts/runbooks/writeCreates or updates an Azure Automation runbookNY
Microsoft.Automation/automationAccounts/schedules/deleteDeletes an Azure Automation schedule assetNN
Microsoft.Automation/automationAccounts/schedules/getCount/actionGets the count of Azure Automation schedulesNN
Microsoft.Automation/automationAccounts/schedules/writeCreates or updates an Azure Automation schedule assetNY
Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/deleteDeletes an Azure Automation Software Update ConfigurationNN
Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/writeCreates or updates Azure Automation Software Update ConfigurationNN
Microsoft.Automation/automationAccounts/sourceControls/deleteDeletes an Azure Automation source controlNN
Microsoft.Automation/automationAccounts/sourceControls/listKeys/writeCreates or updates an Azure Automation source controlNN
Microsoft.Automation/automationAccounts/sourceControls/writeCreates or updates an Azure Automation source controlNN
Microsoft.Automation/automationAccounts/variables/deleteDeletes an Azure Automation variable assetNN
Microsoft.Automation/automationAccounts/variables/writeCreates or updates an Azure Automation variable assetNN
Microsoft.Automation/automationAccounts/watchers/deleteDelete an Azure Automation watcher jobNN
Microsoft.Automation/automationAccounts/watchers/start/actionStart an Azure Automation watcher jobNN
Microsoft.Automation/automationAccounts/watchers/stop/actionStop an Azure Automation watcher jobNN
Microsoft.Automation/automationAccounts/watchers/watcherActions/deleteDelete an Azure Automation watcher job actionsNN
Microsoft.Automation/automationAccounts/watchers/watcherActions/writeCreate an Azure Automation watcher job actionsNN
Microsoft.Automation/automationAccounts/watchers/writeCreates an Azure Automation watcher jobNN
Microsoft.Automation/automationAccounts/webhooks/actionAzure Automation control-plane operation recorded in the activity log when a runbook webhook is generated. Persistence-relevant: an adversary can create a webhook to trigger a runbook through an unauthenticated, internet-exposed URL.NY
Microsoft.Automation/automationAccounts/webhooks/deleteDeletes an Azure Automation webhookNN
Microsoft.Automation/automationAccounts/webhooks/writeCreates or updates an Azure Automation webhookNY
Microsoft.Automation/automationAccounts/writeCreates or updates an Azure Automation accountYY
Microsoft.Automation/register/actionRegisters the subscription to Azure AutomationYN

any: Azure Automation (catch-all)

#
Namespace
Microsoft.Automation

Description

Catch-all for Azure-Microsoft.Automation rules that match the resource provider but no specific operation.

Microsoft.Automation/automationAccounts/agentRegistrationInformation/regenerateKey/action

#
Namespace
Microsoft.Automation

Description

Writes a request to regenerate Azure Automation DSC keys

Microsoft.Automation/automationAccounts/certificates/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation certificate asset

Microsoft.Automation/automationAccounts/certificates/getCount/action

#
Namespace
Microsoft.Automation

Description

Reads the count of certificates

Microsoft.Automation/automationAccounts/certificates/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation certificate asset

Microsoft.Automation/automationAccounts/compilationjobs/write

#
Namespace
Microsoft.Automation

Description

Writes an Azure Automation DSC's Compilation

Microsoft.Automation/automationAccounts/configurations/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation DSC's content

Microsoft.Automation/automationAccounts/configurations/getCount/action

#
Namespace
Microsoft.Automation

Description

Reads the count of an Azure Automation DSC's content

Microsoft.Automation/automationAccounts/configurations/write

#
Namespace
Microsoft.Automation

Description

Writes an Azure Automation DSC's content

Microsoft.Automation/automationAccounts/connections/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation connection asset

Microsoft.Automation/automationAccounts/connections/getCount/action

#
Namespace
Microsoft.Automation

Description

Reads the count of connections

Microsoft.Automation/automationAccounts/connections/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation connection asset

