Microsoft.Web/sites/host/listKeys/action
Microsoft.Web/sites/host/listKeys/action
Event
The list host keys endpoint returns function-app host-level key information, including the master key and extension system keys. Host keys authorize function-level HTTP endpoints across the app; the master key also authorizes runtime administrative APIs. Per-function key retrieval is a distinct endpoint.
Security Context
Unauthorized retrieval can expose credentials (T1552). Keys do not bypass App Service authentication, network restrictions, or application-specific checks. A host-key event is neither ARM administration nor proof that any function executed; legitimate management also retrieves keys.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Web/sites/host/listKeys/action. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor/authorization context; verify effective authority. |
resourceId, correlationId | Exact target and related management operations. |
status, subStatus | Outcome and any asynchronous follow-up. |
properties.requestbody | Submitted configuration where present; returned secrets are intentionally absent. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the function app/slot, caller, and approved key-retrieval purpose.
- Inspect App Service authentication, private/public network access, runtime admin isolation, and relevant key rotation.
- Correlate runtime administrative requests and function executions; do not copy live keys or code-bearing URLs into notes.
Sample Event
Synthetic scenario. The sample records host-key retrieval for func-occamy-log-processor. No key values, internet reachability, authentication bypass, or invocation is shown.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Web/sites/host/listKeys/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "fnLk227ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100011011", "description": "", "eventDataId": "90000000-0000-4000-8000-000100011100", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:01:48.7421022Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100111011", "operationName": { "value": "Microsoft.Web/sites/host/listKeys/action", "localizedValue": "List Web App Host Keys" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Web", "localizedValue": "Microsoft.Web" }, "resourceType": { "value": "Microsoft.Web/sites/host", "localizedValue": "Microsoft.Web/sites/host" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:01:49.3052812Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default/listKeys", "message": "Microsoft.Web/sites/host/listKeys/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...