Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Detection & Response

Articles in Detection & Response.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Detection & Response

Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries

OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...

Entra ID & IdentityDetection & Response

Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL

Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...

AzureDetection & Response

Detecting SAS Token Exposure: Defender for Cloud and Sentinel KQL

Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.

Entra ID & IdentityDetection & Response

Detecting Help Desk Social Engineering: Entra Sign-In Logs and Sentinel KQL

Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.

Microsoft 365Detection & Response

Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries

Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.

Microsoft 365Detection & Response

Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries

Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.

Multi-CloudDetection & Response

Detecting File Transfer Zero-Day Exploitation: Sentinel and GuardDuty Detections

Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.

Multi-CloudDetection & Response

Detecting CI/CD Secrets Theft: Sentinel and GuardDuty Detections

After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...

Multi-CloudDetection & Response

Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections

Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.

AzureDetection & Response

Detecting Azure Blob Public Access: Defender for Cloud and Sentinel KQL

Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...

Entra ID & IdentityDetection & Response

Detecting MFA Push Bombing: Entra Sign-In Logs and Sentinel KQL

MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.

Microsoft 365Detection & Response

Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries

Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and...

Entra ID & IdentityDetection & Response

Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL

SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.

Microsoft 365Detection & Response

Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries

AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that...

Microsoft 365Detection & Response

Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries

Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from...

Multi-CloudDetection & Response

Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections

Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.

Entra ID & IdentityDetection & Response

Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL

MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...

Multi-CloudDetection & Response

Detecting Log4j Exploitation: Sentinel and GuardDuty Detections

Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.

AzureDetection & Response

Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL

Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.

AzureDetection & Response

Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel

Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.

Microsoft 365Detection & Response

Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries

Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.

Microsoft 365Detection & Response

Detecting Low-Code Data Exposure: Defender XDR and Sentinel Hunting Queries

Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.

Multi-CloudDetection & Response

Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections

MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.

Multi-CloudDetection & Response

Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections

Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.

← NewerPage 2 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.