Azure VM web process to IMDS token theft chain

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query hunts for likely Azure VM post-RCE identity abuse by correlating suspicious web or management service child process execution with IMDS (Azure Instance Metadata Service) access and optional near-term public egress.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID b8c5b7f8-6c3c-4c34-8d12-3f2f5f0dc184
Tactics InitialAccess, Execution, CredentialAccess
Techniques T1190, T1059, T1528
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity