By
•
January 05, 2025
•
azure
azure ad
Daily Blog
entraid
sunday funday
•
Hello Reader,
Welcome back to Sunday Funday! This week we are going straight in to topics I see as current research blind spots. We are going to be focusing on Entra ID aka Azure AD and what evidence you can find when people run tools like Bloodhound/Sharphound. I look forward to your thorough responses as we work as a community to overcome lack of knowledge.
The Prize:
The Rules:
$100 Amazon Giftcard
An apperance on the following week's Forensic Lunch!
The Challenge:
What evidence is left behind in Azure when an attacker runs Bloodhound or any derivative like Sharphound. You should document at least two scenarios:
1. Default logging
2. Turning on any optional logging you want to test.
Your response can be a link to your own blog, an email, a document etc.. Bonus points if you point out specific indicators that can be searched for or alerted off of.