Skip to content
Threat Feed

Tag

Service Principal

8 briefs RSS
medium advisory

Entra ID Service Principal Sign-in from Unusual ASN

Detection of Entra ID service principal sign-ins originating from a previously unseen combination of workload identity and source autonomous system number (ASN), potentially indicating compromised credentials or malicious activity.

Entra ID azure entra-id service-principal initial-access
2r 2t
high advisory

Azure Service Principal Authentication from Multiple Countries

Detects Azure service principals authenticating from multiple countries within a short time, indicating potentially compromised credentials being used from different geographic locations.

Azure +1 cloud service principal initial access credential compromise
2r 1t
high advisory

Azure AD Service Principal Created

The creation of a Service Principal in an Azure AD environment is detected, which can be used by adversaries to establish persistence and bypass multi-factor authentication.

Azure Active Directory azure cloud persistence service-principal
2r 1t
medium advisory

Detection of Azure Service Principal Creation

Detects the creation of a service principal in Azure, which could indicate potential attacker activity for lateral movement or persistence.

Azure cloud service principal persistence lateral movement
3r 1t
medium advisory

Azure Service Principal Removal Detection

Detection of a service principal removal in Azure, potentially indicating malicious activity or an attempt to remove evidence of a compromise.

Azure service principal stealth cloud
2r 1t
high advisory

Azure AD Admin Consent Bypassed by Service Principal

A service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.

Azure Active Directory +1 azuread admin-consent service-principal privilege-escalation
2r 1t
medium advisory

Entra ID User Added as Service Principal Owner for Persistence

An adversary may add a user account as an owner for an Azure service principal to define what an application can do in the Azure AD tenant, potentially leading to persistence and privilege escalation.

Entra ID +1 azure service-principal persistence privilege-escalation
2r 4t
high advisory

Azure AD Service Principal Privilege Escalation

An Azure Active Directory (Azure AD) Service Principal elevates its own privileges by adding itself to a new application role assignment, potentially leading to unauthorized access and control within the Azure environment.

Azure AD azure azure-ad service-principal privilege-escalation
2r 1t