Analytics Medium

Azure Privilege Escalation Using an Application

An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:

An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.

Investigative actions:

Check if the affected account is new to the organization. Check whether the application that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

Test period:
5 Hours
Deduplication:
1 Day