logo

Cloud Discovery With AzureHound

ID: 2c6d0420-3339-5d5b-9eb6-eb66b2b12a1c

STIX ID: report--2c6d0420-3339-5d5b-9eb6-eb66b2b12a1c

Feed Name: Palo Alto Networks Unit 42

Date Published: 2025-10-24

Date Updated: 2026-04-28

Author: Margaret Kelley, Bill Batchelor and Eyal Rafian

...
...

This report examines AzureHound, a BloodHound collection tool, and how threat actors leverage it for Azure/Entra ID discovery, mapping its commands to MITRE ATT&CK techniques (e.g., account, group/role, storage, service, and infrastructure discovery). It highlights logging nuances—rich visibility via Microsoft Graph activity logs versus gaps for ARM REST list/read operations—then offers mitigations (phishing‑resistant MFA, Conditional Access, Token Protection, PIM/PAM, CSPM/CDR/EDR coverage) and practical hunting guidance using Graph logs and Cortex XQL (e.g., AzureHound user‑agent and bursty enumeration patterns). The report also notes observed usage by Curious Serpens/Peach Sandstorm, Void Blizzard, and Storm‑0501 and provides steps to tune detections and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.