Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Detection & Response

Articles in Detection & Response.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Detection & Response

Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries

Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.

Multi-CloudDetection & Response

Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections

Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.

Microsoft 365Detection & Response

Detecting Third-Party App Tenant Access: Defender XDR and Sentinel Hunting Queries

A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.

Entra ID & IdentityDetection & Response

Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL

Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...

Entra ID & IdentityDetection & Response

Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL

Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...

AzureDetection & Response

Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL

Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...

Entra ID & IdentityDetection & Response

Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL

Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.

Microsoft 365Detection & Response

Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries

Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.

Multi-CloudDetection & Response

Monitoring Third-Party SaaS Risk Signals and Breach Notifications

You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.

Microsoft 365Detection & Response

Detecting Meeting Hijacking: Defender XDR and Sentinel Hunting Queries

Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...

Microsoft 365Detection & Response

Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries

Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.

Multi-CloudDetection & Response

Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections

Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...

AzureDetection & Response

Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL

Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.

Multi-CloudDetection & Response

Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections

Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.

AWSDetection & Response

Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries

Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.

AWSDetection & Response

Detecting SSRF Metadata Credential Theft: CloudTrail, GuardDuty and Athena Queries

The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...

AzureDetection & Response

Detecting Exposed RDP Exploitation: Defender for Cloud and Sentinel KQL

Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...

Microsoft 365Detection & Response

Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries

A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...

Microsoft 365Detection & Response

Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries

Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...

Multi-CloudDetection & Response

Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments

Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...

Entra ID & IdentityDetection & Response

Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL

Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...

Entra ID & IdentityDetection & Response

Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL

SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...

Microsoft 365Detection & Response

Detecting OAuth App Over-Permission: Defender XDR and Sentinel Hunting Queries

OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...

Microsoft 365Detection & Response

Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries

Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across...

← NewerPage 3 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.