BigHugger
sk Skill · mukul975

detecting-azure-service-principal-abuse

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role assignment, admin consent bypass, and service principal enumeration. Use when investigating suspected privilege escalation or persistence via service principals, or building threat-hunting queries for Entra ID identity abuse.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlsentinelpowershellsplunkPythondetectioncredential-abuseprivilege-escalationsplservice-principalentra-idazure
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python