Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.
Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.
Detect the exposure
- GitHub secret scanning alerts (including partner alerts sent to providers like AWS and Microsoft).
- Defender for Cloud secrets scanning findings on VMs and code.
- Purview DLP alerts for credentials shared in documents or chats.
- Third-party monitoring of public paste sites and code repositories.
Detect the misuse
- Super admin or highly privileged accounts signing in from unfamiliar IPs, countries or devices.
- Admin accounts used at unusual times or from hosting providers.
- Admin accounts accessing customer or tenant data in bulk.
- Service accounts signing in interactively.
Where the data lives
- Entra ID sign-in logs and Identity Protection.
- SaaS admin audit logs (connected to Sentinel or Defender for Cloud Apps).
- CloudTrail for AWS root and admin activity.
A starting query
Privileged Entra ID accounts signing in from new countries:
let admins = IdentityInfo
| where AssignedRoles has_any ("Global Administrator", "Privileged Role Administrator", "Security Administrator")
| distinct AccountUPN;
SigninLogs
| where UserPrincipalName in~ (admins) and ResultType == "0"
| summarize Countries = make_set(Location) by UserPrincipalName, bin(TimeGenerated, 1d)
(The IdentityInfo table requires UEBA in Sentinel.)
Response
- Rotate the credential immediately.
- Review all actions taken with it.
- Remove the exposed copy and find out how it got there.
- Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed Incident Teardowns
- How to Find and Vault Hardcoded Credentials Across Cloud Services How-To & Hardening
- CIO Brief: IoT and SaaS Admin Access — The Overlooked Privilege CIO Briefings