cd
Toggle Menu
whoami
detection
blog
tags
Detections tagged with
T1556
Jan 7, 2025
Azure Key Vault - Vault Access Configuration Modified
#KQL
#Sentinel
#Azure Key Vault
#Misconfiguration
#T1555.006
#T1556
Jan 10, 2025
Azure Key Vault - Potential Privilege Escalation Activity
#KQL
#Sentinel
#Azure Key Vault
#T1555.006
#T1556
Jan 12, 2025
AWS CloudTrail - New Access Key Created for Root User
#KQL
#Sentinel
#AWS CloudTrail
#T1556
#T1098.001
Jan 19, 2025
Azure Key Vault - User Adds Themselves to a Vault Access Policy
#KQL
#Sentinel
#Azure Key Vault
#Misconfiguration
#T1555.006
#T1556