Microsoft Defender for Cloud PoC Series – Microsoft Defender for Resource Manager

Published Jul 12 2021 01:09 PM 4,130 Views
Microsoft

Introduction

This Microsoft Defender for Cloud PoC Series provides guidelines on how to perform a proof of concept for a specific Defender for Cloud plan. For a more holistic approach where you need to validate Microsoft Defender for Cloud please read How to Effectively Perform a Microsoft Defender for Cloud PoC article.

 

Planning

As part of your Microsoft Defender for Resource Manager PoC you need to identify the use case scenarios that you want to validate. A common scenario is cloud service discovery, where an adversary may try to enumerate the cloud services that are running via calls to Azure Resource Manager. You can use the Alerts identified by Microsoft Defender for Resource Manager as your starting point to plan which actions you want to execute.

 

Since the enablement of this plan is performed on the Azure back end, it will not affect the performance of your workloads in Azure.

Keep in mind that you have 30 days free trial of Microsoft Defender for Resource Manager, which means that you should plan to execute your PoC prior to this expiration and based on the results keep it enabled or not.

 

enablearm.png

 

Preparation

You need at least Security Admin role to enable Microsoft Defender for Resource Manager. For more information about roles and privileges, visit this article. If you are conducting this PoC in partnership with the SOC Team, make sure they are familiar with the alerts that may appear once you enable this plan. Review all alerts available at our Alerts Reference Guide.

 

From the readiness perspective, make sure to review the following resources to better understand Microsoft Defender for Resource Manager:

 

Implementation and validation

You can use the sample alert feature to validate Microsoft Defender for Resource Manager alerts, or you can use the procedures from this article to simulate an attack and see how Microsoft Defender for Resource Manager detects. As you review each alert is important to understand how to make sense of the metadata available. Read this article for more information on how to respond to ARM alerts.

 

Conclusion

By the end of this PoC you should be able to determine the value of this solution and the importance to have this level of threat detection to your workloads.

 

P.S. Subscribe to our Microsoft Defender for Cloud to stay up to date on helpful tips and new releases and join our Tech Community where you can be one of the first to hear the latest Microsoft Defender for Cloud news, announcements and get your questions answered by Azure Security experts.

