Detecting Azure Lateral Movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

theheavenlyd3mon 7441d21 4 files · 24.5 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-cloud/skills/Anthropic-Cybersecurity-Skills/skills/detecting-azure-lateral-movement commit 7441d21894

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-azure-lateral-movement