Account/Subscription compromised not able to know how to track the criminel

Salam ELIAS 237 Reputation points
2025-10-24T07:57:00.2233333+00:00

Recently, I discovered that one of the accounts (not sure which one, I have either SP or managed IDs as well as my main user which is the global admin in MFA state).

Somebody succeeded to create so many Vms, Vnetworks.....which I deleted which costed me the whole cost for the subscription for the october month. As spending limit was reached. the criminel was not able to create new resources until yesterday, he started back again when my subscription was renabled.

I craeted an alert to be notified whenever new resources are created on subscription level. I receive the alerts but a lot of details in the alert but we dont see which resource was created nor who created it.

So the main question is how can or track who is doing this

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.