Microsoft.Automation/automationAccounts/connectionTypes/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation connection type asset

Microsoft.Automation/automationAccounts/connectionTypes/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation connection type asset

Microsoft.Automation/automationAccounts/convertGraphRunbookContent/action

#
Namespace
Microsoft.Automation

Description

Convert Graph Runbook Content to its raw serialized format and vice-versa

Microsoft.Automation/automationAccounts/credentials/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation credential asset

Microsoft.Automation/automationAccounts/credentials/getCount/action

#
Namespace
Microsoft.Automation

Description

Reads the count of credentials

Microsoft.Automation/automationAccounts/credentials/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation credential asset

Microsoft.Automation/automationAccounts/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation account

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/dwh92eef0automation",
    "action": "Microsoft.Automation/automationAccounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/dwh92eef0automation",
    "action": "Microsoft.Automation/automationAccounts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "af55874c-8bf4-45ac-803d-776162ba1d61",
  "EventDataId": "bc0984dc-5eb5-25c7-50fc-a929012019f1",
  "EventSubmissionTimestamp": "2026-07-02T17:24:58.6949672Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.AUTOMATION/AUTOMATIONACCOUNTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/dwh92eef0automation",
    "message": "Microsoft.Automation/automationAccounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bc0984dc-5eb5-25c7-50fc-a929012019f1",
    "eventSubmissionTimestamp": "2026-07-02T17:24:58.6949672Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0automation",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/dwh92eef0automation",
    "message": "Microsoft.Automation/automationAccounts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bc0984dc-5eb5-25c7-50fc-a929012019f1",
    "eventSubmissionTimestamp": "2026-07-02T17:24:58.6949672Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0automation",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.AUTOMATION",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Automation/automationAccounts/diagnosticSettings/write

#
Namespace
Microsoft.Automation

Description

Sets the diagnostic setting for the resource

Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/delete

#
Namespace
Microsoft.Automation

Description

Deletes a Hybrid Runbook Worker Group

Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/delete

#
Namespace
Microsoft.Automation

Description

Deletes a Hybrid Runbook Worker

Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/move/action

#
Namespace
Microsoft.Automation

Description

Moves Hybrid Runbook Worker from one Worker Group to another

Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/write

#
Namespace
Microsoft.Automation

Description

Creates a Hybrid Runbook Worker

Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/write

#
Namespace
Microsoft.Automation

Description

Creates a Hybrid Runbook Worker Group

Microsoft.Automation/automationAccounts/jobs/resume/action

#
Namespace
Microsoft.Automation

Description

Resumes an Azure Automation job

Microsoft.Automation/automationAccounts/jobs/runbookContent/action

#
Namespace
Microsoft.Automation

Description

Gets the content of the Azure Automation runbook at the time of the job execution

Microsoft.Automation/automationAccounts/jobs/stop/action

#
Namespace
Microsoft.Automation

Description

Stops an Azure Automation job

Microsoft.Automation/automationAccounts/jobs/suspend/action

#
Namespace
Microsoft.Automation

Description

Suspends an Azure Automation job

Microsoft.Automation/automationAccounts/jobs/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation job

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Serverless Script Execution source informational: Detects when serverless resources execute PowerShell or Python scripts through Azure Automation runbook jobs or Azure Function Apps. Adversaries may abuse access to serverless resources to execute commands with inherited permissions from managed identities, RunAs accounts, or hybrid worker groups.T1059, T1651

Microsoft.Automation/automationAccounts/jobSchedules/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation job schedule

Microsoft.Automation/automationAccounts/jobSchedules/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation job schedule

Microsoft.Automation/automationAccounts/listKeys/action

#
Namespace
Microsoft.Automation

Description

Reads the Keys for the automation account

Microsoft.Automation/automationAccounts/modules/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation Powershell module

Microsoft.Automation/automationAccounts/modules/getCount/action

#
Namespace
Microsoft.Automation

Description

Gets the count of Powershell modules within the Automation Account

Microsoft.Automation/automationAccounts/modules/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation Powershell module

