BigHugger
sk Skill · mukul975

detecting-entra-offensive-tools-in-graph-logs

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and AzureHound, including User-Agent signatures, roadrecon endpoint sweeps, and sign-in correlation. Use when investigating suspicious Microsoft Graph API activity, Entra ID reconnaissance, or building Sentinel analytics rules to…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonaadinternalskustosentinelkqlmicrosoft-graphbashentra-iddetection-engineeringroadtoolsthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python