Skip to content

Microsoft.Compute/virtualMachines/extensions/write

Azure

Microsoft.Compute/virtualMachines/extensions/write

service: Azure - Compute
tactics:
techniques:

Event

Installs or configures a VM extension. Behavior depends on its publisher, type, settings, and guest-agent state. Custom Script can download files and execute a supplied command or script; fileUris alone does not establish which command ran. It normally runs once for a configuration, not automatically on every boot.

Security Context

Unauthorized script-capable extension use can support cloud administration command execution (T1651). Routine agent deployment uses the same operation. An extension write does not by itself establish a reverse shell, persistence, or successful guest execution.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/virtualMachines/extensions/write. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the publisher, handler type/version, and complete settings through authorized evidence collection; protect sensitive settings.
  3. Compare guest-agent and extension instance-view results with guest process, file, and network telemetry.
  4. Inspect actual script content without executing it, and verify any persistent changes separately.

Sample Event

Synthetic scenario. The sample shows a CustomScript configuration with a download URI. Sensitive settings are omitted; this is a partial logging illustration, not a complete deployment request. No command or guest result is shown.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Compute/virtualMachines/extensions/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001/extensions/installerCustomScript"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010101100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010101101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T22:18:08.4172395Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010101110",
"operationName": {
"value": "Microsoft.Compute/virtualMachines/extensions/write",
"localizedValue": "Create or update virtual machine extension"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Compute",
"localizedValue": "Microsoft.Compute"
},
"resourceType": {
"value": "Microsoft.Compute/virtualMachines/extensions",
"localizedValue": "Microsoft.Compute/virtualMachines/extensions"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001/extensions/installerCustomScript",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T22:18:09.0184277Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"requestbody": "{\"location\":\"eastus\",\"properties\":{\"publisher\":\"Microsoft.Azure.Extensions\",\"type\":\"CustomScript\",\"typeHandlerVersion\":\"2.1\",\"autoUpgradeMinorVersion\":true,\"settings\":{\"fileUris\":[\"https://scripts.example/install.sh\"]}}}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001/extensions/installerCustomScript",
"message": "Microsoft.Compute/virtualMachines/extensions/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010101111",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001/extensions/installerCustomScript?api-version=2024-03-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.