Remote usage of an Azure Service Principal token
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal Application Access Token (T1528), Unsecured Credentials (T1552)
Severity
Informational
Description
An Azure Service Principal token was used externally of the cloud environment.
Attacker's Goals
Exfiltrate valid token and abuse it remotely.
Investigative actions
Verify whether the service principal should be used remotely.
Check what API calls were executed by the service principal.
Determine whether the service principal is compromised.
Variations
Was this helpful?
