App credential change followed by SP sign-in burst

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects likely cloud persistence by correlating app credential operations with near-term service principal authentication bursts.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID 1bd11966-beb8-4ee9-bb8d-f6627b45a250
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1078.004, T1550.001
Required Connectors AzureActiveDirectory
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity