Detecting Azure Service Principal Abuse

by mukul975 mukul975/detecting-azure-service-principal-abuse multi-file Updated


Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

SKILL.md

Related

  1. Detecting OAUTH Token Theft · mukul975 bundle
    Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
    24.6k
    repo stars
  2. Entra Agent Id · microsoft bundle
    Create and manage OAuth2-capable identities for AI agents using Microsoft Graph beta API.
    2.7k
    repo stars
  3. Detecting Azure Lateral Movement · mukul975 bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    24.6k
    repo stars
  4. Detecting Compromised Cloud Credentials · mukul975 bundle
    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    24.6k
    repo stars
  5. Azure Identity Rust · microsoft
    Authenticate to Azure services from Rust using Microsoft Entra ID credentials, including managed identity, service principal, and local development tools.
    2.7k
    repo stars
  6. Azure Identity Dotnet · microsoft
    Authenticate .NET applications to Azure services using Microsoft Entra ID with support for managed identities, service principals, and developer credentials.
    2.7k
    repo stars

Frequently asked questions

How do I install the Detecting Azure Service Principal Abuse skill?

Run npx skillmds add mukul975/detecting-azure-service-principal-abuse in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Detecting Azure Service Principal Abuse skill do?

Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments. It is listed under Security, DevOps & Infra, Cloud Platforms, Incident Response on SkillMD.

Is Detecting Azure Service Principal Abuse safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: FAIL. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Detecting Azure Service Principal Abuse?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Detecting Azure Service Principal Abuse free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Detecting Azure Service Principal Abuse?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.