Clankerusecase
Azure detection coverage
← Back to main site
Home/ Targets/ Azure

Azure detections

Clankerusecase tracks 70 detection use cases covering the Azure attack surface across 68 MITRE ATT&CK techniques.

Detections targeting Microsoft Azure — Activity Logs, Azure AD, Sentinel SecurityEvent / SigninLogs.

Open Detection Library → View on the matrix
70Use cases
68Techniques
60Articles
6Kill-chain phases

Top techniques on Azure (25)

Reconnaissance (1)

[LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP

Delivery (8)

Azure AD brute-force login Internal delivery · alerting DD Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal delivery · hunting DSP [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package Bespoke delivery · alerting DSP

Exploitation (10)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] Entra ID Device Authorization Grant (device code) authentication flow sign-in Bespoke exploit · alerting DSΣPDD [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering Bespoke exploit · alerting DSPDDCS [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD

Installation (10)

Azure AD member assigned Global Administrator role Internal install · alerting DD Azure AD MFA disabled for a user Internal install · alerting DD Azure diagnostic setting deleted Internal install · alerting DD Azure new owner added to service principal Internal install · alerting DD Azure SQL Server firewall rule created Internal install · alerting DD Azure user added to administrative group Internal install · alerting DD [LLM] OWAReaper server-side persistence: Owner rights granted to 'Default' user on mailbox folders Bespoke install · alerting DSΣP [LLM] Entra helpdesk password reset immediately followed by new MFA method registration (ShinyHunters ATO) Bespoke install · alerting SPDD [LLM] New attacker device registered/joined to Microsoft Entra ID Bespoke install · hunting DSΣPDD [LLM] Entra ID device registration = ARToken PRT persistence after device-code token theft Bespoke install · hunting DSΣDD

Command & Control (7)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [LLM] Suspicious OAuth application consent granting broad scopes (ShinyHunters DataLoader-style persistence) Bespoke c2 · hunting DSΣPDD [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD

Actions on Objectives (34)

Azure Key Vault keys / secrets read Internal actions · alerting DD Azure storage soft-delete disabled Internal actions · alerting DD MFA fatigue / push-bombing Internal actions · alerting DSP OAuth consent / suspicious app grant Internal actions · alerting DSΣP [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Azure AD FullAccessAsApp Permission Assigned ESCU actions · alerting P Azure AD Multi-Factor Authentication Disabled ESCU actions · alerting P Azure AD New MFA Method Registered For User ESCU actions · alerting P Azure AD Privileged Graph API Permission Assigned ESCU actions · alerting P Azure AD Service Principal New Client Credentials ESCU actions · alerting P Azure AD Service Principal Privilege Escalation ESCU actions · alerting P Azure Automation Account Created ESCU actions · alerting P Azure Automation Runbook Created ESCU actions · alerting P Azure Runbook Webhook Created ESCU actions · alerting P Microsoft Intune Device Health Scripts ESCU actions · hunting P Microsoft Intune DeviceManagementConfigurationPolicies ESCU actions · hunting P Microsoft Intune Manual Device Management ESCU actions · hunting P Microsoft Intune Mobile Apps ESCU actions · hunting P [LLM] Bulk M365 / SharePoint / OneDrive file download by a single identity (cloud data theft) Bespoke actions · alerting DSP [LLM] SSO application-access burst — one identity authenticating to many distinct SaaS apps in a short window Bespoke actions · alerting DSPDD [LLM] Exposed-credential reuse: one identity authenticating to 3+ distinct cloud services within 1 hour Bespoke actions · alerting DSDDCW [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] Post-compromise malicious inbox rule for defense evasion (UAT-11764 / ARToken BEC) Bespoke actions · hunting DSDD [LLM] n8n-MCP destructive workflow version backup deletion (delete/prune/truncate) — CVE-2026-54052 impact Bespoke actions · alerting SΣP [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP [LLM] Post-device-code token abuse: mailbox / OneDrive / Teams access from a new IP after device-code sign-in Bespoke actions · alerting DS [LLM] ARToken BEC toolkit: inbox forwarding/hiding rule creation on compromised M365 mailbox Bespoke actions · hunting DSΣ [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke actions · alerting DSP [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD

Recent articles citing Azure-targeted detections