Cloud Discovery With AzureHound
ID: 2c6d0420-3339-5d5b-9eb6-eb66b2b12a1c
STIX ID: report--2c6d0420-3339-5d5b-9eb6-eb66b2b12a1c
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-10-24
Date Updated: 2026-04-28
Author: Margaret Kelley, Bill Batchelor and Eyal Rafian
This report examines AzureHound, a BloodHound collection tool, and how threat actors leverage it for Azure/Entra ID discovery, mapping its commands to MITRE ATT&CK techniques (e.g., account, group/role, storage, service, and infrastructure discovery). It highlights logging nuances—rich visibility via Microsoft Graph activity logs versus gaps for ARM REST list/read operations—then offers mitigations (phishing‑resistant MFA, Conditional Access, Token Protection, PIM/PAM, CSPM/CDR/EDR coverage) and practical hunting guidance using Graph logs and Cortex XQL (e.g., AzureHound user‑agent and bursty enumeration patterns). The report also notes observed usage by Curious Serpens/Peach Sandstorm, Void Blizzard, and Storm‑0501 and provides steps to tune detections and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
