| AAD Connect host remote admin followed by Entra privilege operation |
Persistence, PrivilegeEscalation, LateralMovement |
Internal use:
IdentityInfo |
| App credential change followed by SP sign-in burst |
Persistence, PrivilegeEscalation |
- |
| Appliance management session followed by RBAC write |
LateralMovement, PrivilegeEscalation, Persistence |
AzureActivity |
| Azure Network Configuration Tampered by Compromised Identity |
DefenseEvasion, Persistence, PrivilegeEscalation |
DeviceInfo
DeviceNetworkInfo Internal use:
BehaviorAnalytics |
| Azure Storage Access via AccountKey or SAS Token from First-Seen External IP |
Exfiltration |
StorageBlobLogs |
| Azure Storage Bulk Download via AccountKey or SAS Token from External IP |
Exfiltration, Collection |
StorageBlobLogs |
| Azure VM web process to IMDS token theft chain |
InitialAccess, Execution, CredentialAccess |
- |
| CVE Exploitation Indicators on Network Appliance (3P) |
InitialAccess, Persistence, DefenseEvasion |
CommonSecurityLog |
| Cloud Run Command followed by kernel persistence indicators on target servers |
LateralMovement, Persistence, Execution |
AzureActivity
DeviceImageLoadEvents
DeviceProcessEvents |
| Credential Stuffing or Password Spray on VPN or Firewall (3P Appliance) |
CredentialAccess, InitialAccess |
CommonSecurityLog |
| Cross-subscription and resource-group enumeration sweep by single identity |
Discovery |
AzureActivity |
| Email Forwarding Rule Created to External Address |
Collection, Exfiltration |
- |
| Entra App credential change followed by service principal sign-in burst |
Persistence, CredentialAccess, DefenseEvasion |
- |
| Entra hybrid user sign-in followed by on-prem lateral movement |
LateralMovement, ValidAccounts |
DeviceInfo Internal use:
IdentityInfo |
| Federated Identity Provider Added to Tenant |
Persistence |
AuditLogs
SigninLogs |
| IAM and subscription enumeration followed by Key Vault operations |
Discovery, CredentialAccess, PrivilegeEscalation |
AzureActivity |
| IAM reconnaissance followed by role assignment write attempt |
Discovery, PrivilegeEscalation, Persistence |
AzureActivity |
| Identity and app enumeration followed by novel non-interactive tuple |
Discovery, CredentialAccess, LateralMovement |
AADNonInteractiveUserSignInLogs
AzureActivity |
| K8s token audit then novel cloud control plane operations |
CredentialAccess, Discovery, PrivilegeEscalation |
CloudAuditEvents |
| Kerberoast burst followed by cloud sign-in |
CredentialAccess, LateralMovement, ValidAccounts |
SecurityEvent Internal use:
IdentityInfo |
| Key Vault discovery followed by data-store access enumeration |
Discovery, Collection, CredentialAccess |
AzureActivity |
| Key Vault harvest to SPN sign-in then out-of-scope resource access |
CredentialAccess, Discovery, Collection |
AADServicePrincipalSignInLogs
AzureActivity |
| Key Vault secret harvest followed by novel SPN sign-in from non-1P IP |
CredentialAccess, DefenseEvasion, Persistence |
AADServicePrincipalSignInLogs
AzureActivity |
| Key Vault secret read then Storage key-auth pivot |
Exfiltration, CredentialAccess, Collection, DefenseEvasion |
AzureActivity
CloudStorageAggregatedEvents |
| Key Vault secret read then partial storage exfil |
CredentialAccess, Collection, Exfiltration, DefenseEvasion |
AzureActivity
CloudStorageAggregatedEvents |
| Kubernetes daemonset or cronjob by non-automation identity |
Persistence, PrivilegeEscalation |
AzureDiagnostics |
| Kubernetes first-seen control-plane writer |
InitialAccess, Execution, Persistence |
AzureDiagnostics |
