Skip to content

Commit a164633

Browse files
Update release-notes.md
Move new alert to April 2023
1 parent 0bb23a6 commit a164633

File tree

1 file changed

+11
-12
lines changed

1 file changed

+11
-12
lines changed

articles/defender-for-cloud/release-notes.md

Lines changed: 11 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,20 @@ To learn about *planned* changes that are coming soon to Defender for Cloud, see
1919
## April 2023
2020

2121
Updates in April include:
22-
22+
- [New alert in Defender for Resource Manager](#new-alert-in-defender-for-resource-manager)
2323
- [New preview Unified Disk Encryption recommendation](#unified-disk-encryption-recommendation-preview)
2424
- [Changes in the recommendation "Machines should be configured securely"](#changes-in-the-recommendation-machines-should-be-configured-securely)
2525

26+
### New alert in Defender for Resource Manager
27+
28+
Defender for Resource Manager has the following new alert:
29+
30+
| Alert (alert type) | Description | MITRE tactics | Severity |
31+
|---|---|:-:|---|
32+
| **PREVIEW - Suspicious creation of compute resources detected**<br>(ARM_SuspiciousComputeCreation) | Microsoft Defender for Resource Manager identified a suspicious creation of compute resources in your subscription utilizing Virtual Machines/Azure Scale Set. The identified operations are designed to allow administrators to efficiently manage their environments by deploying new resources when needed. While this activity may be legitimate, a threat actor might utilize such operations to conduct crypto mining.<br> The activity is deemed suspicious as the compute resources scale is higher than previously observed in the subscription. <br> This can indicate that the principal is compromised and is being used with malicious intent. | Impact | Medium |
33+
34+
You can see a list of all of the [alerts available for Resource Manager](alerts-reference.md#alerts-resourcemanager).
35+
2636
### Unified Disk Encryption recommendation (preview)
2737

2838
We have introduced a unified disk encryption recommendation in public preview, `Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost` and `Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost`.
@@ -50,7 +60,6 @@ No action is required on the customer side, and there's no expected impact on th
5060

5161
Updates in March include:
5262

53-
- [New alert in Defender for Resource Manager](#new-alert-in-defender-for-resource-manager)
5463
- [A new Defender for Storage plan is available, including near-real time malware scanning and sensitive data threat detection](#a-new-defender-for-storage-plan-is-available-including-near-real-time-malware-scanning-and-sensitive-data-threat-detection)
5564
- [Data-aware security posture (preview)](#data-aware-security-posture-preview)
5665
- [Improved experience for managing the default Azure security policies](#improved-experience-for-managing-the-default-azure-security-policies)
@@ -61,16 +70,6 @@ Updates in March include:
6170
- [New preview recommendation for Azure SQL Servers](#new-preview-recommendation-for-azure-sql-servers)
6271
- [New alert in Defender for Key Vault](#new-alert-in-defender-for-key-vault)
6372

64-
### New alert in Defender for Resource Manager
65-
66-
Defender for Resource Manager has the following new alert:
67-
68-
| Alert (alert type) | Description | MITRE tactics | Severity |
69-
|---|---|:-:|---|
70-
| **PREVIEW - Suspicious creation of compute resources detected**<br>(ARM_SuspiciousComputeCreation) | Microsoft Defender for Resource Manager identified a suspicious creation of compute resources in your subscription utilizing Virtual Machines/Azure Scale Set. The identified operations are designed to allow administrators to efficiently manage their environments by deploying new resources when needed. While this activity may be legitimate, a threat actor might utilize such operations to conduct crypto mining.<br> The activity is deemed suspicious as the compute resources scale is higher than previously observed in the subscription. <br> This can indicate that the principal is compromised and is being used with malicious intent. | Impact | Medium |
71-
72-
You can see a list of all of the [alerts available for Resource Manager](alerts-reference.md#alerts-resourcemanager).
73-
7473
### A new Defender for Storage plan is available, including near-real time malware scanning and sensitive data threat detection
7574

7675
Cloud storage plays a key role in the organization and stores large volumes of valuable and sensitive data. Today we are announcing a new Defender for Storage plan. If you’re using the previous plan (now renamed to "Defender for Storage (classic)"), you will need to proactively [migrate to the new plan](defender-for-storage-classic-migrate.md) in order to use the new features and benefits.

0 commit comments

Comments
 (0)