Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent

Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.

FreeReviewedSigma · High · v5
Product
azure
Service
signinlogs
Author
Janantha Marasinghe (SigmaHQ), DRL 1.1
Published
2022-11-27
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies activity consistent with AzureHound by matching the default User-Agent string used after a successful sign-in. Attackers often run AzureHound to enumerate Azure AD and related permissions for subsequent discovery and targeting. The detection relies on Azure sign-in log telemetry, specifically the User-Agent field and the ResultType indicating successful authentication.

Related detections8 linkedT1526 — drag to rearrange
Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
Suspicious Azure CLI Enumeration of Roles and Logic Apps
Suspicious AWS Organizations and Account Discovery via aws (via cloudtrail)
Suspicious Anonymous Access to Kubernetes API Server via Audit Log
AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Kubernetes RBAC SelfSubjectRulesReview Permission Enumeration Attempt
GitHub Audit Log: Self-Hosted Runner Configuration Changes
Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Pivot detection · T1526 · 8 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.