Multi-CloudDetection & ResponseRetrospectives

Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.

Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.

Detect the exposure

  • GitHub secret scanning alerts (including partner alerts sent to providers like AWS and Microsoft).
  • Defender for Cloud secrets scanning findings on VMs and code.
  • Purview DLP alerts for credentials shared in documents or chats.
  • Third-party monitoring of public paste sites and code repositories.

Detect the misuse

  • Super admin or highly privileged accounts signing in from unfamiliar IPs, countries or devices.
  • Admin accounts used at unusual times or from hosting providers.
  • Admin accounts accessing customer or tenant data in bulk.
  • Service accounts signing in interactively.

Where the data lives

  • Entra ID sign-in logs and Identity Protection.
  • SaaS admin audit logs (connected to Sentinel or Defender for Cloud Apps).
  • CloudTrail for AWS root and admin activity.

A starting query

Privileged Entra ID accounts signing in from new countries:

let admins = IdentityInfo
| where AssignedRoles has_any ("Global Administrator", "Privileged Role Administrator", "Security Administrator")
| distinct AccountUPN;
SigninLogs
| where UserPrincipalName in~ (admins) and ResultType == "0"
| summarize Countries = make_set(Location) by UserPrincipalName, bin(TimeGenerated, 1d)

(The IdentityInfo table requires UEBA in Sentinel.)

Response

  1. Rotate the credential immediately.
  2. Review all actions taken with it.
  3. Remove the exposed copy and find out how it got there.
detect exposed super admin credentialsVerkada2021

More on this story