Suspicious Credential Added to Application or Service Principal in Entra ID (via azure)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-05-09
Updated
2026-08-28

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects new password or certificate credentials being added to an Entra ID application or service principal, the persistence technique Silk Typhoon uses to abuse OAuth applications and service principals holding administrative permissions. Adversaries append their own secrets to trusted applications to authenticate as the app and access mail, OneDrive, and SharePoint through MSGraph, so unexpected credential additions signal a supply-chain identity compromise.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious IAM Access Key Creation for Persistence (via cloudtrail)
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious AWS Administrator Policy Attachment via CloudTrail (via aws)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Inline Policy Granting Full S3 Access
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious GCP Service Account Key Creation for Persistence (via gcp.audit)
Suspicious Device Registration Following OAuth Token Theft
Suspicious Credential Added to Application or Service Principal in Entra ID (via azure)
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.