Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This query hunts for Entra application or service principal credential changes that are followed by rapid sign-in activity for the affected principal.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | 24e7f5fe-4f87-43b3-85f5-c620f8b51a83 |
| Tactics | Persistence, CredentialAccess, DefenseEvasion |
| Techniques | T1098, T1078.004, T1550 |
| Required Connectors | AzureActiveDirectory |
| Source | View on GitHub |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity