Forum Discussion

Steph32UK's avatar
Steph32UK
Copper Contributor
Oct 31, 2022

Azure Sign-in Logs

Hi,

I've been tracking some activity which I think is somewhat malicious. Within sign-in logs I've noticed quite a few failures from user accounts under application "Microsoft Azure CLI". Over the last month there has been an ever-increasing amount of this traffic from users that would have no reason (or business) to be signing into this application. 99% of attempts are failures and I am wondering if there is some other process, unbeknown to the user that could cause this error?

 

I am happy to share the excerpt below as an example as we definitely don't have staff in Russia! Or any of the other strange countries appearing for location.

 
Microsoft Azure CLI
Failure
91.243.188.240
Moskva, Moskva, RU

 

I am the Cyber Analyst for my organisation but relatively new to the field with only a newly qualified Apprentice and TL with equal knowledge in Cyber as myself.

Thanks,

Stephen

6 Replies

Resources