azure-defender-automation-action-configuration

Defender automation actions can expose Logic App resource IDs, Event Hub connection targets, and operator-entered text.

azurehigh service: azure:defender emits ContainsSecret

Where it sits

locationMicrosoft.Security/automations properties.{sources,actions,scopes,description}
location kindpolicy_document
data kindscredential webhook_secret sensitive_data
emits edgeContainsSecret
serviceDefender for Cloud (azure:defender)

Collection recipe

access moderead_api
operationAutomations - Get
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Security/automations/read

References

move · open · esc close