Clankerusecase
Azure detection coverage
← Back to main site
Home/ Targets/ Azure

Azure detections

Clankerusecase tracks 71 detection use cases covering the Azure attack surface across 72 MITRE ATT&CK techniques.

Detections targeting Microsoft Azure — Activity Logs, Azure AD, Sentinel SecurityEvent / SigninLogs.

Open Detection Library → View on the matrix
71Use cases
72Techniques
60Articles
6Kill-chain phases

Top techniques on Azure (25)

Reconnaissance (1)

[LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP

Delivery (10)

Azure AD brute-force login Internal delivery · alerting DD Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal delivery · hunting DSP [LLM] Corporate sign-in from DPRK IT-worker VPS / AstrillVPN infrastructure (Famous Chollima) Bespoke delivery · hunting DSΣPDD [LLM] Successful Entra ID device-code authentication (ARToken/EvilTokens PhaaS MFA bypass) Bespoke delivery · hunting DSΣP [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package Bespoke delivery · alerting DSP

Exploitation (12)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [LLM] Entra ID password spray: many distinct accounts failing auth from few source IPs Bespoke exploit · alerting DSPDD [LLM] Entra ID MFA fatigue: burst of MFA-challenge failures followed by a successful MFA sign-in Bespoke exploit · alerting DSPDD [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] OAuth device-code authorization flow sign-in (ARToken/EvilTokens MFA bypass) Bespoke exploit · hunting DSΣ [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering Bespoke exploit · alerting DSPDDCS [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD

Installation (8)

Azure AD member assigned Global Administrator role Internal install · alerting DD Azure AD MFA disabled for a user Internal install · alerting DD Azure diagnostic setting deleted Internal install · alerting DD Azure new owner added to service principal Internal install · alerting DD Azure SQL Server firewall rule created Internal install · alerting DD Azure user added to administrative group Internal install · alerting DD [LLM] AI resource key creation paired with logging/alert teardown in cloud control plane Bespoke install · hunting SPDDCW [LLM] High-privilege OAuth consent grant to Flowise application (offline_access / Mail / Files) Bespoke install · hunting DSΣDD

Command & Control (5)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD

Actions on Objectives (35)

Azure Key Vault keys / secrets read Internal actions · alerting DD Azure storage soft-delete disabled Internal actions · alerting DD MFA fatigue / push-bombing Internal actions · alerting DSP OAuth consent / suspicious app grant Internal actions · alerting DSΣP [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Azure AD FullAccessAsApp Permission Assigned ESCU actions · alerting P Azure AD Multi-Factor Authentication Disabled ESCU actions · alerting P Azure AD New MFA Method Registered For User ESCU actions · alerting P Azure AD Privileged Graph API Permission Assigned ESCU actions · alerting P Azure AD Service Principal New Client Credentials ESCU actions · alerting P Azure AD Service Principal Privilege Escalation ESCU actions · alerting P Azure Automation Account Created ESCU actions · alerting P Azure Automation Runbook Created ESCU actions · alerting P Azure Runbook Webhook Created ESCU actions · alerting P Microsoft Intune Device Health Scripts ESCU actions · hunting P Microsoft Intune DeviceManagementConfigurationPolicies ESCU actions · hunting P Microsoft Intune Manual Device Management ESCU actions · hunting P Microsoft Intune Mobile Apps ESCU actions · hunting P [LLM] First-time Entra directory enumeration via Graph/PowerShell CLI tooling by a user Bespoke actions · hunting DSPDD [LLM] Post-quishing cloud token replay: MFA-satisfied sign-in shortly after QR-attachment email Bespoke actions · alerting DSPDD [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN Bespoke actions · hunting DSPDD [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP Bespoke actions · alerting DS [LLM] Entra ID sign-in or session from Storm-2945 AiTM device-code phishing infrastructure Bespoke actions · hunting DSΣPDD [LLM] Email-hiding inbox rules created post-compromise (BEC / mailbox concealment) Bespoke actions · hunting DSΣP [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] Post-compromise M365 defense-evasion inbox rule creation (UAT-11764 mailbox takeover) Bespoke actions · hunting DSΣ [LLM] n8n-MCP destructive workflow version backup deletion (delete/prune/truncate) — CVE-2026-54052 impact Bespoke actions · alerting SΣP [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke actions · alerting DSP [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD

Recent articles citing Azure-targeted detections