Microsoft.ContainerRegistry/registries/listCredentials/action
Microsoft.ContainerRegistry/registries/listCredentials/action
Event
The registry admin account must be enabled. Its username and two independently renewable passwords provide shared registry push/pull access. ARM permission to retrieve credentials and subsequent registry authentication are separate; network restrictions still apply.
Security Context
Unauthorized credential retrieval can support T1552. Approved provisioning also uses this operation. A successful request does not prove image download, modification, or deployment to an AKS workload.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerRegistry/registries/listCredentials/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Check adminUserEnabled, caller authorization, and the approved need for shared credentials.
- Inspect registry network restrictions and password rotation history; handle any returned passwords as secrets.
- Correlate actual registry push/pull and deployment evidence before claiming workload compromise.
Sample Event
Synthetic scenario. The sample records successful credential retrieval. Returned passwords and downstream registry activity are absent.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.ContainerRegistry/registries/listCredentials/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010111000", "description": "", "eventDataId": "90000000-0000-4000-8000-000010111001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T22:42:18.7172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010111010", "operationName": { "value": "Microsoft.ContainerRegistry/registries/listCredentials/action", "localizedValue": "List Container Registry credentials" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.ContainerRegistry", "localizedValue": "Microsoft Container Registry" }, "resourceType": { "value": "Microsoft.ContainerRegistry/registries", "localizedValue": "Microsoft.ContainerRegistry/registries" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T22:42:19.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy", "message": "Microsoft.ContainerRegistry/registries/listCredentials/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010111011", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerRegistry/registries/acroccamy/listCredentials?api-version=2023-11-01-preview" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...