Name:Microsoft Intune Mobile Apps id:98e6b389-2806-4426-a580-8a92cb0d9710 version:5 date:None author:Dean Luxton status:experimental type:Hunting Description:Microsoft Intune supports deploying packaged applications to support software deployment, this functionality can also be abused for deploying malicious payloads to intune managed devices.
This detection identifies when a new packaged application has been added, updated or deleted.
Data_source:
-Azure Monitor Activity
search:`azure_monitor_activity` operationName="*MobileApp*" | rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin | rex field="operationName" "^(?P<action>\w+)\s" | replace "Patch" with "updated", "Create" with "created", "Delete", with "deleted", "assign", with "assigned" IN action | table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId status tenantId correlationId | `microsoft_intune_mobile_apps_filter`