AzureDetection & ResponseRetrospectives

Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2021, written in 2026 with the benefit of hindsight.

Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.

Signals worth watching

  • Inbound connections to agent management ports (5985, 5986, 1270 for OMI) from the internet.
  • Agent processes (for example, omiengine or omiagent on Linux) spawning shells or downloading files.
  • New Custom Script, Run Command or VMAccess extensions deployed by unexpected identities.
  • Defender for Servers alerts for suspicious extension use.

Where the data lives

  • Defender for Endpoint / Defender for Servers process events on Linux and Windows VMs.
  • Azure Activity logs for extension write operations and Run Command.
  • NSG flow logs for inbound management port traffic.

A starting query

Extension and Run Command operations in Azure Activity:

AzureActivity
| where OperationNameValue has_any ("MICROSOFT.COMPUTE/VIRTUALMACHINES/EXTENSIONS/WRITE",
    "MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION")
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, CallerIpAddress, _ResourceId, OperationNameValue

Run Command and Custom Script extensions are legitimate admin tools — and attacker favorites. Compare callers against known automation identities.

Response

  1. Investigate unexpected extension deployments or Run Command executions.
  2. Check what the script executed.
  3. Remove unauthorized extensions and review the caller's other activity.
  4. Patch vulnerable agents and close exposed ports.
detect vm agent exploitationOMIGOD2021

More on this story