Microsoft.Automation/automationAccounts/nodeConfigurations/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation DSC's node configuration

Microsoft.Automation/automationAccounts/nodeConfigurations/rawContent/action

#
Namespace
Microsoft.Automation

Description

Reads an Azure Automation DSC's node configuration content

Microsoft.Automation/automationAccounts/nodeConfigurations/write

#
Namespace
Microsoft.Automation

Description

Writes an Azure Automation DSC's node configuration

Microsoft.Automation/automationAccounts/nodes/delete

#
Namespace
Microsoft.Automation

Description

Deletes Azure Automation DSC nodes

Microsoft.Automation/automationAccounts/nodes/write

#
Namespace
Microsoft.Automation

Description

Creates or updates Azure Automation DSC nodes

Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Automation

Description

Delete an Azure Automation Private Endpoint Connection Proxy

Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Automation

Description

Validate a Private endpoint connection request (groupId Validation)

Microsoft.Automation/automationAccounts/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation Private Endpoint Connection Proxy

Microsoft.Automation/automationAccounts/privateEndpointConnections/delete

#
Namespace
Microsoft.Automation

Description

Delete an Azure Automation Private Endpoint Connection

Microsoft.Automation/automationAccounts/privateEndpointConnections/write

#
Namespace
Microsoft.Automation

Description

Approve or reject an Azure Automation Private Endpoint Connection

Microsoft.Automation/automationAccounts/python2Packages/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation Python 2 package

Microsoft.Automation/automationAccounts/python2Packages/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation Python 2 package

Microsoft.Automation/automationAccounts/python3Packages/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation Python 3 package

Microsoft.Automation/automationAccounts/python3Packages/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation Python 3 package

Microsoft.Automation/automationAccounts/runbooks/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation runbook

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Automation Runbook Deleted source low: Identifies when an Azure Automation runbook is deleted. An adversary may delete an Azure Automation runbook in order to disrupt their target's automated business operations or to remove a malicious runbook for defense evasion.T1485

Panther #

  • Azure Automation Runbook Deleted source informational: Detects when an Azure Automation runbook is deleted. Adversaries may delete runbooks to cover their tracks after using them for malicious purposes, to disrupt automated security responses, or to eliminate forensic evidence. Legitimate runbook deletions should be rare and controlled through change management processes.T1070

Microsoft.Automation/automationAccounts/runbooks/draft/content/write

#
Namespace
Microsoft.Automation

Description

Creates the content of an Azure Automation runbook draft

Microsoft.Automation/automationAccounts/runbooks/draft/testJob/resume/action

#
Namespace
Microsoft.Automation

Description

Resumes an Azure Automation runbook draft test job

Microsoft.Automation/automationAccounts/runbooks/draft/testJob/stop/action

#
Namespace
Microsoft.Automation

Description

Stops an Azure Automation runbook draft test job

Microsoft.Automation/automationAccounts/runbooks/draft/testJob/suspend/action

#
Namespace
Microsoft.Automation

Description

Suspends an Azure Automation runbook draft test job

Microsoft.Automation/automationAccounts/runbooks/draft/testJob/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation runbook draft test job

Microsoft.Automation/automationAccounts/runbooks/draft/undoEdit/action

#
Namespace
Microsoft.Automation

Description

Undo edits to an Azure Automation runbook draft

Microsoft.Automation/automationAccounts/runbooks/draft/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation runbook draft

