Repeated failed Azure SQL database deletions via bad API version
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
Microsoft Sentinel (KQL)

