Suspicious Legacy AAD Graph Enumeration With Scripting User Agent

PremiumReviewedSigma · Medium · v1
Product
azure
Service
azureactivity
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects enumeration of users groups and service principals through the legacy Azure AD Graph API versions 1.5 and 1.6 from scripting user agents such as python aiohttp curl and Go-http-client as described in Elastic research on AAD Graph activity logs. Programmatic access to the deprecated Graph endpoint frequently reflects tenant reconnaissance rather than sanctioned application traffic.

Related detections4 linkedT1087.004 — drag to rearrange
Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Kubernetes RBAC SelfSubjectRulesReview Permission Enumeration Attempt
Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Suspicious Legacy AAD Graph Enumeration With Scripting User Agent
Pivot detection · T1087.004 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.