Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Detection & Response

Articles in Detection & Response.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityDetection & Response

Detecting Suspicious Activity From SSO-Connected Third-Party Platforms

Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.

AI SecurityDetection & Response

Detecting Rogue AI Agent Activity: Agent Telemetry and Egress Alerts

Rogue or manipulated AI agents reveal themselves through activity outside their expected scope. These detections focus on egress, unexpected data access and...

AWSDetection & Response

Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries

Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.

Entra ID & IdentityDetection & Response

Hunting for Suspicious Entra Provisioning and Service Principal Changes

Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...

AI SecurityDetection & Response

Detecting AI Agent Sandbox Escape: Agent Telemetry and Egress Alerts

AI agents escaping containment or misusing access produce telemetry you can watch. These detections focus on agent identities, network egress and shared...

Microsoft 365Detection & Response

Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries

Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.

AzureDetection & Response

Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL

Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.

Microsoft 365Detection & Response

Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries

Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.

AWSDetection & Response

Detecting Automated AWS Privilege Escalation: CloudTrail, GuardDuty and Athena Queries

When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...

Multi-CloudDetection & Response

Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections

Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...

Entra ID & IdentityDetection & Response

Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL

When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...

Multi-CloudDetection & Response

Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections

Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.

Microsoft 365Detection & Response

Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries

SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...

Microsoft 365Detection & Response

Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries

Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.

Entra ID & IdentityDetection & Response

Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL

After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.

Multi-CloudDetection & Response

Detecting GitHub Actions Supply Chain Attack: Sentinel and GuardDuty Detections

Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...

Entra ID & IdentityDetection & Response

Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL

When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...

AWSDetection & Response

Detecting AWS Session Token Hijacking: CloudTrail, GuardDuty and Athena Queries

Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.

AWSDetection & Response

Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries

Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.

Multi-CloudDetection & Response

Detecting Stolen API Key: Sentinel and GuardDuty Detections

Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.

AWSDetection & Response

Detecting Exposed Environment Variables: CloudTrail, GuardDuty and Athena Queries

Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion...

Multi-CloudDetection & Response

Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections

Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.

Multi-CloudDetection & Response

Detecting Compromised Open Source Packages: Sentinel and GuardDuty Detections

Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...

Multi-CloudDetection & Response

Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections

Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.

Page 1 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.