⛅Azure detections
Clankerusecase tracks 71 detection use cases covering the Azure attack surface across 72 MITRE ATT&CK techniques.
Detections targeting Microsoft Azure — Activity Logs, Azure AD, Sentinel SecurityEvent / SigninLogs.
71Use cases
72Techniques
60Articles
6Kill-chain phases
Top techniques on Azure (25)
T1078.004Cloud Accounts17T1528Steal Application Access Token10T1190Exploit Public-Facing Application8T1098Account Manipulation6T1098.001Additional Cloud Credentials6T1566.002Spearphishing Link6T1621Multi-Factor Authentication Request Generation5T1078Valid Accounts4T1195.002Compromise Software Supply Chain4T1072Software Deployment Tools4T1021.007Cloud Services4T1550.004Web Session Cookie4T1114.003Email Forwarding Rule4T1567Exfiltration Over Web Service4T1071.001Web Protocols4T1556Modify Authentication Process3T1552.001Credentials In Files3T1566.001Spearphishing Attachment3T1550.001Application Access Token3T1098.005Device Registration3T1556.006Multi-Factor Authentication3T1136.003Cloud Account3T1564.008Email Hiding Rules3T1562.008T1562.0082T1485Data Destruction2