Azure Storage Azure-Microsoft.Storage
any: Azure Storage (catch-all)
#Description
Catch-all for Azure-Microsoft.Storage rules that match the resource provider but no specific operation.
Microsoft.Storage/locations/ActionsRPOperationStatuses/write
#Description
Creates or updates an ActionsRP operation status
Microsoft.Storage/locations/DataManagementRPOperationStatuses/write
#Description
Creates or updates a DataManagamentRP operation status
Microsoft.Storage/locations/deleteVirtualNetworkOrSubnets/action
#Description
Notifies Microsoft.Storage that virtual network or subnet is being deleted
Microsoft.Storage/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/action
#Microsoft.Storage/locations/previewActions/action
#Microsoft.Storage/register/action
#Description
Registers the subscription for the storage resource provider and enables the creation of storage accounts.
Microsoft.Storage/storageAccounts/accountLocks/delete
#Microsoft.Storage/storageAccounts/accountLocks/deleteLock/action
#Microsoft.Storage/storageAccounts/accountLocks/write
#Microsoft.Storage/storageAccounts/accountMigrations/write
#Description
Customer is able to update their storage account redundancy for increased resiliency
Microsoft.Storage/storageAccounts/advancedPlatformMetrics/delete
#Microsoft.Storage/storageAccounts/advancedPlatformMetrics/write
#Microsoft.Storage/storageAccounts/blobServices/containers/clearLegalHold/action
#Description
Clear blob container legal hold
Microsoft.Storage/storageAccounts/blobServices/containers/delete
#Description
Returns the result of deleting a container
Microsoft.Storage/storageAccounts/blobServices/containers/getAcl/action
#Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/delete
#Description
Delete blob container immutability policy
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1490, T1562, T1562.001
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/extend/action
#Description
Extend blob container immutability policy
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/lock/action
#Description
Lock blob container immutability policy
Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies/write
#Description
Put blob container immutability policy
Microsoft.Storage/storageAccounts/blobServices/containers/lease/action
#Description
Returns the result of leasing blob container
Microsoft.Storage/storageAccounts/blobServices/containers/migrate/action
#Microsoft.Storage/storageAccounts/blobServices/containers/setAcl/action
#Microsoft.Storage/storageAccounts/blobServices/containers/setLegalHold/action
#Description
Set blob container legal hold
Microsoft.Storage/storageAccounts/blobServices/containers/write
#Description
Returns the result of patch blob container
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 2 rules | panther |
resultType (panther rule field) | in | Success | 2 rules | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1222, T1537, T1619Panther #
T1530↳ also matches Microsoft.Storage/storageAccounts/blobServices/write, Microsoft.Storage/storageAccounts/write T1222, T1567.002
Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
#Description
Returns a user delegation key for the blob service
Microsoft.Storage/storageAccounts/blobServices/getInfo/action
#Microsoft.Storage/storageAccounts/blobServices/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource.
Microsoft.Storage/storageAccounts/blobServices/write
#Description
Returns the result of put blob service properties
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 4 rules | panther |
resultType (panther rule field) | in | Success | 4 rules | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485T1485, T1490T1485, T1490
Microsoft.Storage/storageAccounts/connectors/delete
#Description
Delete a storage connector.
Microsoft.Storage/storageAccounts/connectors/testExistingConnection/action
#Description
Test the connection of an existing storage connector.
Microsoft.Storage/storageAccounts/connectors/write
#Description
Creates or updates a storage connector.
Microsoft.Storage/storageAccounts/delete
#Description
Deletes an existing storage account.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"action": "Microsoft.Storage/storageAccounts/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"action": "Microsoft.Storage/storageAccounts/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "fc1a2604-7b0a-493d-8552-f679c469fff7",
"EventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
"EventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"message": "Microsoft.Storage/storageAccounts/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
"eventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsa25394",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"message": "Microsoft.Storage/storageAccounts/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "29fa9414-6fc7-e092-2035-d8ee6a28cfe8",
"eventSubmissionTimestamp": "2026-06-29T18:11:31.2147942Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsa25394",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.STORAGE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:11:31.2147942Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.storage/storageaccounts/zcsa25394"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure.activitylogs.identity.claims_initiated_by_user.name (elastic rule field) | is_not_null | | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1489T1485, T1489Panther #
T1485, T1490
Microsoft.Storage/storageAccounts/encryptionScopes/hoboConfigurations/write
#Microsoft.Storage/storageAccounts/encryptionScopes/write
#Microsoft.Storage/storageAccounts/failover/action
#Description
Customer is able to control the failover in case of availability issues
Microsoft.Storage/storageAccounts/fileServices/generateUserDelegationKey/action
#Description
Returns a user delegation key for the file service
Microsoft.Storage/storageAccounts/fileServices/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource.
Microsoft.Storage/storageAccounts/fileServices/write
#Description
Put file service properties
Microsoft.Storage/storageAccounts/hnsonmigration/action
#Description
Customer is able to migrate to hns account type
Microsoft.Storage/storageAccounts/hoboConfigurations/write
#Microsoft.Storage/storageAccounts/inventoryPolicies/delete
#Microsoft.Storage/storageAccounts/inventoryPolicies/write
#Microsoft.Storage/storageAccounts/joinPerimeter/action
#Description
Access check for joining Network Security Perimeter
Microsoft.Storage/storageAccounts/listAccountSas/action
#Description
Returns the Account SAS token for the specified storage account.
Microsoft.Storage/storageAccounts/listkeys/action
#Description
Returns the access keys for the specified storage account.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"action": "Microsoft.Storage/storageAccounts/listKeys/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"action": "Microsoft.Storage/storageAccounts/listKeys/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "2815a35c-c303-4de7-8178-760ed598170e",
"EventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
"EventSubmissionTimestamp": "2026-07-03T02:17:04.173868Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/LISTKEYS/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"message": "Microsoft.Storage/storageAccounts/listKeys/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
"eventSubmissionTimestamp": "2026-07-03T02:17:04.173868Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsa",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"message": "Microsoft.Storage/storageAccounts/listKeys/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6689e3c5-b2cf-9da5-7956-47aa7098b287",
"eventSubmissionTimestamp": "2026-07-03T02:17:04.1738680Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsa",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.STORAGE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ActivityStatusValue (kusto rule field) | eq | success | 2 rules | kusto |
azure.activitylogs.identity.authorization.evidence.principal_type (elastic rule field) | eq | user | 1 rule | elastic |
count_ (kusto rule field) | ge | 5 | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1003Elastic #
T1078, T1078.004, T1555, T1555.006Kusto #
T1059↳ also matches Microsoft.Storage/storageAccounts/write Panther #
T1530, T1552
Microsoft.Storage/storageAccounts/listServiceSas/action
#Description
Returns the Service SAS token for the specified storage account.
Microsoft.Storage/storageAccounts/localUsers/delete
#Description
Delete local user
Microsoft.Storage/storageAccounts/localusers/listKeys/action
#Description
List local user keys
Microsoft.Storage/storageAccounts/localusers/regeneratePassword/action
#Microsoft.Storage/storageAccounts/localusers/write
#Description
Create or update local user
Microsoft.Storage/storageAccounts/managementPolicies/delete
#Description
Delete storage account management policies
Microsoft.Storage/storageAccounts/managementPolicies/write
#Description
Put storage account management policies
Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/delete
#Microsoft.Storage/storageAccounts/networkSecurityPerimeterAssociationProxies/write
#Microsoft.Storage/storageAccounts/networkSecurityPerimeterConfigurations/action
#Microsoft.Storage/storageAccounts/objectReplicationPolicies/delete
#Description
Delete object replication policy
Microsoft.Storage/storageAccounts/objectReplicationPolicies/restorePointMarkers/write
#Description
Create object replication restore point marker
Microsoft.Storage/storageAccounts/objectReplicationPolicies/write
#Description
Create or update object replication policy
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/delete
#Description
Delete Private Endpoint Connection Proxies
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/updatePrivateEndpointProperties/action
#Description
Update storage account private endpoint properties
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/validate/action
#Description
Validate Private Endpoint Connection Proxies
Microsoft.Storage/storageAccounts/privateEndpointConnectionProxies/write
#Description
Put Private Endpoint Connection Proxies
Microsoft.Storage/storageAccounts/privateEndpointConnections/delete
#Description
Delete Private Endpoint Connection
Microsoft.Storage/storageAccounts/privateEndpointConnections/write
#Description
Put Private Endpoint Connection
Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action
#Description
Approve Private Endpoint Connections
Microsoft.Storage/storageAccounts/privateEndpoints/move/action
#Microsoft.Storage/storageAccounts/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource.
Microsoft.Storage/storageAccounts/queueServices/generateUserDelegationKey/action
#Description
Returns a user delegation key for the queue service
Microsoft.Storage/storageAccounts/queueServices/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource.
Microsoft.Storage/storageAccounts/queueServices/queues/delete
#Description
Returns the result of deleting a queue
Microsoft.Storage/storageAccounts/queueServices/queues/getAcl/action
#Description
Returns the result of processing a message
Microsoft.Storage/storageAccounts/queueServices/queues/setAcl/action
#Description
Returns the result of processing a message
Microsoft.Storage/storageAccounts/queueServices/queues/write
#Description
Returns the result of writing a queue
Microsoft.Storage/storageAccounts/queueServices/write
#Description
Returns the result of setting queue service properties
Microsoft.Storage/storageAccounts/regeneratekey/action
#Description
Regenerates the access keys for the specified storage account.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"action": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"action": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "a54f8a7e-498e-42ec-ae7b-d9b8003d523a",
"EventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
"EventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/REGENERATEKEY/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"message": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
"eventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsa",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/dwhc6a93dsa",
"message": "Microsoft.Storage/storageAccounts/regenerateKey/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "b40d0c9a-e6ca-7a5a-d07c-af344bed0ea4",
"eventSubmissionTimestamp": "2026-07-03T02:17:05.5450383Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dsa",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.STORAGE",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.001, T1552, T1552.005Panther #
T1098
Microsoft.Storage/storageAccounts/restoreBlobRanges/action
#Description
Restore blob ranges to the state of the specified time
Microsoft.Storage/storageAccounts/restorePoints/delete
#Description
Delete object replication restore point
Microsoft.Storage/storageAccounts/revokeUserDelegationKeys/action
#Description
Revokes all the user delegation keys for the specified storage account.
Microsoft.Storage/storageAccounts/rotateKey/action
#Microsoft.Storage/storageAccounts/services/diagnosticSettings/write
#Description
Create/Update storage account diagnostic settings.
Microsoft.Storage/storageAccounts/storageTaskAssignments/delete
#Microsoft.Storage/storageAccounts/storageTaskAssignments/write
#Microsoft.Storage/storageAccounts/tableServices/generateUserDelegationKey/action
#Description
Returns a user delegation key for the table service
Microsoft.Storage/storageAccounts/tableServices/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Creates or updates the diagnostic setting for the resource.
Microsoft.Storage/storageAccounts/tableServices/tables/delete
#Description
Delete tables
Microsoft.Storage/storageAccounts/tableServices/tables/getAcl/action
#Description
Merge or update table entities
Microsoft.Storage/storageAccounts/tableServices/tables/setAcl/action
#Description
Merge or update table entities
Microsoft.Storage/storageAccounts/tableServices/tables/write
#Description
Create tables
Microsoft.Storage/storageAccounts/tableServices/write
#Description
Set table service properties
Microsoft.Storage/storageAccounts/updateAccountContainerHoldingPeriod/action
#Microsoft.Storage/storageAccounts/updateAutoRotateUserKeys/action
#Microsoft.Storage/storageAccounts/updateInternalProperties/action
#Microsoft.Storage/storageAccounts/write
#Description
Creates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"action": "Microsoft.Storage/storageAccounts/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"action": "Microsoft.Storage/storageAccounts/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "584251ce-eb35-46eb-acec-6721a6073546",
"EventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
"EventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.STORAGE/STORAGEACCOUNTS/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"message": "Microsoft.Storage/storageAccounts/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
"eventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsa25394",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Storage/storageAccounts/zcsa25394",
"message": "Microsoft.Storage/storageAccounts/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "876eed4f-7d11-8970-4fb1-4a7700dd1893",
"eventSubmissionTimestamp": "2026-06-29T17:50:17.1099996Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcsa25394",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.STORAGE",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.STORAGE",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:50:17.1099996Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.storage/storageaccounts/zcsa25394"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 4 rules | panther |
resultType (panther rule field) | in | Success | 4 rules | panther |
ActivityStatusValue (kusto rule field) | eq | success | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1530Kusto #
T1059↳ also matches Microsoft.Storage/storageAccounts/listkeys/action Panther #
T1098T1567T1071
Microsoft.Storage/storageTasks/delete
#Description
Deletes an existing storage task
Microsoft.Storage/storageTasks/promote/action
#Description
Promote specific version of storage task to current version
Microsoft.Storage/storageTasks/write
#Description
Creates or updates storage task
Microsoft.Storage/unregister/action
#Microsoft.Storage/contextCaches/contextCacheContainers/delete
#Description
Delete a container from a Context Cache resource.
Microsoft.Storage/contextCaches/contextCacheContainers/write
#Description
Create or update a container in a Context Cache resource.
Microsoft.Storage/contextCaches/delete
#Description
Delete a Context Cache resource.
Microsoft.Storage/contextCaches/write
#Description
Create or update a Context Cache resource.
Microsoft.Storage/locations/ContextCacheRPOperationStatuses/write
#Description
Writes the status of an asynchronous Context Cache operation.
Microsoft.Storage/storageAccounts/abortHnsOnMigration/action
#Description
Customer is able to abort an ongoing Hns migration on the storage account