AzureDetection & ResponseRetrospectives

Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.

Signals worth watching

  • Data plane requests from IP addresses outside your applications' known ranges.
  • Large or unusual query volumes, especially reads across many containers.
  • Key regeneration or key listing operations by unexpected identities.
  • Requests authenticated with keys after you've moved applications to Entra ID.
  • Defender for Azure Cosmos DB alerts (for example, access from suspicious IPs, potential SQL injection, unusual data extraction).

Where the data lives

  • Cosmos DB diagnostic logs (DataPlaneRequests, QueryRuntimeStatistics) sent to Log Analytics.
  • Azure Activity logs for control plane operations such as listKeys and regenerateKey.
  • Defender for Cloud alerts.

A starting query

Who listed keys for Cosmos DB accounts:

AzureActivity
| where OperationNameValue has "MICROSOFT.DOCUMENTDB/DATABASEACCOUNTS/LISTKEYS"
| project TimeGenerated, Caller, CallerIpAddress, ResourceGroup, _ResourceId, ActivityStatusValue

Listing keys is required for some deployments, but should come from known automation identities.

Response

  1. Regenerate affected keys immediately.
  2. Review data plane logs for the period of exposure.
  3. Restrict network access and move to Entra ID authentication.
detect cosmos db key misuseChaosDB2021

More on this story