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto/runbooks/zcrb/draft/content",
    "action": "Microsoft.Automation/automationAccounts/runbooks/draft/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto/runbooks/zcrb/draft/content",
    "action": "Microsoft.Automation/automationAccounts/runbooks/draft/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3b27a961-98fa-467c-bfd2-3fac47ab4595",
  "EventDataId": "fafa574a-2180-9b37-6558-d05626ad49e1",
  "EventSubmissionTimestamp": "2026-06-29T17:43:18.9321792Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.AUTOMATION/AUTOMATIONACCOUNTS/RUNBOOKS/DRAFT/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto/runbooks/zcrb/draft/content",
    "message": "Microsoft.Automation/automationAccounts/runbooks/draft/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fafa574a-2180-9b37-6558-d05626ad49e1",
    "eventSubmissionTimestamp": "2026-06-29T17:43:18.9321792Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcauto/zcrb/content",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto/runbooks/zcrb/draft/content",
    "message": "Microsoft.Automation/automationAccounts/runbooks/draft/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fafa574a-2180-9b37-6558-d05626ad49e1",
    "eventSubmissionTimestamp": "2026-06-29T17:43:18.9321792Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcauto/zcrb/content",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "resourceGroup": "RG-LOGCAPTURE-GEN"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.AUTOMATION",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:43:18.9321792Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.automation/automationaccounts/zcauto/runbooks/zcrb/draft/content"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

Microsoft.Automation/automationAccounts/runbooks/getCount/action

#
Namespace
Microsoft.Automation

Description

Gets the count of Azure Automation runbooks

Microsoft.Automation/automationAccounts/runbooks/publish/action

#
Namespace
Microsoft.Automation

Description

Publishes an Azure Automation runbook draft

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

Microsoft.Automation/automationAccounts/runbooks/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation runbook

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
status.value (splunk rule field)eqsucceeded1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

  • Azure Automation Runbook Created source: The following analytic detects the creation of a new Azure Automation Runbook within an Azure tenant. It leverages Azure Audit events, specifically the Azure Activity log category, to identify when a new Runbook is created or updated. This…T1136, T1136.003

Panther #

Microsoft.Automation/automationAccounts/schedules/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation schedule asset

Microsoft.Automation/automationAccounts/schedules/getCount/action

#
Namespace
Microsoft.Automation

Description

Gets the count of Azure Automation schedules

Microsoft.Automation/automationAccounts/schedules/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation schedule asset

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Azure Automation Schedule Created or Modified source informational: Detects when an Azure Automation schedule is created or modified. Schedules define when and how often automation runbooks execute. Adversaries may create or modify schedules to establish persistence by executing malicious runbooks at regular intervals or specific times. This technique allows attackers to maintain access and execute commands without requiring direct interaction.T1053.005, T1068

Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation Software Update Configuration

Microsoft.Automation/automationAccounts/softwareUpdateConfigurations/write

#
Namespace
Microsoft.Automation

Description

Creates or updates Azure Automation Software Update Configuration

Microsoft.Automation/automationAccounts/sourceControls/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation source control

Microsoft.Automation/automationAccounts/sourceControls/listKeys/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation source control

Microsoft.Automation/automationAccounts/sourceControls/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation source control

Microsoft.Automation/automationAccounts/variables/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation variable asset

Microsoft.Automation/automationAccounts/variables/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation variable asset

Microsoft.Automation/automationAccounts/watchers/delete

#
Namespace
Microsoft.Automation

Description

Delete an Azure Automation watcher job

Microsoft.Automation/automationAccounts/watchers/start/action

#
Namespace
Microsoft.Automation

Description

Start an Azure Automation watcher job

Microsoft.Automation/automationAccounts/watchers/stop/action

#
Namespace
Microsoft.Automation

Description

Stop an Azure Automation watcher job

Microsoft.Automation/automationAccounts/watchers/watcherActions/delete

#
Namespace
Microsoft.Automation

Description

Delete an Azure Automation watcher job actions

Microsoft.Automation/automationAccounts/watchers/watcherActions/write

#
Namespace
Microsoft.Automation

Description

Create an Azure Automation watcher job actions

Microsoft.Automation/automationAccounts/watchers/write

#
Namespace
Microsoft.Automation

Description

Creates an Azure Automation watcher job

Microsoft.Automation/automationAccounts/webhooks/action

#
Namespace
Microsoft.Automation

Description

Azure Automation control-plane operation recorded in the activity log when a runbook webhook is generated. Persistence-relevant: an adversary can create a webhook to trigger a runbook through an unauthenticated, internet-exposed URL.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

