Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This query hunts for likely Azure VM post-RCE identity abuse by correlating suspicious web or management service child process execution with IMDS (Azure Instance Metadata Service) access and optional near-term public egress.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | b8c5b7f8-6c3c-4c34-8d12-3f2f5f0dc184 |
| Tactics | InitialAccess, Execution, CredentialAccess |
| Techniques | T1190, T1059, T1528 |
| Required Connectors | MicrosoftThreatProtection |
| Source | View on GitHub |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity