Detecting Azure Lateral Movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

thedixitjain 7de03b0 4 files · 24.6 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/devops-and-infra/detecting-azure-lateral-movement commit 7de03b0c22

Frequently asked questions

npx skillmds add thedixitjain/detecting-azure-lateral-movement