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-2542303%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Defender%20PoC%20Series%20%E2%80%93%20Azure%20Defender%20for%20Resource%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2542303%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F124214%22%20target%3D%22_blank%22%3E%40Yuri%20Diogenes%3C%2FA%3E%26nbsp%3Bfor%20Sharing%20with%20the%20Community%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fhtml%2F%40B71AFCCE02F5853FE57A20BD4B04EADD%2Fimages%2Femoticons%2Fcool_40x40.gif%22%20alt%3D%22%3Acool%3A%22%20title%3D%22%3Acool%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2539915%22%20slang%3D%22en-US%22%3EMicrosoft%20Defender%20for%20Cloud%20PoC%20Series%20%E2%80%93%20Microsoft%20Defender%20for%20Resource%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2539915%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EIntroduction%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EThis%20Microsoft%20Defender%20for%20Cloud%20PoC%20Series%20provides%20guidelines%20on%20how%20to%20perform%20a%20proof%20of%20concept%20for%20a%20specific%20Defender%20for%20Cloud%20plan.%20For%20a%20more%20holistic%20approach%20where%20you%20need%20to%20validate%26nbsp%3BMicrosoft%20Defender%20for%20Cloud%20please%20read%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fhow-to-effectively-perform-an-azure-security-center-poc%2Fba-p%2F516874%22%20target%3D%22_blank%22%3EHow%20to%20Effectively%20Perform%20a%20Microsoft%20Defender%20for%20Cloud%20PoC%3C%2FA%3E%20article.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPlanning%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EAs%20part%20of%20your%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-resource-manager-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Defender%20for%20Resource%20Manager%3C%2FA%3E%20PoC%20you%20need%20to%20identify%20the%20use%20case%20scenarios%20that%20you%20want%20to%20validate.%20A%20common%20scenario%20is%20%3CA%20href%3D%22https%3A%2F%2Fattack.mitre.org%2Ftechniques%2FT1526%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ecloud%20service%20discovery%3C%2FA%3E%2C%20where%20an%20adversary%20may%20try%20to%20enumerate%20the%20cloud%20services%20that%20are%20running%20via%20calls%20to%20Azure%20Resource%20Manager.%20You%20can%20use%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-reference%23alerts-resourcemanager%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlerts%3C%2FA%3E%20identified%20by%20Microsoft%20Defender%20for%20Resource%20Manager%20as%20your%20starting%20point%20to%20plan%20which%20actions%20you%20want%20to%20execute.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESince%20the%20enablement%20of%20this%20plan%20is%20performed%20on%20the%20Azure%20back%20end%2C%20it%20will%20not%20affect%20the%20performance%20of%20your%20workloads%20in%20Azure.%3C%2FP%3E%0A%3CP%3EKeep%20in%20mind%20that%20you%20have%2030%20days%20free%20trial%20of%20Microsoft%20Defender%20for%20Resource%20Manager%2C%20which%20means%20that%20you%20should%20plan%20to%20execute%20your%20PoC%20prior%20to%20this%20expiration%20and%20based%20on%20the%20results%20keep%20it%20enabled%20or%20not.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22enablearm.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F323316i7742A95DF3005173%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22enablearm.png%22%20alt%3D%22enablearm.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPreparation%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EYou%20need%20at%20least%20Security%20Admin%20role%20to%20enable%20Microsoft%20Defender%20for%20Resource%20Manager.%20For%20more%20information%20about%20roles%20and%20privileges%2C%20visit%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-permissions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E.%20If%20you%20are%20conducting%20this%20PoC%20in%20partnership%20with%20the%20SOC%20Team%2C%20make%20sure%20they%20are%20familiar%20with%20the%20alerts%20that%20may%20appear%20once%20you%20enable%20this%20plan.%20Review%20all%20alerts%20available%20at%20our%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-reference%23alerts-resourcemanager%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlerts%20Reference%20Guide%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20the%20readiness%20perspective%2C%20make%20sure%20to%20review%20the%20following%20resources%20to%20better%20understand%20Microsoft%20Defender%20for%20Resource%20Manager%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FYVlW9udoYB0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Defender%20for%20ARM%20and%20DNS%20%7C%20Microsoft%20Defender%20for%20Cloud%20in%20the%20Field%20%2313%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-resource-manager-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Defender%20for%20Resource%20Manager%20Documentation%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EImplementation%20and%20validation%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EYou%20can%20use%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-alert-validation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Esample%20alert%3C%2FA%3E%20feature%20to%20validate%20Microsoft%20Defender%20for%20Resource%20Manager%20alerts%2C%20or%20you%20can%20use%20the%20procedures%20from%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fvalidating-azure-defender-for-resource-manager-alerts%2Fba-p%2F2227469%22%20target%3D%22_blank%22%3Ethis%20article%3C%2FA%3E%20to%20simulate%20an%20attack%20and%20see%20how%20Microsoft%20Defender%20for%20Resource%20Manager%20detects.%20As%20you%20review%20each%20alert%20is%20important%20to%20understand%20how%20to%20make%20sense%20of%20the%20metadata%20available.%20Read%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-resource-manager-usage%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E%20for%20more%20information%20on%20how%20to%20respond%20to%20ARM%20alerts.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EConclusion%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EBy%20the%20end%20of%20this%20PoC%20you%20should%20be%20able%20to%20determine%20the%20value%20of%20this%20solution%20and%20the%20importance%20to%20have%20this%20level%20of%20threat%20detection%20to%20your%20workloads.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EP.S.%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FASCNewsSubscribe%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ESubscribe%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eto%20our%26nbsp%3BMicrosoft%20Defender%20for%20Cloud%20to%20stay%20up%20to%20date%20on%20helpful%20tips%20and%20new%20releases%20and%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FASCTechCommunity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ejoin%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eour%26nbsp%3BTech%20Community%26nbsp%3Bwhere%20you%20can%20be%20one%20of%20the%20first%20to%20hear%20the%20latest%20Microsoft%20Defender%20for%20Cloud%20news%2C%20announcements%20and%20get%20your%20questions%20answered%20by%20Azure%20Security%20experts.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2539915%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22new_teaser.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F323315i96DFBB124613C0B2%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22new_teaser.png%22%20alt%3D%22new_teaser.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Co-Authors
Version history
Last update:
‎Nov 02 2021 10:15 AM
Updated by:
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE