Skip to main content

Suspicious Azure API calls indicating PostgreSQL security configuration change

ID:azure_postgresql_security_config_changed_suspicious
Data type:Azure Activity
Severity:
Low
-
Medium
MITRE ATT&CK:TA0005:T1562

Description​

AlphaSOC detected changes to Azure PostgreSQL Flexible Server security configuration via Microsoft.DBforPostgreSQL/flexibleServers/configurations/write. This detection monitors changes to the connection_throttle.enable setting, which helps protect against brute force attacks.

Disabling connection throttling removes protection against password spraying and brute force authentication attacks.

Impact​

Disabling connection throttling allows for brute force attacks against database user accounts. This can lead to credential compromise and unauthorized data access, particularly for accounts with weak passwords.

Severity​

SeverityCondition
Low
Unexpected action or ASN
Medium
Two unexpected properties at the same time

Investigation and Remediation​

Review Azure Activity logs to identify who modified the security configuration. Check PostgreSQL authentication logs for signs of brute force attempts following the configuration change.

If unauthorized, immediately re-enable connection throttling. Investigate whether any authentication attacks occurred during the vulnerability window and reset passwords for potentially compromised accounts. Review the principal's other activities and rotate their credentials.