Hybrid Attack - Cloud & Identity

Hybrid Attack - Cloud & Identity Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com
Categories Security - Threat Protection
Version 3.0.0
Author Microsoft - support@microsoft.com
First Published 2026-06-15
Last Updated 2026-07-29
Solution Folder Hybrid Attack - Cloud & Identity
Marketplace Azure Marketplace · Popularity: ⚪ Very Low (0%)

This solution includes hunting queries for hybrid attack scenarios spanning on-premises, cloud, and identity environments. The queries are designed to detect multi-stage attack techniques that leverage both cloud and identity signals. By correlating activities across different domains, these hunting queries help security analysts identify complex attack patterns that may go unnoticed when looking at individual data sources in isolation.

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Tables Used

This solution queries 19 table(s) from its content items:

Table Used By Content
AADNonInteractiveUserSignInLogs Hunting, Workbooks
AADServicePrincipalSignInLogs Hunting, Workbooks
AADUserRiskEvents Hunting, Workbooks
AuditLogs Hunting, Workbooks
AzureActivity Hunting, Workbooks
AzureDiagnostics Hunting, Workbooks
CloudAppEvents Hunting, Workbooks
CloudAuditEvents Hunting, Workbooks
CloudProcessEvents Hunting, Workbooks
CloudStorageAggregatedEvents Hunting, Workbooks
CommonSecurityLog Hunting, Workbooks
DeviceImageLoadEvents Hunting
DeviceInfo Hunting, Workbooks
DeviceNetworkInfo Hunting, Workbooks
DeviceProcessEvents Hunting
Event Workbooks
SecurityEvent Hunting
SigninLogs Hunting, Workbooks
StorageBlobLogs Hunting, Workbooks

Internal Tables

The following 3 table(s) are used internally by this solution's content items:

Table Used By Content
BehaviorAnalytics Hunting, Workbooks
IdentityInfo Hunting, Workbooks
ThreatIntelIndicators Hunting, Workbooks

Content Items

This solution includes 55 content item(s):

