Skip to content

Microsoft.KeyVault/vaults/secrets/delete

Azure

Microsoft.KeyVault/vaults/secrets/delete

service: Azure - Key Vault
tactics:
techniques:

Event

SecretDelete acts on the named secret, including all versions, rather than selecting a single version. With soft-delete, recovery remains possible during retention; purge is a separate operation. Deleting a stored password does not itself rotate or invalidate that password in the downstream service.

Security Context

Malicious deletion can disrupt dependent workloads (contextual T1485). Approved retirement also uses it. Cached values and redundancy affect impact, and deletion is not proof of immediate application failure or irreversible loss.

Log Source

Azure Key Vault resource logs, AuditEvent category, with operationName: SecretDelete. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.

Key Fields

FieldInvestigation value
operationName, resultType, properties.httpStatusCodeData-plane operation and result.
identity.claim, callerIpAddressRecorded principal and client context; corroborate attribution.
properties.requestUri, properties.idVault object and version where specified.
correlationId, timeCorrelation and timing; no returned secret or private key is logged here.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm the secret name, outcome, retention, purge protection, and any recovery or purge records.
  3. Review dependent applications and observed retrieval failures, including caches and alternative credentials.
  4. Coordinate recovery or downstream credential rotation according to the actual incident; do not infer prior exfiltration.

Sample Event

Synthetic scenario. The sample deletes bowtruckle-prod-db-password without a version suffix. It does not show purge, downstream password invalidation, or application impact.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"time": "2026-04-15T18:13:42.6029771Z",
"resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD",
"operationName": "SecretDelete",
"operationVersion": "7.4",
"category": "AuditEvent",
"resultType": "Success",
"resultSignature": "OK",
"resultDescription": "",
"durationMs": "33",
"callerIpAddress": "203.0.113.66",
"correlationId": "90000000-0000-4000-8000-000100001000",
"identity": {
"claim": {
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation"
}
},
"properties": {
"id": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password",
"clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)",
"requestUri": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password?api-version=7.4",
"httpStatusCode": 200
},
"tenantId": "10000000-0000-4000-8000-000000000001"
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.