May 21, 2023, 9:48 a.m. | /u/elnano005

cybersecurity www.reddit.com

Hi everyone,
I am noticing lately on Azure sign in logs there are multiple bruteforce attempts from malicious IP on 'high risk' users on 'Microsoft Azure CLI' application with failure reason 'Sign-in was blocked due to real-time detection rule(s): TI\_RT\_0015' (error code 500532).
Below the error:
\*\*\*\*\*\*\*\*\*\*\*\*\*
Status: Failure
Continuous access evaluation: No
Sign-in error code: 500532
Failure reason: Sign-in was blocked due to real-time detection rule(s): TI\_RT\_0015
Application: Microsoft Azure CLI
\*\*\*\*\*\*\*\*\*\*\*\*\*
I searched on sign-in logs on Sentinel …

application azure blocked bruteforce cli code cybersecurity detection error high logs malicious microsoft microsoft azure risk sign

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC