Defender-CloudAppEvents
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Cloud app activity | Y | Y |
any: Cloud app activity
#Example Event #
{
"AccountDisplayName": "Admin User",
"AccountId": "11111111-1111-1111-1111-111111111111",
"AccountObjectId": "11111111-1111-1111-1111-111111111111",
"AccountType": "Admin",
"ActionType": "Add service principal.",
"ActivityObjects": [
{
"Type": "Application",
"Role": "Parameter",
"ServiceObjectType": "Azure Service Principal - Object ID"
},
{
"Type": "Application",
"Role": "Target object",
"Name": "dw-rt2-delegate"
},
{
"Type": "Application",
"Role": "Parameter",
"Id": "Other",
"ServiceObjectType": "Azure Service Principal - Application ID"
},
{
"Type": "Tenant",
"Role": "Parameter",
"Id": "00000000-0000-0000-0000-000000000001"
},
{
"Type": "User",
"Role": "Actor",
"Name": "Admin User",
"Id": "11111111-1111-1111-1111-111111111111",
"ApplicationId": 11161,
"ApplicationInstance": 0
}
],
"ActivityObjects@odata.type": "#Collection(String)",
"ActivityType": "Add",
"AdditionalFields": {
"@odata.type": "#microsoft.graph.security.dynamicColumnValue"
},
"AppInstanceId": 0,
"Application": "Microsoft 365",
"ApplicationId": 11161,
"AuditSource": "Defender for Cloud Apps app connector",
"DeviceType": "Other",
"IsAdminOperation": 0,
"IsAdminOperation@odata.type": "#SByte",
"IsExternalUser": 0,
"IsExternalUser@odata.type": "#SByte",
"IsImpersonated": 0,
"IsImpersonated@odata.type": "#SByte",
"LastSeenForUser": {
"@odata.type": "#microsoft.graph.security.dynamicColumnValue",
"ActionType": 0,
"ActionType@odata.type": "#Int64",
"Application": 0,
"Application@odata.type": "#Int64",
"OSPlatform": 0,
"OSPlatform@odata.type": "#Int64",
"UserAgent": 0,
"UserAgent@odata.type": "#Int64"
},
"OAuthAppId": "5165532d-c344-423b-973e-b4493d5450c5",
"OSPlatform": "Linux",
"ObjectName": "dw-rt2-delegate",
"ObjectType": "Application",
"RawEventData": {
"@odata.type": "#microsoft.graph.security.dynamicColumnValue",
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"Actor@odata.type": "#Collection(String)",
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"AzureActiveDirectoryEventType@odata.type": "#Int64",
"CreationTime": "2026-07-25T21:49:08.0000000Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)",
"AppId": "5165532d-c344-423b-973e-b4493d5450c5",
"AppOwnerOrganizationId": "00000000-0000-0000-0000-000000000001",
"ServicePrincipalProvisioningType": "Other"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ExtendedProperties@odata.type": "#Collection(String)",
"Id": "7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
"InterSystemsId": "d557c366-e388-4fdc-8160-62c183a4bba8",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "AccountEnabled",
"NewValue": [
true
],
"OldValue": []
},
{
"Name": "AppPrincipalId",
"NewValue": [
"5165532d-c344-423b-973e-b4493d5450c5"
],
"OldValue": []
},
{
"Name": "DisplayName",
"NewValue": [
"dw-rt2-delegate"
],
"OldValue": []
},
{
"Name": "ServicePrincipalName",
"NewValue": [
"5165532d-c344-423b-973e-b4493d5450c5"
],
"OldValue": []
},
{
"Name": "Credential",
"NewValue": [
{
"CredentialType": 2,
"KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
"KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
}
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "AccountEnabled, AppPrincipalId, DisplayName, ServicePrincipalName, Credential",
"OldValue": ""
}
],
"ModifiedProperties@odata.type": "#Collection(String)",
"ObjectId": "5165532d-c344-423b-973e-b4493d5450c5",
"Operation": "Add service principal.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"RecordType@odata.type": "#Int64",
"ResultStatus": "Success",
"SupportTicketId": "",
"Target": [
{
"ID": "ServicePrincipal_3ce33562-8f77-4735-afa3-eb60a90c3377",
"Type": 2
},
{
"ID": "3ce33562-8f77-4735-afa3-eb60a90c3377",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dw-rt2-delegate",
"Type": 1
},
{
"ID": "5165532d-c344-423b-973e-b4493d5450c5",
"Type": 2
},
{
"ID": "5165532d-c344-423b-973e-b4493d5450c5",
"Type": 4
},
{
"ID": "00000000-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "Other",
"Type": 2
}
],
"Target@odata.type": "#Collection(String)",
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"UserType@odata.type": "#Int64",
"Version": 1,
"Version@odata.type": "#Int64",
"Workload": "AzureActiveDirectory"
},
"ReportId": "75768946_11161_7943e2c0-acf1-4d0a-ab3f-ee682ed1d93e",
"Timestamp": "2026-07-25T21:49:08Z",
"UncommonForUser@odata.type": "#Collection(String)",
"UserAgent": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
Detection Patterns #
Exfiltration: Exfiltration Over Physical Medium
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Active (kusto rule field) | eq | true | 4 rules | kusto |
ValidUntil (kusto rule field) | is_null | | 4 rules | kusto |
CloudAppEvents_TimeGenerated (kusto rule field) | cross_field_compare | ExpirationDateTime | 3 rules | kusto |
CloudAppEvents_TimeGenerated (kusto rule field) | cross_field_compare | ValidUntil | 3 rules | kusto |
ActionType (kusto rule field) | eq | UsbDriveMounted | 1 rule | kusto |
ActionType (kusto rule field) | in | ExecuteToolByGateway | 2 rules | kusto |
ActionType (kusto rule field) | in | ExecuteToolByMCPServer | 2 rules | kusto |
ActionType (kusto rule field) | in | ExecuteToolBySDK | 2 rules | kusto |
ActionType (kusto rule field) | in | InferenceCall | 2 rules | kusto |
ActionType (kusto rule field) | in | InvokeAgent | 2 rules | kusto |
ActionType (kusto rule field) | in | FileCreated | 1 rule | kusto |
Image (kusto rule field) | is_not_null | | 2 rules | kusto |
User_Id (kusto rule field) | is_not_null | | 2 rules | kusto |
User_Id (kusto rule field) | regex_match | ^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$ | 2 rules | kusto |
AccountObjectId (kusto rule field) | is_not_null | | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1485T1071T1566