⛅Azure detections
Clankerusecase tracks 70 detection use cases covering the Azure attack surface across 68 MITRE ATT&CK techniques.
Detections targeting Microsoft Azure — Activity Logs, Azure AD, Sentinel SecurityEvent / SigninLogs.
70Use cases
68Techniques
60Articles
6Kill-chain phases
Top techniques on Azure (25)
T1078.004Cloud Accounts13T1528Steal Application Access Token11T1190Exploit Public-Facing Application8T1098Account Manipulation6T1566.002Spearphishing Link6T1550.001Application Access Token5T1195.002Compromise Software Supply Chain5T1567Exfiltration Over Web Service5T1071.001Web Protocols5T1556Modify Authentication Process4T1098.001Additional Cloud Credentials4T1098.005Device Registration4T1530Data from Cloud Storage4T1078Valid Accounts4T1556.006Multi-Factor Authentication4T1072Software Deployment Tools4T1021.007Cloud Services4T1114.003Email Forwarding Rule4T1552.001Credentials In Files3T1566.001Spearphishing Attachment3T1098.003Additional Cloud Roles3T1136.003Cloud Account3T1564.008Email Hiding Rules3T1485Data Destruction2T1621Multi-Factor Authentication Request Generation2