Interactive investigation
Investigate credential abuse and Azure persistence with Microsoft Sentinel
Correlate sign-in, audit, and Azure activity to validate a privileged cloud compromise and coordinate the response.
Scenario briefing
Microsoft Sentinel creates a high-severity incident after a successful sign-in from an unfamiliar network is followed by a privileged role assignment and a new application credential. The operations target a production subscription and occur outside the administrator's normal working pattern.
Mission
Validate whether the activity is malicious, reconstruct the cloud attack sequence, determine the affected identities and resources, contain every access path, and improve the detection after closure.
Products
Ready to investigate?
Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.