Investigating Azure Incidents

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs, anchor the investigation on the identity that made the calls (a user, service principal, or managed identity), trace privilege escalation through role assignments, hunt managed-identity token abuse and VM run-command code execution, and detect storage or Key Vault data theft while correlating back to Entra sign-in logs. Use when responding to a suspected Azure resource compromise, anomalous Azure Activity Log entries, a Microsoft Defender for Cloud alert, managed-identity or service-principal abuse, a crypto-mining VM, or storage-account exfiltration.

trilwu 25c8280 20.9 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/investigating-azure-incidents commit 25c8280ed9

Frequently asked questions

npx skillmds add trilwu/investigating-azure-incidents