Skip to main content

investigating-azure-incidents

Investigate a suspected Azure and Entra ID compromise from the control plane — Azure Activity Log, Entra sign-in and audit logs, and the Microsoft 365 unified audit log, queried with KQL in Log Analytics/Sentinel — to reconstruct identity abuse, MFA and conditional-access bypass, service-principal and app-consent abuse, role changes, and Key Vault access. Use when the evidence is Azure/Entra logs rather than a host. Identity is the perimeter here; the sign-in and audit logs are the crime scene.

Aller à l'installation

Informations de source

Dépôt
EvilFreelancer/secs
Dernière activité de la source
8 août 2026 à 20:56
Langue détectée de SKILL.md
anglais
Étoiles
9
Forks
2

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.