Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL
Retrospective: this article looks back at events from January 2020, written in 2026 with the benefit of hindsight.
Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.
Signals worth watching
- New NSG rules allowing inbound traffic from
Internet,*or0.0.0.0/0. - PaaS data services with public network access switched on.
- Firewall rules on Azure SQL or storage allowing all IP addresses.
- Data access from unfamiliar public IPs.
- Defender for Cloud alerts for anomalous data access or access from suspicious IPs.
Where the data lives
- Azure Activity logs: write operations on NSGs, SQL firewall rules and network settings.
- Defender for Cloud: recommendations and alerts (Defender for Storage, Defender for SQL, Defender for Cosmos DB).
- Resource diagnostic logs for data access.
A starting query
Find NSG rule changes in Azure Activity logs:
AzureActivity
| where OperationNameValue =~ "MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/SECURITYRULES/WRITE"
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, ResourceGroup, _ResourceId, Properties
Parse the Properties field (or use Azure Resource Graph change analysis) to find rules with a source of Internet or *.
Response
- Revert the rule or disable public access.
- Check access logs for the exposure window.
- Identify who made the change and why.
- Add a preventive Azure Policy so the same change is blocked in future.