Benchmark: SQL Detections
Description
This detection benchmark contains recommendations when scanning Azure SQL activity logs.
Usage
Install the mod:
mkdir dashboardscd dashboardspowerpipe mod initpowerpipe mod install github.com/turbot/tailpipe-mod-azure-activity-log-detections
Start the Powerpipe server:
powerpipe server
Open http://localhost:9033 in your browser and select SQL Detections.
Run this benchmark in your terminal:
powerpipe benchmark run azure_activity_log_detections.benchmark.sql_detections
Snapshot and share results via Turbot Pipes:
powerpipe benchmark run azure_activity_log_detections.benchmark.sql_detections --share
Detections
- SQL Database Deleted
- SQL Database TDE Created or Updated
- SQL Server Deleted
- SQL Server Firewall Rule Created or Updated
- SQL Server Role Assignment Created or Updated