Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL
Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.
Signals worth watching
- Identity: SSPR resets or MFA method removal followed by sign-ins from new devices; mass Microsoft Graph enumeration by a user.
- Azure control plane: Key Vault access policy or RBAC changes; storage firewall changes; NSG modifications; PIM activations outside normal patterns.
- VMs: Run Command and VMAccess extension use; new remote access tools installed; Defender Antivirus disabled.
- Data: large reads from Storage, SQL exports, Key Vault secret reads by unusual identities.
Where the data lives
- Entra ID audit and sign-in logs; Microsoft Graph activity logs.
- Azure Activity logs.
- Key Vault diagnostic logs (
AzureDiagnosticsor resource-specific tables). - Defender for Endpoint and Defender for Cloud alerts.
Starting queries
Run Command and extensions:
AzureActivity
| where OperationNameValue has_any ("RUNCOMMAND/ACTION", "VIRTUALMACHINES/EXTENSIONS/WRITE")
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, CallerIpAddress, _ResourceId, OperationNameValue
Key Vault secret reads by caller:
AzureDiagnostics
| where ResourceProvider == "MICROSOFT.KEYVAULT" and OperationName == "SecretGet"
| summarize Reads = count() by CallerIPAddress, identity_claim_upn_s, Resource, bin(TimeGenerated, 1h)
Defender tampering on endpoints:
DeviceEvents
| where ActionType in ("AntivirusDisabled", "TamperingAttempt")
| project Timestamp, DeviceName, InitiatingProcessAccountName, ActionType
Response
- Disable compromised identities; revoke sessions.
- Remove attacker RBAC changes and firewall modifications.
- Rotate Key Vault secrets and storage keys accessed.
- Remove remote access tools and re-enable protections on VMs.
Sources
- Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach Incident Teardowns
- How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks How-To & Hardening
- CIO Brief: One Compromised Identity, Every Cloud Layer CIO Briefings