HomeSecurityHow Microsoft Azure Storage Logs help with breach investigation...

How Microsoft Azure Storage Logs help with security breach investigation

After a security breach, forensic investigators work quickly to track down the attacker. Security experts have analyzed this situation and found that a key source of evidence is often overlooked: Microsoft Azure Storage logs.

See also: Critical flaws in Azure and Power allow privilege escalation

Microsoft Azure Storage

Although often overlooked, these logs provide invaluable information that can help reconstruct an attack, detect data theft, and identify security gaps. Azure Storage Accounts, which can contain vast amounts of sensitive data, are a prime target for malicious actors seeking to extract information.

However, the diagnostic logging that records their malicious activity is not always enabled by default, creating a significant blind spot for incident response teams. Without these logs, critical evidence of how attackers gained access and stole data could be lost forever.

Malicious actors exploit various vulnerabilities to gain unauthorized access, including misconfigured security settings, weak access controls, and credential leaks. Two common methods include the misuse of Shared Access Signature (SAS) tokens, which grant specific permissions for a limited time, and the exposure of Storage Account keys, which provide privileged, long-term access to data.

Once logging is properly enabled, researchers can turn to the StorageBlobLogs table within Microsoft Azure Storage Log Analytics. These logs capture key details about every read, write, and delete operation on the stored data.

See also: Vulnerability in Azure Active Directory Exposes Credentials

How Microsoft Azure Storage Logs help with security breach investigation
How Microsoft Azure Storage Logs help with security breach investigation

The key fields provide a digital trail of the attacker's actions:

– OperationName: Identifies the specific operation performed, such as “GetBlob” (download file), “PutBlob” (upload file), or “DeleteBlob.”
– CallerIpAddress: Reveals the IP address of the requester, helping to identify the origin of the malicious activity.
– UserAgentHeader: Provides clues about the tools used to access the data, distinguishing between access from a web browser, the Azure portal, or specialized tools such as AzCopy or Azure Storage Explorer.
– AuthenticationType: Indicates how the user was authenticated, whether through standard credentials (OAuth), a SAS token , or an Account Key.

By analyzing these fields, researchers can distinguish between legitimate user activity and the actions of a malicious actor. For example, a sudden increase in “ListContainers” or “ListBlobs” operations from an unknown IP address could indicate that an attacker is mapping the storage environment. Similarly, monitoring “GetBlob” operations can confirm data extraction and pinpoint which files were compromised.

Investigations often begin by correlating suspicious connections from Microsoft Entra ID with activity in storage logs. In one scenario, a compromised user account with administrative privileges could be used to grant another malicious account access roles such as “Storage Blob Data Contributor.” AzureActivity logs would show this role assignment, while StorageBlobLogs logs would then reveal the new account hacking and downloading sensitive files.

By correlating the authentication hash of a SAS token, researchers can track every action performed with that token, even if the attacker changes IP addresses. This helps determine the full scope of the breach.

See also: Cloudflare: Lost 55% of logs for 3.5 hours

How Microsoft Azure Storage Logs help with security breach investigation
How Microsoft Azure Storage Logs help with security breach investigation

Dreymann and Shiva P ’s analysis highlights a critical message for organizations using Azure: enabling storage account logging is not just an option but a necessity. These Microsoft Azure Storage logs are essential for forensic analysis after a breach, allowing teams to understand the scope of the incident, guide remediation efforts, and implement stronger controls to prevent future data theft.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS