Skip to content

Microsoft.Compute/virtualMachines/runCommand/action

Azure

Microsoft.Compute/virtualMachines/runCommand/action

service: Azure - Compute
tactics:
techniques:

Event

Action Run Command invokes a script through the Azure VM agent. Linux scripts run as root; Windows scripts run as SYSTEM. Direct inbound SSH/RDP is unnecessary, but a functioning agent, required outbound connectivity, and management-plane authorization are still needed. Managed Run Command uses a separate runCommands resource workflow.

Security Context

Unauthorized commands can support T1651 and T1059. Legitimate troubleshooting uses the same facility. A requested authorized_keys change is not proof that the file changed or an SSH login occurred.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Compute/virtualMachines/runCommand/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify caller authorization and approved command content; treat script strings as evidence, not commands to execute.
  3. Correlate Run Command output, exit status, agent health, and guest filesystem/process evidence.
  4. For key installation attempts, check actual authorized_keys changes and SSH authentication separately.

Sample Event

Synthetic scenario. The inert script text requests installation of an illustrative RSA public key under root. Its private key was discarded when the example key was generated. This review did not execute the script or change any VM.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Compute/virtualMachines/runCommand/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010110000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010110001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T22:24:18.5172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010110010",
"operationName": {
"value": "Microsoft.Compute/virtualMachines/runCommand/action",
"localizedValue": "Run Command on Virtual Machine"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Compute",
"localizedValue": "Microsoft.Compute"
},
"resourceType": {
"value": "Microsoft.Compute/virtualMachines",
"localizedValue": "Microsoft.Compute/virtualMachines"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T22:24:19.0148229Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"requestbody": "{\"commandId\":\"RunShellScript\",\"script\":[\"mkdir -p /root/.ssh && echo 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCSFAOzPrWNzzx1t+oKZz+tec7iBOVi7G8Qqt0pR7IgPqkM+d/ZoTjNQNveR6ZBbXkECM0a/hmYp31MsoILkko0HXPunBEvi6mvjwbC0fSIOY1meuDuckdVUgfvoyyJSKbRh3gQKNuYlD6rDOsedot7u3zXD0wUgnFrL7kBSoOmc7s4EV0FNC8dyoaQd0fLXbyKguQLYFx9ddrd5QwQccCV4TnSaXIwvgCYYFCi5RLDJjN/nlB8aJkI2HJIbSbcE1MbvqO6ffnjnF/gVzbI/vA5LlLNvdsdYd3Z0Wbs/GiIVoP4P7oTeg1e9Sgo5Qo+xRD3KM1iyQjAn83U6bGPp+UX synthetic-review-example' >> /root/.ssh/authorized_keys && chmod 600 /root/.ssh/authorized_keys\"]}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001",
"message": "Microsoft.Compute/virtualMachines/runCommand/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010110011",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-occamy-ingest-001/runCommand?api-version=2024-03-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
  • T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.