//Cyber.Engineer

Azure Active Directory: Threat Hunting - SPN Key Count

Azure Service Principals in your tenant should be periodically reviewed just as app registration secrets and passwords should be, see post https://www.cyber.engineer/azure-active-directory-threat-hunting-app-registration-key-count as they both work hand-in-hand. What is a service principal? To access resources that are secured by an Azure AD tenant, the entity that

Azure Active Directory: Threat Hunting - App Reg Key Count

As part of your organisation's proactive threat hunting, app registrations with secrets and passwords configured should be reviewed to look for any suspicious entries. The following Powershell script which I like to run in CloudShell will give you an overview within your tenant. Service principals work hand-in-hand with app registrations,

Azure Defender: Unusual unauthenticated access to your storage account

Investigating Azure Defender Unusual unauthenticated access to your storage account. What is the $web container?

O365: Enable mailbox auditing for all mailboxes

Mailbox auditing allows you to discover illicit activities performed in an Exchange Online mailbox, whether by an attacker because of a compromised account or by a malicious insider who has delegate access.

O365: Disable legacy authentication

Using legacy authentication may, in some circumstances, increase the risk of account compromise due to how the password is transmitted and stored.

//Cyber.Engineer © 2026