| Kubernetes secret enumeration followed by pod exec |
CredentialAccess, Execution |
AzureDiagnostics |
| MFA Method Added on Risky Account |
Persistence |
AuditLogs
SigninLogs |
| Multi-Mailbox Access by Single IP via Cloud App Permissions |
Collection, Exfiltration |
CloudAppEvents Internal use:
ThreatIntelIndicators |
| Multi-service network exposure followed by key and data access |
DefenseEvasion, CredentialAccess, Collection |
AzureActivity |
| Novel SPN sign-in followed by Azure RBAC write |
PrivilegeEscalation, Persistence, DefenseEvasion |
AADServicePrincipalSignInLogs
AzureActivity |
| Novel identity then Key Vault secret burst |
Exfiltration, Discovery, CredentialAccess, Collection |
AADNonInteractiveUserSignInLogs
AADServicePrincipalSignInLogs
AzureActivity
SigninLogs |
| Novel sign-in context followed by IAM reconnaissance burst |
Discovery, CredentialAccess |
AADNonInteractiveUserSignInLogs
AzureActivity
SigninLogs |
| OAuth consent change followed by first-seen OAuthAppId burst |
InitialAccess, Discovery, Collection |
CloudAppEvents |
| Partial failures followed by read concentration |
Discovery, Collection, Exfiltration, DefenseEvasion |
CloudStorageAggregatedEvents |
| Pod cloud CLI then KeyVault or storage access |
CredentialAccess, Discovery, Collection |
CloudAuditEvents
CloudProcessEvents |
| Pod token tooling then cloud RBAC write |
CredentialAccess, PrivilegeEscalation, DefenseEvasion |
CloudAuditEvents
CloudProcessEvents |
| Post-Auth Config Change on Network Appliance (3P) |
DefenseEvasion, Persistence |
CommonSecurityLog |
| RDP to hybrid joined device followed by Entra access |
LateralMovement, ValidAccounts |
DeviceInfo Internal use:
IdentityInfo |
| Rare kernel load followed by novel non-interactive sign-in tuple |
Persistence, DefenseEvasion, CredentialAccess |
AADNonInteractiveUserSignInLogs
DeviceImageLoadEvents |
| Rare service principal authentication tuple |
CredentialAccess, Persistence |
- |
| Rare service principal sign-in followed by RBAC write |
CredentialAccess, PrivilegeEscalation, Persistence |
- |
| Risky Successful Sign-in to VPN or Network Access Application |
InitialAccess |
AADUserRiskEvents
SigninLogs |
| Secret Added to Dormant Service Principal |
Persistence, PrivilegeEscalation |
AADServicePrincipalSignInLogs
AuditLogs |
| Service principal Conditional Access anomaly |
DefenseEvasion, Persistence |
AADServicePrincipalSignInLogs |
| Service principal credential change followed by novel SP sign-in |
Persistence, PrivilegeEscalation |
AADServicePrincipalSignInLogs
AuditLogs |
| Suspicious OAuth App Consent Granting Sensitive Permissions |
Collection, Exfiltration, Persistence |
AuditLogs |
| Suspicious sign-in followed by auth method or role change |
InitialAccess, Persistence, PrivilegeEscalation |
AuditLogs
SigninLogs |
| Suspicious sign-in followed by cloud network exposure writes |
InitialAccess, DefenseEvasion, Discovery |
AADNonInteractiveUserSignInLogs
AzureActivity
SigninLogs |
| Threat Intelligence Matched IP on Network Appliance Traffic |
InitialAccess, CommandAndControl |
CommonSecurityLog Internal use:
ThreatIntelIndicators |
| VPN Credential Stuffing and Password Spray |
InitialAccess, CredentialAccess |
AADNonInteractiveUserSignInLogs
SigninLogs
TacitRed_Findings_CL Internal use:
BehaviorAnalytics |
| WMI or remote admin execution on hybrid device followed by cloud sign-in |
LateralMovement, Execution, ValidAccounts |
DeviceInfo Internal use:
IdentityInfo |
| Web service child process with egress |
InitialAccess, Execution |
- |