Skip to content

Microsoft.ContainerRegistry/registries/listCredentials/action

Azure

Microsoft.ContainerRegistry/registries/listCredentials/action

service: Azure - Container Registry
techniques:

Event

The registry admin account must be enabled. Its username and two independently renewable passwords provide shared registry push/pull access. ARM permission to retrieve credentials and subsequent registry authentication are separate; network restrictions still apply.

Security Context

Unauthorized credential retrieval can support T1552. Approved provisioning also uses this operation. A successful request does not prove image download, modification, or deployment to an AKS workload.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerRegistry/registries/listCredentials/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationInitiating identity and recorded authorization context; corroborate effective permissions.
resourceId, correlationIdTarget and related operation records.
status, subStatusOutcome and asynchronous acceptance versus completion.
properties.requestbody, httpRequestConfiguration or command and endpoint when present; these fields are not guaranteed.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Check adminUserEnabled, caller authorization, and the approved need for shared credentials.
  3. Inspect registry network restrictions and password rotation history; handle any returned passwords as secrets.
  4. Correlate actual registry push/pull and deployment evidence before claiming workload compromise.

Sample Event

Synthetic scenario. The sample records successful credential retrieval. Returned passwords and downstream registry activity are absent.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.ContainerRegistry/registries/listCredentials/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010111000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010111001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T22:42:18.7172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010111010",
"operationName": {
"value": "Microsoft.ContainerRegistry/registries/listCredentials/action",
"localizedValue": "List Container Registry credentials"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.ContainerRegistry",
"localizedValue": "Microsoft Container Registry"
},
"resourceType": {
"value": "Microsoft.ContainerRegistry/registries",
"localizedValue": "Microsoft.ContainerRegistry/registries"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T22:42:19.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy",
"message": "Microsoft.ContainerRegistry/registries/listCredentials/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010111011",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy/listCredentials?api-version=2023-11-01-preview"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.