Multi-CloudDetection & ResponseRetrospectives

Detecting Stolen API Key: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.

Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.

Signals worth watching

  • API calls from IP addresses outside your expected ranges.
  • Password resets of local accounts within the remote support tool.
  • Remote sessions started outside business hours or without associated tickets.
  • Remote sessions to unusual numbers of endpoints.
  • New remote support agents installed on endpoints unexpectedly.
  • Vendor security notices.

Where the data lives

  • Remote support tool audit logs (forwarded via API or syslog to your SIEM).
  • Endpoint telemetry showing remote support processes and child processes.
  • Network logs for connections to vendor infrastructure.

A starting query

Remote support tool processes spawning command shells on endpoints:

DeviceProcessEvents
| where InitiatingProcessFileName has_any ("bomgar", "beyondtrust", "ScreenConnect", "TeamViewer", "AnyDesk", "Splashtop")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, ProcessCommandLine

Remote support legitimately runs commands; compare against ticket records and technician schedules.

Unexpected installation

DeviceFileEvents
| where FileName has_any ("ScreenConnect", "AnyDesk", "TeamViewer")
| where ActionType == "FileCreated"
| project Timestamp, DeviceName, FolderPath, InitiatingProcessAccountName

Response

  1. Revoke and rotate API keys.
  2. Terminate active sessions.
  3. Review session logs for actions taken.
  4. Investigate endpoints accessed.
detect stolen api keyUS Treasury / BeyondTrust2024

More on this story