Content Type Count
Hunting Queries 54
Workbooks 1

Hunting Queries

Name Tactics Tables Used
AAD Connect host remote admin followed by Entra privilege operation Persistence, PrivilegeEscalation, LateralMovement Internal use:
IdentityInfo
App credential change followed by SP sign-in burst Persistence, PrivilegeEscalation -
Appliance management session followed by RBAC write LateralMovement, PrivilegeEscalation, Persistence AzureActivity
Azure Network Configuration Tampered by Compromised Identity DefenseEvasion, Persistence, PrivilegeEscalation DeviceInfo
DeviceNetworkInfo
Internal use:
BehaviorAnalytics
Azure Storage Access via AccountKey or SAS Token from First-Seen External IP Exfiltration StorageBlobLogs
Azure Storage Bulk Download via AccountKey or SAS Token from External IP Exfiltration, Collection StorageBlobLogs
Azure VM web process to IMDS token theft chain InitialAccess, Execution, CredentialAccess -
CVE Exploitation Indicators on Network Appliance (3P) InitialAccess, Persistence, DefenseEvasion CommonSecurityLog
Cloud Run Command followed by kernel persistence indicators on target servers LateralMovement, Persistence, Execution AzureActivity
DeviceImageLoadEvents
DeviceProcessEvents
Credential Stuffing or Password Spray on VPN or Firewall (3P Appliance) CredentialAccess, InitialAccess CommonSecurityLog
Cross-subscription and resource-group enumeration sweep by single identity Discovery AzureActivity
Email Forwarding Rule Created to External Address Collection, Exfiltration -
Entra App credential change followed by service principal sign-in burst Persistence, CredentialAccess, DefenseEvasion -
Entra hybrid user sign-in followed by on-prem lateral movement LateralMovement, ValidAccounts DeviceInfo
Internal use:
IdentityInfo
Federated Identity Provider Added to Tenant Persistence AuditLogs
SigninLogs
IAM and subscription enumeration followed by Key Vault operations Discovery, CredentialAccess, PrivilegeEscalation AzureActivity
IAM reconnaissance followed by role assignment write attempt Discovery, PrivilegeEscalation, Persistence AzureActivity
Identity and app enumeration followed by novel non-interactive tuple Discovery, CredentialAccess, LateralMovement AADNonInteractiveUserSignInLogs
AzureActivity
K8s token audit then novel cloud control plane operations CredentialAccess, Discovery, PrivilegeEscalation CloudAuditEvents
Kerberoast burst followed by cloud sign-in CredentialAccess, LateralMovement, ValidAccounts SecurityEvent
Internal use:
IdentityInfo
Key Vault discovery followed by data-store access enumeration Discovery, Collection, CredentialAccess AzureActivity
Key Vault harvest to SPN sign-in then out-of-scope resource access CredentialAccess, Discovery, Collection AADServicePrincipalSignInLogs
AzureActivity
Key Vault secret harvest followed by novel SPN sign-in from non-1P IP CredentialAccess, DefenseEvasion, Persistence AADServicePrincipalSignInLogs
AzureActivity
Key Vault secret read then Storage key-auth pivot Exfiltration, CredentialAccess, Collection, DefenseEvasion AzureActivity
CloudStorageAggregatedEvents
Key Vault secret read then partial storage exfil CredentialAccess, Collection, Exfiltration, DefenseEvasion AzureActivity
CloudStorageAggregatedEvents
Kubernetes daemonset or cronjob by non-automation identity Persistence, PrivilegeEscalation AzureDiagnostics
Kubernetes first-seen control-plane writer InitialAccess, Execution, Persistence AzureDiagnostics
Kubernetes secret enumeration followed by pod exec CredentialAccess, Execution AzureDiagnostics
MFA Method Added on Risky Account Persistence AuditLogs
SigninLogs
Multi-Mailbox Access by Single IP via Cloud App Permissions Collection, Exfiltration CloudAppEvents
Internal use:
ThreatIntelIndicators
Multi-service network exposure followed by key and data access DefenseEvasion, CredentialAccess, Collection AzureActivity
Novel SPN sign-in followed by Azure RBAC write PrivilegeEscalation, Persistence, DefenseEvasion AADServicePrincipalSignInLogs
AzureActivity
Novel identity then Key Vault secret burst Exfiltration, Discovery, CredentialAccess, Collection AADNonInteractiveUserSignInLogs
AADServicePrincipalSignInLogs
AzureActivity
SigninLogs
Novel sign-in context followed by IAM reconnaissance burst Discovery, CredentialAccess AADNonInteractiveUserSignInLogs
AzureActivity
SigninLogs
OAuth consent change followed by first-seen OAuthAppId burst InitialAccess, Discovery, Collection CloudAppEvents
Partial failures followed by read concentration Discovery, Collection, Exfiltration, DefenseEvasion CloudStorageAggregatedEvents
Pod cloud CLI then KeyVault or storage access CredentialAccess, Discovery, Collection CloudAuditEvents
CloudProcessEvents
Pod token tooling then cloud RBAC write CredentialAccess, PrivilegeEscalation, DefenseEvasion CloudAuditEvents
CloudProcessEvents
Post-Auth Config Change on Network Appliance (3P) DefenseEvasion, Persistence CommonSecurityLog
RDP to hybrid joined device followed by Entra access LateralMovement, ValidAccounts DeviceInfo
Internal use:
IdentityInfo
Rare kernel load followed by novel non-interactive sign-in tuple Persistence, DefenseEvasion, CredentialAccess AADNonInteractiveUserSignInLogs
DeviceImageLoadEvents
Rare service principal authentication tuple CredentialAccess, Persistence -
Rare service principal sign-in followed by RBAC write CredentialAccess, PrivilegeEscalation, Persistence -
Risky Successful Sign-in to VPN or Network Access Application InitialAccess AADUserRiskEvents
SigninLogs
Secret Added to Dormant Service Principal Persistence, PrivilegeEscalation AADServicePrincipalSignInLogs
AuditLogs
Service principal Conditional Access anomaly DefenseEvasion, Persistence AADServicePrincipalSignInLogs
Service principal credential change followed by novel SP sign-in Persistence, PrivilegeEscalation AADServicePrincipalSignInLogs
AuditLogs
Suspicious OAuth App Consent Granting Sensitive Permissions Collection, Exfiltration, Persistence AuditLogs
Suspicious sign-in followed by auth method or role change InitialAccess, Persistence, PrivilegeEscalation AuditLogs
SigninLogs
Suspicious sign-in followed by cloud network exposure writes InitialAccess, DefenseEvasion, Discovery AADNonInteractiveUserSignInLogs
AzureActivity
SigninLogs
Threat Intelligence Matched IP on Network Appliance Traffic InitialAccess, CommandAndControl CommonSecurityLog
Internal use:
ThreatIntelIndicators
VPN Credential Stuffing and Password Spray InitialAccess, CredentialAccess AADNonInteractiveUserSignInLogs
SigninLogs
TacitRed_Findings_CL
Internal use:
BehaviorAnalytics
WMI or remote admin execution on hybrid device followed by cloud sign-in LateralMovement, Execution, ValidAccounts DeviceInfo
Internal use:
IdentityInfo
Web service child process with egress InitialAccess, Execution -

Workbooks

Name Tables Used
HybridAttack-Cloud&Identity AADNonInteractiveUserSignInLogs
AADServicePrincipalSignInLogs
AADUserRiskEvents
AuditLogs
AzureActivity
AzureDiagnostics
CloudAppEvents
CloudAuditEvents
CloudProcessEvents
CloudStorageAggregatedEvents
CommonSecurityLog
DeviceInfo
DeviceNetworkInfo
Event
SigninLogs
StorageBlobLogs
Internal use:
BehaviorAnalytics
IdentityInfo
ThreatIntelIndicators

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 26-06-2026 Private Preview Release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index