Alerts Azure Storage
In brief
Seven Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants.
What Defender admins need to know
Administrators should use the updated severity labels when reviewing and prioritizing these documented alerts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
MITRE tactics: Initial Access
Severity: High/LowInformational
Potential malware uploaded to a storage account
MITRE tactics: Discovery
Severity: Medium/LowInformational
Unusual amount of data extracted from a storage account
MITRE tactics: Execution
Severity: Medium/LowInformational
Unusual deletion in a storage account
MITRE tactics: Exfiltration
Severity: Medium/LowInformational
Unusual unauthenticated public access to a sensitive blob container
MITRE tactics: Exfiltration / Resource Development / Impact
Severity: MediumInformational
Suspicious external operation to an Azure storage account with overly permissive SAS token
MITRE tactics: Exfiltration / Resource Development / Impact
Severity: MediumInformational
Unusual SAS token was used to access an Azure storage account from a public IP address
MITRE tactics: Exfiltration / Resource Development / Impact
Severity: LowInformational
Malicious blob uploaded to storage account
@@ -117,7 +117,7 @@ Storage.Files_GeoAnomaly) **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Initial Access -**Severity**: High/Low+**Severity**: Informational ### **Potential malware uploaded to a storage account** @@ -183,7 +183,7 @@ Storage.Files_AccessInspectionAnomaly) **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Discovery -**Severity**: Medium/Low+**Severity**: Informational ### **Unusual amount of data extracted from a storage account** @@ -224,7 +224,7 @@ Storage.Files_DataExplorationAnomaly) **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Execution -**Severity**: Medium/Low+**Severity**: Informational ### **Unusual deletion in a storage account** @@ -237,7 +237,7 @@ Storage.Files_DeletionAnomaly) **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Exfiltration -**Severity**: Medium/Low+**Severity**: Informational ### **Unusual unauthenticated public access to a sensitive blob container** @@ -350,7 +350,7 @@ Even if the access is legitimate, using a high-permission SAS token with a long **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Exfiltration / Resource Development / Impact -**Severity**: Medium+**Severity**: Informational ### **Suspicious external operation to an Azure storage account with overly permissive SAS token** @@ -366,7 +366,7 @@ Even if the access is legitimate, using a high-permission SAS token with a long **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Exfiltration / Resource Development / Impact -**Severity**: Medium+**Severity**: Informational ### **Unusual SAS token was used to access an Azure storage account from a public IP address** @@ -381,7 +381,7 @@ It's possible that a SAS token was leaked or generated by a malicious actor eith **[MITRE tactics](alerts-reference.md#mitre-attck-tactics)**: Exfiltration / Resource Development / Impact -**Severity**: Low+**Severity**: Informational ### **Malicious blob uploaded to storage account** 