Microsoft.KeyVault/vaults/secrets/read
Microsoft.KeyVault/vaults/secrets/read
Event
SecretGet returns the secret value to an authorized client over HTTPS. Listing secrets returns metadata, not their values. A versioned request selects that version; omitting the version requests the latest. Audit records describe access but do not contain the returned secret value.
Security Context
Unauthorized access can expose credentials from a cloud secret store (T1555.006). Normal application retrieval is frequent. A suggestive secret name does not prove its contents, compromised caller intent, or use against a database.
Log Source
Azure Key Vault resource logs, AuditEvent category, with operationName: SecretGet. Enable diagnostic collection to the required destination. The catalog permission-style title is not the data-plane audit operation name. Export wrappers and casing vary; this is not a default ARM Activity Log read record.
Key Fields
| Field | Investigation value |
|---|---|
operationName, resultType, properties.httpStatusCode | Data-plane operation and result. |
identity.claim, callerIpAddress | Recorded principal and client context; corroborate attribution. |
properties.requestUri, properties.id | Vault object and version where specified. |
correlationId, time | Correlation and timing; no returned secret or private key is logged here. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the caller, effective vault authorization, network access, secret name/version, and result.
- Compare retrieval timing and volume with the application’s normal behavior and approved maintenance.
- Correlate downstream authentication and access evidence securely; avoid placing secret values in incident notes.
Sample Event
Synthetic scenario. The sample records successful retrieval of an illustrative version of bowtruckle-prod-db-password. No returned value, prior policy change, or downstream use is shown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "time": "2026-04-15T17:51:09.7842155Z", "resourceId": "/SUBSCRIPTIONS/20000000-0000-4000-8000-000000000001/RESOURCEGROUPS/RG-BOWTRUCKLE-VAULT/PROVIDERS/MICROSOFT.KEYVAULT/VAULTS/KV-BOWTRUCKLE-PROD", "operationName": "SecretGet", "operationVersion": "7.4", "category": "AuditEvent", "resultType": "Success", "resultSignature": "OK", "resultDescription": "", "durationMs": "28", "callerIpAddress": "203.0.113.66", "correlationId": "90000000-0000-4000-8000-000100001011", "identity": { "claim": { "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation" } }, "properties": { "id": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password/0a6d57ee888b8ca36d60ab241430d713", "clientInfo": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)", "requestUri": "https://kv-bowtruckle-prod.vault.azure.net/secrets/bowtruckle-prod-db-password/0a6d57ee888b8ca36d60ab241430d713?api-version=7.4", "httpStatusCode": 200 }, "tenantId": "10000000-0000-4000-8000-000000000001"}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.