IAM reconnaissance followed by role assignment write attempt

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects likely escalation staging where IAM discovery is followed by role assignment write operations by the same caller.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID 9259db24-159e-411d-a893-a9f2c819bdf4
Tactics Discovery, PrivilegeEscalation, Persistence
Techniques T1526, T1087.004, T1098.003
Required Connectors AzureActivity
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AzureActivity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity