AzureDetection & ResponseRetrospectives

Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2020, written in 2026 with the benefit of hindsight.

Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.

Signals worth watching

  • New NSG rules allowing inbound traffic from Internet, * or 0.0.0.0/0.
  • PaaS data services with public network access switched on.
  • Firewall rules on Azure SQL or storage allowing all IP addresses.
  • Data access from unfamiliar public IPs.
  • Defender for Cloud alerts for anomalous data access or access from suspicious IPs.

Where the data lives

  • Azure Activity logs: write operations on NSGs, SQL firewall rules and network settings.
  • Defender for Cloud: recommendations and alerts (Defender for Storage, Defender for SQL, Defender for Cosmos DB).
  • Resource diagnostic logs for data access.

A starting query

Find NSG rule changes in Azure Activity logs:

AzureActivity
| where OperationNameValue =~ "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/SECURITYRULES/WRITE"
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, ResourceGroup, _ResourceId, Properties

Parse the Properties field (or use Azure Resource Graph change analysis) to find rules with a source of Internet or *.

Response

  1. Revert the rule or disable public access.
  2. Check access logs for the exposure window.
  3. Identify who made the change and why.
  4. Add a preventive Azure Policy so the same change is blocked in future.
detect exposed cloud databaseMicrosoft support database2020

More on this story