Skip to content

Microsoft.Web/sites/host/listKeys/action

Azure

Microsoft.Web/sites/host/listKeys/action

service: Azure - Web
techniques:

Event

The list host keys endpoint returns function-app host-level key information, including the master key and extension system keys. Host keys authorize function-level HTTP endpoints across the app; the master key also authorizes runtime administrative APIs. Per-function key retrieval is a distinct endpoint.

Security Context

Unauthorized retrieval can expose credentials (T1552). Keys do not bypass App Service authentication, network restrictions, or application-specific checks. A host-key event is neither ARM administration nor proof that any function executed; legitimate management also retrieves keys.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Web/sites/host/listKeys/action. Inspect outcome and final state; request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor/authorization context; verify effective authority.
resourceId, correlationIdExact target and related management operations.
status, subStatusOutcome and any asynchronous follow-up.
properties.requestbodySubmitted configuration where present; returned secrets are intentionally absent.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the function app/slot, caller, and approved key-retrieval purpose.
  3. Inspect App Service authentication, private/public network access, runtime admin isolation, and relevant key rotation.
  4. Correlate runtime administrative requests and function executions; do not copy live keys or code-bearing URLs into notes.

Sample Event

Synthetic scenario. The sample records host-key retrieval for func-occamy-log-processor. No key values, internet reachability, authentication bypass, or invocation is shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Web/sites/host/listKeys/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "fnLk227ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100011011",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100011100",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:01:48.7421022Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100111011",
"operationName": {
"value": "Microsoft.Web/sites/host/listKeys/action",
"localizedValue": "List Web App Host Keys"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Web",
"localizedValue": "Microsoft.Web"
},
"resourceType": {
"value": "Microsoft.Web/sites/host",
"localizedValue": "Microsoft.Web/sites/host"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T18:01:49.3052812Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Web/sites/func-occamy-log-processor/host/default/listKeys",
"message": "Microsoft.Web/sites/host/listKeys/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.