/
Activity log
Activity log
This diagnostic setting will not appear in the diagnostic settings list in Azure Monitor.
Secure it
//A malicious user has stopped a virtual machine in Azure
from cloud.azure.vm.administrative
where operationName = "MICROSOFT.COMPUTE/VIRTUALMACHINES/DEALLOCATE/ACTION"
In this case, the malicious user has gained control of a user account with the Owner role.
, multiple selections available,
Related content
Azure Monitor
Azure Monitor
More like this
Azure
Azure
More like this
Azure Monitor
Azure Monitor
More like this
Alert Pack: Execution (MITRE Att&ck Tactic: TA0002)
Alert Pack: Execution (MITRE Att&ck Tactic: TA0002)
More like this
Virtual Machine Metrics in Azure collector
Virtual Machine Metrics in Azure collector
More like this
Azure Event Hub collector
Azure Event Hub collector
More like this