Interactive investigation

Investigate credential abuse and Azure persistence with Microsoft Sentinel

Correlate sign-in, audit, and Azure activity to validate a privileged cloud compromise and coordinate the response.

DifficultyIntermediateEstimated time35 minPrimary domainManage a security operations environment

Scenario briefing

Microsoft Sentinel creates a high-severity incident after a successful sign-in from an unfamiliar network is followed by a privileged role assignment and a new application credential. The operations target a production subscription and occur outside the administrator's normal working pattern.

Mission

Validate whether the activity is malicious, reconstruct the cloud attack sequence, determine the affected identities and resources, contain every access path, and improve the detection after closure.

Products

Microsoft SentinelMicrosoft Entra IDAzure Activity LogLogic Apps
01

Ready to investigate?

Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.