Analyzing Azure Activity Logs For Threats

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.

theheavenlyd3mon e578391 4 files · 21.6 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-forensics/skills/Anthropic-Cybersecurity-Skills/skills/analyzing-azure-activity-logs-for-threats commit e578391bca

Frequently asked questions

npx skillmds add theheavenlyd3mon/analyzing-azure-activity-logs-for-threats