Skip to content

Microsoft.KeyVault/vaults/secrets/read

Azure

Microsoft.KeyVault/vaults/secrets/read

service: Azure - Key Vault
techniques:

Event

SecretGet returns the secret value to an authorized client over HTTPS. Listing secrets returns metadata, not their values. A versioned request selects that version; omitting the version requests the latest. Audit records describe access but do not contain the returned secret value.

Security Context

Unauthorized access can expose credentials from a cloud secret store (T1555.006). Normal application retrieval is frequent. A suggestive secret name does not prove its contents, compromised caller intent, or use against a database.

Log Source

Azure Key Vault resource logs, AuditEvent category, with operationName: SecretGet. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.

Key Fields

FieldInvestigation value
operationName, resultType, properties.httpStatusCodeData-plane operation and result.
identity.claim, callerIpAddressRecorded principal and client context; corroborate attribution.
properties.requestUri, properties.idVault object and version where specified.
correlationId, timeCorrelation and timing; no returned secret or private key is logged here.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the caller, effective vault authorization, network access, secret name/version, and result.
  3. Compare retrieval timing and volume with the application’s normal behavior and approved maintenance.
  4. Correlate downstream authentication and access evidence securely; avoid placing secret values in incident notes.

Sample Event

Synthetic scenario. The sample records successful retrieval of an illustrative version of bowtruckle-prod-db-password. No returned value, prior policy change, or downstream use is shown.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"time": "2026-04-15T17:51:09.7842155Z",
"resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD",
"operationName": "SecretGet",
"operationVersion": "7.4",
"category": "AuditEvent",
"resultType": "Success",
"resultSignature": "OK",
"resultDescription": "",
"durationMs": "28",
"callerIpAddress": "203.0.113.66",
"correlationId": "90000000-0000-4000-8000-000100001011",
"identity": {
"claim": {
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation"
}
},
"properties": {
"id": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password/0a6d57ee888b8ca36d60ab241430d713",
"clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)",
"requestUri": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password/0a6d57ee888b8ca36d60ab241430d713?api-version=7.4",
"httpStatusCode": 200
},
"tenantId": "10000000-0000-4000-8000-000000000001"
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.