Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.

Signals worth watching

  • Identity: SSPR resets or MFA method removal followed by sign-ins from new devices; mass Microsoft Graph enumeration by a user.
  • Azure control plane: Key Vault access policy or RBAC changes; storage firewall changes; NSG modifications; PIM activations outside normal patterns.
  • VMs: Run Command and VMAccess extension use; new remote access tools installed; Defender Antivirus disabled.
  • Data: large reads from Storage, SQL exports, Key Vault secret reads by unusual identities.

Where the data lives

  • Entra ID audit and sign-in logs; Microsoft Graph activity logs.
  • Azure Activity logs.
  • Key Vault diagnostic logs (AzureDiagnostics or resource-specific tables).
  • Defender for Endpoint and Defender for Cloud alerts.

Starting queries

Run Command and extensions:

AzureActivity
| where OperationNameValue has_any ("RUNCOMMAND/ACTION", "VIRTUALMACHINES/EXTENSIONS/WRITE")
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, CallerIpAddress, _ResourceId, OperationNameValue

Key Vault secret reads by caller:

AzureDiagnostics
| where ResourceProvider == "MICROSOFT.KEYVAULT" and OperationName == "SecretGet"
| summarize Reads = count() by CallerIPAddress, identity_claim_upn_s, Resource, bin(TimeGenerated, 1h)

Defender tampering on endpoints:

DeviceEvents
| where ActionType in ("AntivirusDisabled", "TamperingAttempt")
| project Timestamp, DeviceName, InitiatingProcessAccountName, ActionType

Response

  1. Disable compromised identities; revoke sessions.
  2. Remove attacker RBAC changes and firewall modifications.
  3. Rotate Key Vault secrets and storage keys accessed.
  4. Remove remote access tools and re-enable protections on VMs.

Sources

  1. Source
detect sspr social engineeringStorm-29492026

More on this story