Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-06-29
Updated
2026-08-28

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects an Entra ID sign-in flagged with an anonymized IP address or a high real-time risk level, indicating access through Tor or a VPN anonymizer or from a session Microsoft's risk engine deems likely compromised. Compromise of cloud accounts is the most prevalent technique in the Red Canary Threat Detection Report. Detecting anonymized and high-risk sign-ins surfaces suspicious identity access at the authentication boundary.

Related detections9 linkedT1078.004 — drag to rearrange
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Suspicious AWS Console Login Without MFA
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious AWS STS Session Token and Role Chaining Abuse via CloudTrail (via aws)
Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.