Microsoft.Automation/automationAccounts/webhooks/delete

#
Namespace
Microsoft.Automation

Description

Deletes an Azure Automation webhook

Microsoft.Automation/automationAccounts/webhooks/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation webhook

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
status.value (splunk rule field)eqsucceeded1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

  • Azure Runbook Webhook Created source: The following analytic detects the creation of a new Automation Runbook Webhook within an Azure tenant. It leverages Azure Audit events, specifically the "Create or Update an Azure Automation webhook" operation, to identify this activity.…T1078, T1078.004

Panther #

Microsoft.Automation/automationAccounts/write

#
Namespace
Microsoft.Automation

Description

Creates or updates an Azure Automation account

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto3",
    "action": "Microsoft.Automation/automationAccounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto3",
    "action": "Microsoft.Automation/automationAccounts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "617e1dc9-23b7-44b4-b7d7-281f0cdd7b65",
  "EventDataId": "411a88c5-fa03-2c8f-6e48-9248f437db53",
  "EventSubmissionTimestamp": "2026-06-29T19:04:00.8956296Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.AUTOMATION/AUTOMATIONACCOUNTS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto3",
    "message": "Microsoft.Automation/automationAccounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "411a88c5-fa03-2c8f-6e48-9248f437db53",
    "eventSubmissionTimestamp": "2026-06-29T19:04:00.8956296Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcauto3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Automation/automationAccounts/zcauto3",
    "message": "Microsoft.Automation/automationAccounts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "411a88c5-fa03-2c8f-6e48-9248f437db53",
    "eventSubmissionTimestamp": "2026-06-29T19:04:00.8956296Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcauto3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.AUTOMATION",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:04:00.8956296Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.automation/automationaccounts/zcauto3"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded1 rulepanther
resultType (panther rule field)inSuccess1 rulepanther
status.value (splunk rule field)eqsucceeded1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Automation Account Created source low: Identifies when an Azure Automation account is created. Azure Automation accounts can be used to automate management tasks and orchestrate actions across systems. An adversary may create an Automation account in order to maintain persistence in their target's environment.T1078

Splunk #

  • Azure Automation Account Created source: The following analytic detects the creation of a new Azure Automation account within an Azure tenant. It leverages Azure Audit events, specifically the Azure Activity log category, to identify when an account is created or updated. This…T1136, T1136.003

Panther #

  • Azure Automation Account Created source informational: Detects when an Azure Automation account is created. Azure Automation accounts can be used to automate management tasks and orchestrate actions across systems. Adversaries may create Automation accounts to maintain persistence in their target's environment by leveraging managed identities and runbooks to execute code with elevated privileges.T1078

Microsoft.Automation/register/action

#
Namespace
Microsoft.Automation

Description

Registers the subscription to Azure Automation

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Automation/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Automation/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "8606121c-3afa-4af8-adec-b6e59704892d",
  "EventDataId": "2ad62483-c1ab-9cd8-e1c0-fe09c5493fdf",
  "EventSubmissionTimestamp": "2026-06-29T17:41:53.7457549Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.AUTOMATION/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Automation",
    "message": "Microsoft.Automation/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2ad62483-c1ab-9cd8-e1c0-fe09c5493fdf",
    "eventSubmissionTimestamp": "2026-06-29T17:41:53.7457549Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Automation",
    "message": "Microsoft.Automation/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2ad62483-c1ab-9cd8-e1c0-fe09c5493fdf",
    "eventSubmissionTimestamp": "2026-06-29T17:41:53.7457549Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.AUTOMATION",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "Resource": "",
  "ResourceGroup": "",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.AUTOMATION",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:41:53.7457549Z",
  "Type": "AzureActivity",
  "_ResourceId": ""
}

References #