Secret Added to Dormant Service Principal

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies credentials added to a service principal dormant for 14+ days that then activates. Consistent with Midnight Blizzard (APT29) technique of adding secrets to trusted SPs for stealthy persistent access (T1098.001).

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID e2294d1a-ae7d-4212-94c8-6ceff148993a
Tactics Persistence, PrivilegeEscalation
Techniques T1098.001
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AADServicePrincipalSignInLogs
AuditLogs OperationName == "Add service principal credentials"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity