Detecting Azure Lateral Movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

yanacuti1121 9a476ce 4 files · 24.5 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/detecting-azure-lateral-movement commit 9a476ce0b9

Frequently asked questions

npx skillmds add yanacuti1121/detecting-azure-lateral-movement