logo

Attackers Don’t Need Your Devices Anymore They Just Need Your Identity.

ID: 2059260b-b4bd-57ba-b38d-b825e1813d5c

STIX ID: report--2059260b-b4bd-57ba-b38d-b825e1813d5c

Feed Name: Detect FYI

Threat Score
72/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: Rohitashokgowd

...
...

This report details an "identity-plane" lateral movement technique in which attackers steal a user’s credentials/session token via phishing, use Graph API enumeration to map a tenant, register a service principal (or add credentials) to gain non-human access, and then read/send mail or access files from other users—all without compromising endpoints. It defines a five-stage kill chain (compromise, permission discovery, pivot, cross-identity access, action on objective), lists Defender XDR telemetry sources (MicrosoftGraphActivityLogs, CloudAppEvents, IdentityLogonEvents), and provides multiple KQL detection queries and correlation strategies to identify reconnaissance, suspicious app registrations/credential additions, dormant service-principal credential drops, and anomalous application access patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.