Detecting Azure Lateral Movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-azure-lateral-movement commit 1374ed7db6

Frequently asked questions

npx skillmds@latest add 26zl/detecting-azure-lateral-movement