Suspicious Entra ID Password Spraying via ROPC Grant to Azure CLI App

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects Entra ID authentication attempts using the Resource Owner Password Credential (ROPC) flow against the token endpoint while impersonating the well-known Azure CLI first-party application. Reported by Huntress, adversaries abuse ROPC because it submits username and password directly and can bypass interactive MFA prompts, making it a favored vector for password spraying. Detecting non-interactive ROPC grants tied to the Azure CLI app surfaces credential-guessing campaigns before account takeover.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Entra ROPC Password Spray Against Azure CLI Client
Malicious Consent to Known Traitorware Mail Clients via Azure AD
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Suspicious OfficeHome Sign-In With Axios User Agent via Tycoon 2FA Proxy
Suspicious IAM Persistence and Privilege Escalation Actions
Suspicious AWS STS AssumeRoot Privilege Escalation To Member Account Root
Suspicious AWS Console Phishing MFA Relay Endpoints
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Possible SES Sending Configuration Enumeration via CloudTrail
Suspicious Entra ID Password Spraying via ROPC Grant to Azure CLI App
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.